A product of Nouveau Sentinel
Home/Platform
One platform, five pillars, 20+ modules

Every module. One system of record.

Governance, Risk, Audit & Compliance, Automation & AI, and Platform Admin — 20+ integrated modules sharing the same organizations, controls, and evidence.

Governance · 5 modules · 44 items

Governance

Governance Dashboard, Framework, Policy, Organization, and Compliance — the foundation every other pillar builds on.

Governance Dashboard — C-suite ready

A single-glance executive view of governance, risk, and compliance posture, with real-time aggregate KPI tiles across every GRC pillar.

  • 1Real-time aggregate KPI tiles across every GRC pillar.
  • 2Cross-organization visibility for designated oversight entities.
  • 3Direct click-through from summary tiles to underlying detail.
  • 4Distinct views tuned for CISO, GRC Analyst, and board audiences.
Governance dashboard with Program Health, Compliance Posture, Risk Exposure Index, Response Velocity and Needs Attention panels
Main Dashboard — Global View

Framework Management

Hierarchical or flat structures; 12+ pre-loaded frameworks (ISO 27001/42001, NIST CSF 2.0, PDPL, PISF, ECC-2024, Aramco CCC, GDPR, PCI-DSS, CTDISR, SOC 2, IEC 62443); cross-framework control mapping so you implement once and satisfy many.

Unified control catalogueCustom authoring

Policy Management

Full lifecycle: draft → statements/documents → review → approve → publish → attestation. AI-assisted drafting, review and improvement suggestions, plus a shared Knowledge Center of vetted templates.

7-step lifecycleAttestation campaigns

Organization Management

9-level parent-child hierarchy for federated structures. Organizations record isolated; parents see aggregate posture while children see only their own. Multi-tenant SaaS or on-prem / sovereign deployment per entity.

9-level hierarchyTrue data isolation

Compliance & Control Management

Control implementation tracking with effectiveness ratings, auto-updated from audit test results and evidence validation. Multi-framework control reuse — one control, many standards.

Effectiveness ratingsCoverage analysis
Organization hierarchy tree with a National Cybersecurity Authority root and three child ministries
Organization hierarchy — parent authority with federated child organizations

Multi-entity organizations

A ministry, holding company, or MSSP can model every subsidiary, division, or department as its own organization record — each with isolated data and its own compliance posture, rolled up for oversight.

The compliance model

How CyGuardPro thinks about frameworks

Most GRC tools ask you to rebuild the same controls for every standard you adopt. CyGuardPro keeps controls in one place and lets frameworks point to them.

Minimalist desk with a laptop Core control catalogue

Core control catalogue

The canonical control catalogue — domains and controls you implement against. Structure ships with the product and is treated as read-only.

Colleagues reviewing a laptop screen in a bright office Regulatory frameworks

Regulatory frameworks

ISO, NIST, PDPL, regional and sector packs describe what you must achieve — mainly requirements, not a second control library.

Team gathered around a laptop in a bright office Common Elements

Common Elements

The crosswalk. Requirements map through shared concepts to the core control catalogue, so one control can support many frameworks at once.

Person reviewing a chart with a magnifying loupe next to a laptop Organization Compliance

Organization Compliance

How your company sits against the frameworks it adopted — gaps, coverage, and one-click adoption of the controls you still need.

In practice: Adopt a framework → its requirements cross-map to the core control catalogue automatically → implement each control once → every mapped requirement inherits that implementation's status and evidence → Organization Compliance shows the resulting posture.
Organization Compliance

Domain-by-domain compliance, at a glance

Compare compliance percentage across every adopted framework, then drill into domain-level status — strong, moderate, needs improvement, or critical — right down to individual requirements.

  • 1Cross-framework compliance percentages shown side by side.
  • 2Domain-wise, requirement-wise, and framework-specific views.
Framework compliance bars across ISO 27001:2022, PDPL, ECC-2024, Aramco CCC, NDMO and more, with a domain-wise breakdown
Organization Compliance — framework comparison and domain drill-down
Content packs

Frameworks supported out of the box

12+ pre-loaded frameworks span international standards, regional mandates, and sector-specific requirements, with 100+ additional frameworks ready to be ingested on the go as your organization's requirements evolve. Custom framework authoring covers anything not yet in the catalogue.

