Skip to content

Technology and SaaS

Ship fast and still answer the security questionnaire.

Your estate changes daily, your engineers adopt AI tools before anyone reviews them, and your customers audit you as a condition of the contract.

The pressure

Pressures specific to this sector

Every sector has pressures. These are the ones that change what a security programme is allowed to do here.

  1. An estate that changes faster than any inventory can track.

    A quarterly inventory describes a company that no longer exists by the time it is signed off.

  2. Engineers adopting AI coding tools ahead of any policy.

    By the time the policy exists, a year of usage has already happened without one.

  3. Customer security reviews arriving as a condition of renewal.

    A questionnaire is a revenue event with an engineering cost attached, and it arrives with a deadline.

  4. A small security team supporting a much larger engineering org.

    You are outnumbered, so anything that needs a person per instance does not scale past this quarter.

The constraint

The constraint

An answer that was true last quarter is not an answer, because the company it describes no longer exists.

Frameworks

What you are measured against, and what we actually do about it.

Two states, and they are not the same thing. The cards say which is which rather than listing every framework at the same weight.

  • ISO/IEC 42001

    Scored

    Coverage computed from what AI Guardian detects in usage telemetry. It attests only the controls telemetry can satisfy and says so about the rest.

  • OWASP LLM Top 10

    Scored

    The 2025 list, scored on what Guardian actually detects and responds to, including prompt injection and sensitive-information disclosure.

  • EU AI Act

    Scored

    The deployer obligations Guardian attests under Regulation (EU) 2024/1689, such as AI system identification and record-keeping of system logs.

  • CIS Controls v8

    Scored

    153 safeguards scoped to your cloud footprint and service models, so cloud-specific safeguards apply only where they are relevant.

  • ISO 27001

    Evidenced

    No agent assesses it. The control evidence collected for CIS and CSF is the same evidence an ISO audit asks to see.

  • SOC 2

    Evidenced

    No agent assesses it. SOC 2 Readiness is scoped and documented but has not shipped, so it is named on this page and nothing more.

Scored means an agent assesses that framework control by control and produces a maturity score and a gap register. Evidenced means no agent assesses it: what the platform contributes is the audit trail and the control evidence a reviewer asks to see. Neither is a compliance certification, and framework mapping is a control-evidence aid rather than a legal opinion.

The answer

How the platform works around it.

Three movements, in order. The constraint above is restated in each of them, because it is what makes this sector's version different.

  1. See

    A live estate

    Cloud, identity and code-assistant signal read continuously rather than inventoried periodically, GitHub Copilot usage included, normalised and enriched in under five milliseconds.

  2. Decide

    Exposure that reflects reality

    Known-exploited status, exploit probability and reachability, so the queue matches your risk today rather than a severity field written last quarter.

  3. Act

    Evidence for the questionnaire

    Framework scoring runs continuously and AI governance is evidenced from what is actually detected, so a customer review is an export rather than a project.

Questions

The things this sector asks first.

  • How does it keep up with an estate that changes daily?

    It reads continuously rather than inventorying periodically: cloud, identity and code-assistant signal normalised to one schema and enriched with asset context in under five milliseconds. Where a feed degrades, the records it backs are marked stale rather than quietly served as current.

  • Can we govern AI coding tools without blocking engineers?

    Discovery first, then policy. The inventory catalogues every AI tool in use, sanctioned or not, with a risk score and an owner, and enforcement is per tool, per group and per data class. GitHub Copilot is a first-class telemetry source rather than a domain to block.

  • What does a customer security review actually become?

    An export. The CIS and CSF assessments carry the score, the per-control breakdown, the findings and the remediation roadmap, with the scoping decisions recorded. What it does not become is a claim of certification: that is still your auditor's call.

  • Is SOC 2 covered?

    Not by an agent. SOC 2 Readiness is scoped and documented but has not shipped. The honest position is that the evidence the shipping assessments collect overlaps heavily with what a Trust Services Criteria review asks for, and nothing more than that.