Home / Core / Features

Core · features

Everything Core does, in one place.

Core is organised around three needs: see what you run and who you rely on, keep watch over it, and spend where the risk comes down most. This is the full list, in the terms a reviewer will check it against.

See plans, from free →

01 · Visibility

One record of what you run and who you rely on

Incomplete or inconsistent information about services, suppliers and their controls means protection that misses and response that starts late.

IT services

  • Internal and third-party IT service assessments
  • Data types and data classification
  • RTO and RPO, and CIA ratings
  • Platform, hosting and ownership
  • CMDB references and tiering
  • An architectural view of each service

Organisation and suppliers

  • Enterprise, business unit and business process records
  • Supplier corporate, contract, sizing, financial and insurance data
  • Supplier tiering
  • Entity-level risk and control assessments
  • External scorecards recorded against suppliers

Frameworks, controls and evidence

  • Framework, control and policy library
  • Load your own frameworks alongside the standard ones
  • Custom fields and lists in every function
  • Evidence attached to suppliers, services, risks and controls
  • Documents searchable across the whole account

02 · Vigilance

Assess once, keep it current, see it at every level

A backlog of assessments across several frameworks leads to inconsistent advice, missed obligations and risk nobody is managing.

Assessments

  • Design and operating effectiveness, maturity and compliance
  • Any scope — enterprise, unit, process, IT service, supplier — and any period, with history
  • Every framework vectorised on Oracle AI Database 26ai, so controls match across them automatically
  • Assess once, and carry the result to every other framework
  • Uploaded documents read by AI, and drafted into the assessment
  • Statement of Applicability at any level of the organisation

Questionnaires

  • Questionnaire Builder, with question libraries for any framework
  • Simple or audit-grade questionnaires from one framework or several
  • A responder portal, free and unlimited for respondents
  • Evidence upload, reminders and bulk import
  • Evidence documents read by AI, and drafted into findings for review
  • Observations and findings recorded against each response

Risk and workflow

  • Risk and issue registers at enterprise, unit, process and service level
  • Configurable risk matrices; actions with history
  • Issues raised automatically from failed controls
  • Aggregate up the organisation, or cascade down to suppliers and services
  • Workflow Builder and predefined workflows, with tasks, forms, email, reminders and an audit trail

03 · Value

Spend where the risk comes down most

Remediation set by vendor roadmaps rather than business risk loses the business's attention and the budget's return.

Scenarios

  • Scenario Builder: actor types and motivations
  • MITRE ATT&CK tactics and techniques
  • The data types and critical services each scenario touches
  • MITRE ATT&CK simulation on a service's architecture

Quantification

  • FAIR, with the Open FAIR algorithms or your own financial and statistical models
  • Projected and actual risk by scenario and period, with the options considered
  • Risk bought down, measured each assessment period

Control what-if

  • The effect on risk of one control change, or a group of them
  • Ranked by key-control weighting, MITRE simulation, scorecards or control analytics
  • The return on each option, and the best order to make them in

Platform

What sits underneath

Data and integration

  • Full referential integrity; a rename carries to every linked record
  • CSV import on every form
  • CSV, Excel, PDF and PowerPoint export
  • REST APIs and Office 365
  • Optional Oracle Integration Cloud, with over 400 adapters

Hosting and security

  • Oracle Autonomous Database, in Oracle Cloud's Sydney region
  • Delivered as a service: you need nothing from Oracle, and no Oracle licence or skills, to use it.
  • TLS 1.2 in transit; encrypted at rest
  • Immutable backups
  • Web application firewall
  • Separate development, test and production

Access and tenancy

  • Sign in with your Google or Microsoft tenancy, and its MFA
  • Role-based access with custom roles, down to screen region
  • Sub-accounts per engagement for consultants and partners
  • The assistant built into every page
  • Licences only for the people who run risk and compliance
  • Dashboards for each functional area; deeper reporting through Power BI or Oracle Analytics

Not in Core today

Said up front, so it is not found later

  • Key risk indicators (on the roadmap)
  • Skip logic in questionnaires (on the roadmap)
  • SAML and SCIM as standard; SAML and LDAP today as customisation
  • Incident management
  • Full policy lifecycle

See it on your own frameworks

Start on the Free Tier, or map your current records into Core with an Opportunity Scan.