ISO/IEC 27001:2022
ISO/IEC 42001:2023 (AI)
NIST CSF 2.0
PDPL — Saudi Personal Data Protection Law
PISF
ECC-2024 (Saudi NCA)
Aramco CCC
GDPR
PCI-DSS
CTDISR
SOC 2
IEC 62443
Control implementations

From adoption to verified control

A control implementation is your organization's live working record for a catalogue control — scope, status, effectiveness, evidence, and approval, all in one place.

1
Adopt framework
2
Create implementations
3
Set scope & owner
4
Attach evidence
5
Submit for approval
6
Approve & verify

Scope & status

Mark each control in-scope or out-of-scope with a required justification, then track implementation status, effectiveness rating, and current / target maturity level.

Evidence & coverage

Link evidence, mapped assets, related risks, and policies directly from the control implementation workspace — the same record auditors review.

Governed approval

Submit for approval, approve, return, or verify according to your organization's governance rules — with a full workflow position summary at every step.

Policy Knowledge Center with approved policy template categories including Cybersecurity & Data Privacy Governance and Asset Management
Policy Knowledge Center — adopt approved templates in seconds
Policy lifecycle

Draft, approve, publish, attest

Adopt a vetted template from the shared Knowledge Center, or draft locally with AI assistance. Either path follows the same seven-step lifecycle through to staff attestation.

1
Create
2
Statements
3
Documents
4
Review
5
Approve
6
Publish
7
Attest
Risk · 5 modules · 41 items

Risk

Risk, Asset, Vendor, Incident, and Exception — identify what could go wrong, where it lives, and what you're doing about it.

Team discussing a project around a laptop Risk Management

Risk Management

Four risk origins — framework, control, custom/business, and catalog. Automated residual risk recalculation on every mapping change, probability × impact mapping, and a relationship map. 3,000+ risk library, 7,000+ threat & vulnerability catalogue.

Laptop and monitors on a bright desk Asset Management

Asset Management

Three asset types — devices, data assets, software assets — with dependency chains and CIA classification aligned to FIPS 199, NIST, ISO 27001, and NATO. Risk auto-propagates to dependents via signal automation.

Person reviewing a printed document with a pen Vendor (TPRM)

Vendor (TPRM)

Vendor registration and categorization by type and risk level, assessment workflow with scoring and status tracking, API integration for automated sync, and contract lifecycle tracking with approval workflow.

Hands typing on a laptop in a bright minimal office Incident Management

Incident Management

Full lifecycle: Detected → Triaged → Investigating → Contained → Resolved → Closed, with incident-to-risk and incident-to-control mapping, timeline tracking, and lessons-learned documentation.

Team gathered around laptops in a bright office Exception Management

Exception Management

Four exception types — Control, Policy, Risk Acceptance, and Temporary Waiver. Approval workflow via the generic Workflow Engine, expiry tracking with renewal management, and risk justification tied to policy/control references.

Risk Management Dashboard showing total risks, risk severity, control coverage and risk health
Risk Management Dashboard — Global View
Asset Dependency Map connecting devices, data assets and software with visual relationship lines
Asset Dependency Map — devices, data assets, and software
Risk management

Library → Register → Assessment → Treatment

A 3,000+ risk library and 7,000+ threat & vulnerability catalogue mean most programs adopt known risk scenarios rather than authoring every one from scratch.

1
Adopt from Library
2
Register risk
3
Assess (P × I)
4
Treatment decision
5
Map controls
6
Monitor residual
How treatment works: when a risk assessment's decision is Mitigate, the risk is mapped to core catalogue controls. Residual risk is recalculated automatically as those controls' implementations mature — mapping a control is not the same as mitigating the risk until it is actually implemented and evidenced.
Asset Management dashboard showing total assets, asset value, data classification levels and control implementation progress
Asset Management Dashboard
Asset-aware risk

Risk that knows what it's protecting

Devices, data assets, and software assets carry CIA classification aligned to FIPS 199, NIST, ISO 27001, and NATO standards. When an asset's risk changes, it propagates automatically to everything that depends on it.

  • 1Three asset types with dependency chains between them.
  • 2Risk auto-propagates to dependents via signal automation.
Third parties, incidents & waivers

Risk doesn't stop at your own perimeter

Vendor risk register

Register and categorize vendors by type and risk tier, run assessment workflows with scoring and due dates, and track contract lifecycle with approval workflow. Vendor assessment findings feed the same Unified Findings spine as every other source.

Vendors list showing vendor number, name, organization, type, risk tier and contact
Vendor register — filterable by organization, type, risk tier

Full incident lifecycle

Detected → Triaged → Investigating → Contained → Resolved → Closed, with a timeline of events, response actions, artifacts, incident-to-risk and incident-to-control mapping, and lessons-learned capture before closure.

