Getting started
Create an account, work through the setup wizard, and follow the first-run checklist.
This walks through your first session: creating an organisation, choosing what the platform should do for you, and working the checklist it builds from your answers.
1. Create an account
Sign up at app.ciso360.ai/auth/signup. The Free plan needs no credit card. Sign-in uses your identity provider, so there is no separate password to manage here.
Your first organisation is created for you, together with its main project. The organisation's main domain is the domain the platform treats as yours — it is the target for domain-scoped scans and the anchor for identity-exposure monitoring, so make sure it is a domain you are authorised to assess.
2. Work through the setup wizard
The wizard has three parts. It tailors everything that follows, so it is worth a few honest minutes rather than clicking through.
Your organisation profile
Four questions: where your organisation is based, what sector you are in, how big it is, and how sensitive the data you handle is. These drive which standards are recommended and how scope is narrowed — a health provider in New Zealand and a five-person startup do not get the same starting point.
The modules you want
Pick the capabilities to switch on. You can change these later under Preferences → Scan modules.
| Module | What it does |
|---|---|
| Identity exposure scan | Checks your domain for leaked credentials and identity exposure from known breaches. Passive. |
| Attack surface scan | Passively maps your main domain — subdomains, exposed services and assets. No intrusive probing. |
| Governance & compliance | Enables frameworks and a first guided assessment to measure and demonstrate your posture. |
| Policy starter set | Loads a starter library of editable security policies you can tailor and publish. |
Scanning needs your authorisation
The two scan modules run against your main domain, so enabling them asks you to confirm you are authorised to have that domain assessed. The scans are held until you do, and the acknowledgement is recorded in the audit log.
Your compliance stance
Two questions: your risk appetite, and your primary goal right now — preparing for an audit, improving posture, meeting a regulation, or demonstrating security to customers. The goal decides which task leads your checklist.
Finish with the review step to apply everything.
3. Work the first-run checklist
Applying the wizard seeds a getting-started checklist, visible on the roadmap board, in the "next up" feed and in your actions list. It is tailored: steps appear only for the modules you enabled, and the first item is chosen from your primary goal — "Prepare for your first audit", for example.
Typical order:
- Complete your onboarding profile — your answers from the wizard; reopen it any time to change them.
- Confirm your modules — the capabilities switched on for this organisation.
- Review your attack surface — discovered assets, exposed services and vulnerabilities to triage.
- Review your identity exposure — leaked credentials found against your domain, with remediation guidance.
- Review and publish your starter policies — the starter library arrives as drafts for you to tailor.
- Complete your first compliance assessment — the guided assessment. Without governance and compliance enabled, this becomes Review your security posture with the AI Sidekick over whatever you do run.
- Review your AI-derived risks — risks drafted from your findings, for you to accept or adjust.
- Map your key controls to requirements — link controls you already have to the requirements they satisfy, lifting coverage.
- Attach your first piece of evidence — back a requirement with a document, screenshot or link.
- Integrate a connector — pull posture and evidence from a cloud or identity platform automatically.
- Set your review cadence — how often to review posture; the AI Sidekick proposes a cadence and target maturity for you to approve.
Each step links straight to the feature it is about, and completes when the underlying work actually happens rather than when you tick a box.