Compliance status that arrives after the audit is too late. Archon is a configurable GRC platform for risk management, internal control and regulatory compliance. It models risks, controls, requirements, deviations and actions as one connected graph, so a single control can verify ISO 27001, NIS2, DORA and GDPR at once, criticality follows from information classification instead of being typed in by hand, and leadership sees the picture in real time. Includes a multi-level control library, maturity-based questionnaires and a full deviation-to-action workflow.
A clearance is not a document, it is a status with a start, a review date and an end. Aegis manages the lifecycle of security clearances and approval statuses for people, projects and other security-classified objects: before placement, during the assignment and at exit. Assigning, validating and renewing is automated, the information is always current, and every decision is backed by a complete audit trail. Built for organizations under the Protective Security Act and equivalent regimes.
Preparedness that lives in a separate document is out of date the day it is printed. Citadel models the war organization, critical roles and competencies, dependencies and continuity plans on the same platform as your day-to-day governance, so the picture you activate in a crisis is built from the data you already maintain. Plan the organization, exercise it, and activate it through heightened alert and ultimately war.
Central IGA stops at the boundary of the restricted zone. The fastest-growing blind spot is OT: the operational technology that runs industrial and physical processes, where identity and access are notoriously hard to govern: segmented security zones, legacy systems without modern identity protocols, shared local accounts, and equipment spread across physical sites that central IGA simply cannot reach. As IT and OT converge and regulation such as NIS2 tightens, that ungoverned OT identity becomes both a security and a compliance gap.
Atlas closes it. Rather than replacing your existing IGA, Atlas complements it, extending governed identity and access into the restricted zones and physical locations it cannot reach, with secure local onboarding and enrichment. Atlas operates where connectivity is deliberately constrained, including across data diodes (unidirectional security gateways), and the platform itself can run inside the protected network. So even organizations that run their IGA in the cloud can replace slow, manual routines in OT and other sensitive networks with governed, audited automation, where identity mistakes cost the most. The result is one identity picture across IT and OT, on the same graph as your risks and controls, with no ungoverned islands left behind.
A static CMDB is wrong within weeks. Curator turns it into a continuously curated source of truth for your systems, assets, suppliers, licenses and their dependencies, with assets ingested from your existing endpoint and inventory tools. Because the asset layer sits on the same graph as risk and compliance, you can trace a single component to the information it handles and the requirements that apply, and see at once what is affected if it fails.
Governance, risk and security information in one connected graph, running in your own environment.
Contact information