Incident Management Dashboard Global View with total incidents, high/critical, response and resolution metrics
Incident Management Dashboard

Governed exceptions

Four exception types — Control, Policy, Risk Acceptance, and Temporary Waiver — routed through the workflow engine for approval, with expiry tracking and a bounded renewal process (up to three renewals, opened only within 90 days of expiry).

Exception Management Dashboard Global View with total exceptions, residual risk accepted, approval pipeline and renewals
Exception Management Dashboard
Evidence Integrations list showing OCI Cloud Tenancy, AWS Test Account, Jira Service Management, Microsoft 365 Compliance Center and Splunk SIEM Integration with health status
Evidence Integrations — automated collection with health monitoring
Evidence integrity

Evidence that can withstand an audit

Evidence and support attachments carry MD5 and SHA-256 checksum fields, with automatic hashing on save and SHA-256 fallback at audit link time — so what an auditor sees is provably what was collected.

  • 132 automated collectors across AWS, GCP, Azure, GitHub, Microsoft 365 and Okta.
  • 2Confidentiality and access-level flags on every evidence artifact.
Platform security

How the platform protects itself

Engineering controls documented for evaluators — presented plainly, without overstating what has and hasn't been formally certified.

Access control

Transport & storage

Monitoring & lockout

Auditability

Audit & Compliance · 4 modules · 28 items

Audit & Compliance

Audit, Evidence, Findings, and GDPR — run the audit, prove the control, close the loop.

Audit Management

Full lifecycle — Planned → In Progress → Review → Closed. Automated weighted compliance scoring from test results, AI-predicted completion date and finding likelihood, recurring audit auto-scheduling, and HTML/PDF report generation.

Evidence Management

Evidence-to-control mapping, auto-created on save; AI-assisted validation against defined test rules; automated cloud evidence collection (AWS and more); centralized artifact storage with audit-ready traceability.

Unified Findings

One finding record type, aggregated from every source across the platform — audits, risk assessments, incidents, and vendor assessments. Full lifecycle from open through verification and closure.

GDPR Management

Data subject rights, 72-hour breach notification workflow, DPIA management linked directly to processing activities, and Record of Processing Activities (ROPA) per Article 30 — with an admin portal for DPOs and a public portal for data subjects.

Audit Workspace for PEMRA Compliance Audit showing phase progress, scores, compliance and test coverage
Audit Workspace — plan, test, report, remediate, close
GDPR Management Dashboard with active data breaches, pending requests and processing activities
GDPR Management Dashboard
The audit lifecycle

Six phases, one workspace

Every audit sits in a phase shown as a progress strip, with a readiness checklist gating each advance.

1
Plan & Scope
2
Control Tests
3
Findings & Report
4
Remediation
5
Monitoring
6
Closed
Fieldwork

Control testing, with AI as a starting point — never the final word

Record method, sample, result, and effectiveness for every control test. AI Auto-conduct proposes results for untested controls so testers review rather than start from a blank page.

Structured test records

Test method (inquiry, inspection, observation, re-performance), sample & population size, tester, date, and detailed results — all against the control's official guidance.

AI Auto-conduct

Proposes a result for each untested control, labelled by source (AI-assisted or heuristic). Testers review and accept only what they agree with — the tester remains responsible for every recorded result.

Coverage tracking

See every framework requirement's status — in scope and tested — before leaving fieldwork, so gaps surface early instead of during reporting.

Findings Dashboard showing total, open, escalated, awaiting verification and corrective action due counts
Findings Dashboard — one register for every source
Unified Findings

Every finding, one lifecycle

Findings raised from failed control tests, risk assessments, incidents, or manual entry all follow the same remediation path — from intake to independently verified closure.

1
Open
2
Assigned
3
In progress
4
Resolved
5
Verified
6
Closed
Report categories

Findings map straight into the audit report

CategoryMeaning
Major NCMajor non-conformity
Minor NCMinor non-conformity
ObservationNoted, not a non-conformity
OFIOpportunity for improvement
ExcludedNot reportable in this audit
Governance

Configurable verification and closure

Finding Governance controls how Resolved → Verified and Verified → Closed work — self-verification for lower-risk items, or an independent verifier workflow for anything that needs a second set of eyes.

