These are the questions that come up in almost every first conversation. Where the answer is uncomfortable, it is still the answer.
There is no rate card. Every engagement starts with a due diligence review, and the scope that review establishes decides the price. We quote in writing once we know what is actually in scope. The pricing page sets out the three tracks and what each includes.
No, but most organisations do, because it is the cheapest way to replace an assumption with a documented position. If you already know your scope, the strategic advisory track can begin with the due diligence review instead.
Portal access follows the approval of your request, which is a human decision rather than an automated one. An assessment can be completed as soon as access is granted. An advisory engagement begins on an agreed date after the proposal is accepted.
The advisory practice is led personally, which is the point of it: you engage a named accountable person carrying CIO and CISO responsibility, not an account manager routing you to a delivery pool. The About page sets out the position in full.
Not all of them. Each product carries a stage marker on the Products page: simulation, MVP in development, or preview and hardening. We publish the stage rather than a version number, because a version number implies a shipped release. Products are provisioned to an organisation individually when they are ready for that organisation's use.
The control library carries fifteen frameworks spanning international standards and the GCC regulatory set, including ISO 27001, SOC 2, NIST 800-53, GDPR, UAE PDPL, NESA, ADHICS, Dubai ISR, CBUAE, SAMA CSF, NCA ECC and the regional privacy laws. Cross-framework mapping is mature for a subset of these; the Frameworks page states the position for each one rather than implying uniform depth.
Where the mapping supports it, yes, and that is much of the value of a shared control library. It is not universal. Two frameworks may ask a similar question and still require different evidence, and we do not present a mapping as satisfied coverage. The mapping shows the relationship; an auditor decides whether the evidence answers it.
No, and no platform can. We prepare you for certification and we facilitate the audit. The affirmation comes from an external auditor or certification body. Any platform that tells you it has certified you has misunderstood what certification is.
The application and its database are hosted in Frankfurt, in the European Union. Our sub-processor register names every third party with access to customer data and the purpose of each.
It requires the transfer to be handled properly rather than ignored. UAE PDPL permits cross-border transfer where appropriate safeguards are in place, and the Data Processing Agreement sets out those safeguards. If your regulator requires domestic residency for a specific dataset, tell us during scoping, because that changes the design rather than the paperwork.
Yes. Assessment results, control mappings, evidence records and reports are exportable in open formats. Leaving should cost you effort, not your history.
Yes. You may request deletion of your organisation's data, and the Data Processing Agreement sets out the process and the retention periods that apply where a record must be kept for legal reasons.
Your organisation's users, according to the role you assign them, and our staff only where support requires it and the access is recorded. Audit trails are written as work happens rather than reconstructed afterwards, which means access is visible to you as well as to us.
A structured report: a maturity position by domain, what is in place, what is missing, and a prioritised order of remediation. The priority order is the part that matters. An undifferentiated list of gaps tells you nothing about what to do on Monday.
Yes. You answer for your own organisation, and the report reflects what you reported. It is a structured statement of position, not an audit finding, and it is presented as such throughout.
Yes, and that is the intended use. Results are retained in your portal so a later run can be compared against an earlier one, which is how you evidence direction of travel to a board.
No. It means your reported position against that instrument is strong. Compliance is affirmed by a regulator or an auditor, against evidence, at a point in time. We are careful about this distinction because the alternative is selling false comfort.
Ask it directly. A question that is difficult to answer publicly is usually the one worth asking.