01 /Governance · Risk · Compliance

Structure matters.
The control plane for
modern compliance.

VigiliaRes turns scattered policies, audits, and control evidence into a single, defensible architecture. Run maturity assessments, quantify risk by domain, and hand auditors a paper trail they can actually follow.

Assessment frameworks
17
Avg audit prep
−74%
Control evidence
Continuous
Tenancy
Isolated
/ Trusted by risk teams at
Northwind Bank
Halberd Health
PARALLAX·LABS
Sentinel Mutual
Civica.gov
PIER·9 / FIN
02 /The problem

A binder full of screenshots is not a control framework.

Most compliance programs run on heroics — a spreadsheet maintained by one analyst, a folder of evidence saved “just in case,” a dashboard that nobody trusts the day before an audit.

When the auditor asks why, your team scrambles to reconstruct decisions made eighteen months ago. When the board asks how exposed are we, you give a number with a shrug behind it. There is no system of record. There is only memory.

03 /What it is

One platform.
Four disciplines.

VigiliaRes consolidates the four working surfaces of a modern GRC program into a single, role-aware workspace. Built for the people doing the work — assessors, control owners, internal audit, and the CISO at the top of the chain.

01 / GOVERNANCE

Policy as a graph.

Map controls to frameworks, frameworks to risks, risks to business units. Edit once; propagate everywhere. Version the whole structure.

02 / RISK

Quantified, not guessed.

Score risks across domain, control area, and impact. Roll up to a board-ready number; drill down to the line item that moved the dial.

03 / COMPLIANCE

Evidence, on a timeline.

Continuous evidence collection from your existing stack. Every artifact is dated, attributed, and linked to the control it satisfies.

04 / ASSURANCE

Audits without archaeology.

Hand auditors a read-only workspace scoped to their engagement. Questions land in a queue; answers ship with the receipts attached.

04 /The wizard

Assessments that read like a conversation, not a quiz.

Six control areas, weighted questions, four answer types, automatic evidence attachment. Maturity scoring follows ISO 33020 conventions out of the box.

app.vigiliares.com / grc / assessments / 2026-Q2-iso27001
Q · 7 / 14 · Cryptography · CRY-07

Are cryptographic keys managed through their full lifecycle — generation, distribution, storage, rotation, and destruction — under documented procedure?

Reference: ISO/IEC 27001 A.10.1.2 · NIST SP 800-57 §5.3

Required
RESPONSE · SCALED
Non-existent
Weak
Developing
Managed
Optimised
Score 0Score 100
EVIDENCE · 3 ATTACHED
+ ATTACH
kms-rotation-policy.pdf2026·04·12
aws-kms-config-export.json2026·05·01
quarterly-key-audit.csv2026·05·06
← Q06 · DATA ENCRYPTION AT RESTSave & continue
05 /The score

One number for the board.
Six lenses for the team.

Maturity rolls up cleanly. But it never disconnects from the question that produced it — every dot on this dashboard is one click from its evidence.

OVERALL · 2026 Q2
68
/ 100
Managed+8 vs 2026·Q1
TREND
2024·Q32026·Q2
BY CONTROL AREA
Identity & Access
84
Optimised
Asset Management
72
Managed
Cryptography
65
Managed
Operations Security
54
Developing
Comms Security
60
Developing
Supplier Relationships
38
Weak
06 /Frameworks

Mapped to the canon.

Seventeen framework libraries shipped, kept current by our content team, and extensible for sector-specific overlays. Map a single control to many frameworks — answer once, satisfy many.

ISO 27001
A · 14 ANNEXES
SOC 2
5 · TSC
NIST CSF 2.0
6 · FUNCTIONS
PCI DSS 4
12 · REQS
HIPAA
SEC + PRIV
DORA
EU · 2025
GDPR
DPA · ART. 32
CIS v8
18 · CONTROLS
FedRAMP
MOD + HIGH
HITRUST
CSF · v11
ISO 27701
PIMS
+ 6 more
VIEW ALL →
07 / From the field
“We replaced four spreadsheets, a SharePoint site, and a third-party questionnaire vendor with VigiliaRes. The first audit cycle that followed ran half as long with twice the confidence.”
Marielle Okafor
VP, INFORMATION SECURITY · NORTHWIND BANK
Next step

See VigiliaRes against your own control set.

A 30-minute working session with an architect — bring your current framework, leave with a structural read of where the gaps are.