Introducing

The command center for cyber risk.

Turn Microsoft 365, AWS, GCP, and Oracle Cloud posture into a live CMDB — score ISO 27005 / NIST RMF risks, generate policies and PCI DSS / ISO 27001 / SOC 2 evidence, and run ITIL change control from one register.

ISO 27005 assessment

Live

Threat identification · 5×5 heatmap

68% scored42 risks
3 critical 18 treated
Light and dark modes supported
Frameworks
10 in the library
Clouds
M365 · AWS · GCP · OCI
Change
ITIL change control · CMDB
Assets
Assessments
Risks
Policies
Evidence
Reports
ISO/IEC 27005ISO 27001:2022PCI DSS 4.0SOC 2Microsoft 365AWSGCPGoogle WorkspaceISO/IEC 27005ISO 27001:2022PCI DSS 4.0SOC 2Microsoft 365AWSGCPGoogle Workspace
Product · AI VCISO

Everything a risk program needs. Nothing a spreadsheet deserves.

AI VCISO is Secentic's command center: inventory, assess, treat, and report — with live signals from the clouds you already run.

Compliance evidence workbench

Enable a standard pack — PCI DSS 4.0 (~238 requirements), ISO 27001:2022, ISO 27701, or SOC 2 — and work every requirement: assign teams, attach evidence files, track checklists, and watch the compliance percentage climb.

AI policy generator

Pick from the policy catalog, answer two smart intake questions, and get a full drafted policy with rendered preview and PDF/HTML export.

vCISO strategy plans

Run a CISO maturity assessment, answer AI follow-up probes, and generate a one-year plan: gaps, Q1–Q4 roadmap, quick wins, KPIs, and budget — exported as a board-style PDF.

Ask Secentic assistant

Chat over your own org data — assets, risks, policies, posture. Inbound vendor questionnaires get AI-drafted answers with per-answer confidence.

Continuous security score

Microsoft 365, Entra, Intune, Defender, and Google Workspace posture on autopilot: scheduled syncs, snapshot history, drift alerts, and automated control tests.

AI that actually finishes the register

Analyze assets, score likelihood and impact, and draft treatments in one pass. Review every finding — the model never silently owns your risk posture.

ITIL change enablement

Register every change — standard, normal, major, or emergency, across IT, cloud, network, identity, suppliers, policy and facilities. Configurable CAB approval quorums, freeze windows and SLA escalation, execution checklists, go/no-go, an emergency fast-path, post-implementation reviews, and a CI/CD deploy gate.

CMDB with impact analysis

Assets become configuration items on a typed relationship graph. See the blast radius and affected services before a change, catch shared-CI collisions and freeze-window conflicts, and spot stale or retired CIs from cloud discovery.

AI governance register

Inventory every AI system with purpose, owner, and data class; get deterministic risk tiers and a 12-control governance review score.

Scoring you can defend

Transparent 5×5 heatmaps, residual risk, and treatment status — the language CISOs and auditors share.

Integrations

Pull the estate. Derive the risk.

Stop retyping inventories. Connect the clouds you already operate and let Secentic turn posture into scored, treatable work.

Microsoft 365

  • Secure Score as a living risk signal
  • MFA coverage and Conditional Access gaps
  • Defender alerts turned into register items

Amazon Web Services

  • EC2 instances pulled as assets
  • RDS databases in the inventory
  • S3 buckets ready to assess

Oracle Cloud

  • Compute instances from the tenancy
  • Autonomous Database records
  • Object Storage namespaces

Google Cloud Platform

  • Compute Engine instances as assets
  • Cloud SQL databases in the inventory
  • Cloud Storage buckets ready to assess

Google Workspace

  • Domain-wide delegation via service account
  • 2SV coverage and admin-audit signals
  • Workspace posture folded into the score

Entra ID

  • Identity posture from the same tenant
  • Risk signals folded into monitoring
  • No extra connector to maintain

Change & CI/CD

  • GitHub, GitLab, Azure DevOps and Bitbucket
  • Deploy gate blocks unapproved or frozen releases
  • Snyk, PagerDuty, CloudTrail, Okta and Datadog evidence
How it works

Four moves. One defensible program.

  1. 01

    Connect

    Microsoft 365, AWS, GCP, Oracle Cloud, and Google Workspace posture and inventories sync into one workspace.

  2. 02

    Assess

    Run ISO 27005 / NIST RMF assessments. AI proposes scored risks — likelihood × impact on a defensible 5×5 heatmap.

  3. 03

    Operate & change

    Generate policies, work PCI DSS / ISO 27001 / SOC 2 evidence packs, and run ITIL change control on a live CMDB — CAB approvals, freeze windows and blast-radius impact before anything ships.

  4. 04

    Prove

    Board-ready PDFs, a forward schedule of change, post-implementation reviews, per-framework evidence bundles, a public trust center, and an immutable audit trail — all from the same live data.

Frameworks

Speak ISO, PCI, SOC 2, and NIST without switching tools.

ISO/IEC 27005

Risk management for information security

Context, asset identification, risk analysis, evaluation, and treatment — the full 27005 loop, with a 5×5 heatmap your ISMS can actually defend.

Compliance evidence packs

PCI DSS 4.0 · ISO 27001 · ISO 27701 · SOC 2

Enable a pack with scope and certification period and work the full requirement tree — evidence, assignees, checklists — toward an auditor-ready percentage.

NIST RMF · CSF 2.0

Prepare, categorize, select, assess, authorize, monitor

Run RMF-aligned assessments and carry residual risk into treatments and reports so federal and enterprise programs stay on the same register.

Framework library — policy coverage tracked per framework

ISO 27001:2022 · NIS2 · DORA · PCI DSS 4.0 · SOC 2 · NIST CSF 2.0 · Egypt DPL 151/2020 · NCA ECC · SAMA CSF · UAE PDPL

Frequently asked questions

Open AI VCISO

See every risk before it becomes an incident.

Create an organization in minutes. Connect a cloud later. The register does not wait on a six-month GRC rollout.

Free plan included · per-organization licensing when you scale

Read the documentation →