How it works
How Dashboard, AI Sidekick, Assets, Exposure, penetration tests and assessments, Governance, Risk, Compliance, Actions, Activity and Preferences connect into one continuous loop. Read once to see how the platform fits together.
None of the platform's screens work in isolation. A single task, like approving one proposal, can easily touch several of the areas below in one go. This page walks through the whole loop, in the order it sits on screen, so everything else on this site becomes easier to place. The AI Sidekick acts as an ongoing vCISO for your organisation as part of that loop, not a one-off report.
Dashboard
What it's for: your entry point and pulse-check. Everything the rest of the loop produces surfaces here as current state and trend.
Where it sits in the loop: nothing feeds it directly; it's what you read, not what you do. Every other area below eventually shows up here.
See also: Dashboard.
AI Sidekick
What it's for: the vCISO persona itself. Ask it anything about your posture, and it's also where AI-drafted proposals get their start.
Where it sits in the loop: draws on the context from everything below to answer questions and to draft what shows up in Actions.
See also: AI Sidekick.
Assets
What it's for: the inventory of what you have (networks, identities, apps, devices and data).
Where it sits in the loop: the foundation the exposure side is built on. Every finding is recorded against an asset, and the risks promoted from those findings trace back through them.
See also: Assets.
Exposure
What it's for: vulnerabilities, identity exposure and configuration findings against that inventory.
Where it sits in the loop: takes its input from Assets, and its findings are what Risk and Actions work from next.
See also: Exposure.
Penetration tests and assessments
What it's for: a scoped piece of testing a person does — its scope, window, team, findings and the report you hand over. Called an engagement in the navigation.
Where it sits in the loop: findings you report here join the same pool Exposure fills, so Risk and Actions work from both without caring which of the two found something.
See also: Penetration tests & assessments.
Governance
What it's for: the policies and standards your organisation has committed to.
Where it sits in the loop: sets the frame Compliance gets assessed against, independent of whatever Exposure happens to find.
See also: Governance.
Risk
What it's for: the register where compliance gaps and exposures become tracked, scored risk.
Where it sits in the loop: pulls from both Exposure and Compliance, and is usually what a proposal in Actions is trying to reduce.
See also: Risk.
Compliance
What it's for: assessments against the standards enabled in Governance, covering coverage, maturity and control mapping.
Where it sits in the loop: feeds Risk with gaps, and is one of the two main sources, alongside Exposure, that Actions drafts proposals from.
See also: Compliance.
Actions
What it's for: where a gap or a finding becomes one concrete, specific proposal, and where a person approves, adjusts or rejects it.
Where it sits in the loop: the gate most changes from Exposure, Compliance and Risk pass through before they take effect.
See also: Actions.
Activity
What it's for: the record of scans that have run and are running, showing what the platform has been doing rather than who approved what.
Where it sits in the loop: what re-runs everything. A new scan here is what refreshes Assets and Exposure for the next pass.
See also: Activity.
Preferences
What it's for: your organisation profile, risk appetite, review cadence and the document variables Governance's templates pull from, set during your first hour and revisited as things run.
Where it sits in the loop: not in the data flow. It sets the context the rest of the loop is assessed and reported against.
See also: Preferences.
Activity's next scan is what starts the loop over. A fresh pass refreshes Assets and Exposure, and everything above runs again from there.