Docs

Introduction

What CISO360AI is, how the platform is organised, and where to go next.

CISO360AI is a secure, AI-native platform that unifies

  • Governance, risk and compliance (GRC)
  • Risk management and continuous threat exposure management (CTEM)
  • A native Model Context Protocol (MCP) server to connect your own AI agents

Preview

The platform is currently offered in preview. It is provided as-is, with no warranty and no liability for preview and free-tier use. See the Terms of Service for the full posture.

What the platform does

AI drafts, a person stays accountable

  • AI Sidekick, your AI vCISO. Expert personas that guide, draft and derive risk from compliance gaps, with human approval before higher-risk changes.
  • Bring your own agent. A native MCP server with scope-gated writes — they land directly within an agent key's granted scopes, or wait as a proposal for a person to approve. Available on every plan, including Free.
  • Actions and proposals. AI-drafted changes wait in an inbox for a person to approve or reject before they take effect, and approved remediation work becomes a tracked item. Every decision a person makes is recorded in the audit log.

Do the work once, see it reflected where it maps

  • Compliance and standards. Get audit-ready across the supported standards catalogue, mapped to a common NIST CSF 2.0 spine with bidirectional control ↔ requirement mapping and cross-framework derivation.
  • Cloud and SaaS posture. Connect a cloud or SaaS tenant and it keeps re-checking itself. Cloud and identity configuration checks are mapped to the NIST CSF controls they support: a failing check becomes evidence against the requirement it maps to, plus a remediation proposal that, by default, waits for a person to approve.
  • Risk and remediation. A risk register with inherent and residual scoring, fed by compliance gaps and failed checks, with remediation tracked to done.
  • Policies and reports. A starter policy library to adapt rather than write from scratch, with content blocks shared across documents, version history, and organisation details set once that every generated policy and report picks up.

The first answer in minutes, ranked by what's exploitable

  • Continuous threat exposure management. Passive, active and deep attack-surface discovery with exposure scoring and prioritisation.
  • Identity-exposure monitoring. Dark-web and leaked-credential findings for your domains.
  • Pentest as a Service. Scope a penetration test, report findings from a shared library of reusable write-ups, and generate a client-ready security assessment report, with a retest that links back to it. See Penetration tests & assessments.

How the platform is organised

Three concepts carry everything else.

ConceptWhat it is
OrganisationYour company/tenant, the account boundary that all your users, data, and credentials belong to, and that no other customer can access.
ProjectA scope within an organisation: its assets, assessments, risks and evidence. Every organisation has a main project, which carries the organisation's main domain. Add more for a distinct scope — a public-website project, an IT-department project, a subsidiary — up to the limit on your plan.
ModuleA capability you switch on per organisation: governance and compliance, attack-surface scanning, identity-exposure scanning, and the policy starter set.

Consultancies, MSSPs and vCISOs run several projects, and share projects with third parties, with clean isolation between them.

Next steps

On this page