  • 1Self-verify when governance allows it, with an attested date recorded.
  • 2Critical findings with incomplete corrective actions block audit closure until resolved.
Finding Governance screen showing verification approval and closure approval rules per organization and module
Finding Governance — verification & closure rules
Reporting

Draft, sign off, publish

StatusWhat happens next
DraftSubmit for sign-off — requires at least one recorded control test result
Under reviewAssigned approver acts from their My GRC Work inbox — Approve & sign off or Reject
ApprovedLead auditor publishes the report
PublishedFinal record for the audit engagement
Closure gate: critical findings whose corrective actions are not completed or verified block audit closure. Non-critical open findings do not block closure — they stay tracked under their owners for remediation.
Automation & AI · 3 modules · 29 items

Automation & AI

AI Admin, Tasks, and Analytics — one automation layer working across every module: 13+ AI features and 21 signal-driven automations.

Hands typing on a MacBook in a bright minimal room Asset Discovery

Asset Discovery

Batch ingestion with MAC / IP / fingerprint identification, staged for review before promotion into managed inventory.

Overhead view of a team collaborating with a laptop and charts Evidence Integration

Evidence Integration

32 collectors across AWS, GCP, Azure, GitHub, Microsoft 365 and Okta — automated evidence collection from cloud, code, and identity systems.

Team reviewing a laptop and charts in a bright meeting room AI Document Handlers

AI Document Handlers

Evidence classifier, policy conformance checking, and narrative generation — every AI output stays reviewable before it counts.

Close-up of hands typing on a laptop Gap Assessment

Gap Assessment

Instant gap-to-target analysis across any framework, comparing current control implementation against the standard's expectations.

Laptop displaying a secured network status Auto Control Implementation

Auto Control Implementation

Scanner-driven control status and effectiveness updates that keep implementation records current as evidence changes.

Team reviewing documents together at a table Signal-Driven Auto Workflows

Signal-Driven Auto Workflows

21 automations running silently across every module — from evidence expiry reminders to control status recalculation.

Task Management Dashboard showing total tasks, priority and risk, completion and performance, and budget and hours
Task Management Dashboard — priority, performance, and budget across the organization

Task & Workflow Management

One generic workflow engine driving approvals and automation across every module — Policy, Exception, Finding, Audit, Vendor and more, all from a single "My GRC Work" inbox.

  • 1Sequential and parallel step execution.
  • 2Four actions on any workflow step — Approve, Reject, Delegate, Escalate.
  • 3Unified work inbox — every pending task, one place.
My GRC Work personal inbox listing pending tasks and workflow approvals
My GRC Work — the personal operational inbox

Analytics & Reports

Cross-organization analytics with 49+ interactive, click-through charts across every major GRC module, drawn from real-time backend aggregation APIs.

  • 1Cross-org deep-dive and side-by-side comparison.
  • 2Every chart element is clickable to filtered detail.
  • 3Real-time data from backend aggregation APIs.
Cross-Organization Analytics comparing organizations by compliance score and risk exposure
Analytics & Reports — cross-organization comparison
Platform Admin · 5 modules · 80 items

Platform Admin

Admin, Lookup, Billing, Platform Setting, and Support Centre — the operational backbone of the platform.

Users & Roles (RBAC)

500+ fine-grained, module-level permissions. Create users, assign organization + role combinations (including multi-organization access), and build custom roles with a live navigation preview.

Lookup Management

Centralized lookup and configuration management for the dropdown values, categories, and classifications used across every module.

Billing

Billing and subscription management with annual or manual billing plans, invoices, and payment methods.

Support Centre

Built-in support center with SLA-based ticketing, cross-organization visibility, and ticket-to-task linking.

Users list showing system users, email, organization and assigned roles
Users — organization-scoped accounts and role assignments
Roles list showing system roles, descriptions, and organizations they apply to
Roles — named permission packages, not per-user settings
Users & roles

500+ fine-grained, module-level permissions

Create users, assign organization + role combinations — including people who work across more than one organization — and preview exactly what a role's navigation will look like before rolling it out.

Multi-organization access

People with more than one organization or role are asked to choose a context at sign-in — the menu and permissions follow the context they pick.

Bulk import

Import many users at once from a template spreadsheet — with role codes, organizations, and welcome-email delivery handled automatically.

Navigation preview

Review exactly how the side menu will look for a new role before assigning it to a whole department.

CyGuardPro AI AssistantDocumentation assistant

Ask me about CyGuardPro's features, controls, frameworks, or how to use the platform. I answer from the official CyGuardPro documentation.