Built for groups where security is one function and the estate is not
Nine hospitals, twelve terminals, three subsidiaries with their own DNS. Enterprise scoping lets each part run its own programme while the group sees one number it can defend.
- Assurance pack and data-flow diagrams
- Sub-processor list with 30-day change notice
- Standard DPA with regional residency
- Security questionnaire answered in 5 business days
What Programme adds
Multi-tenant grouping
Each subsidiary gets its own scope, its own owners and its own SLAs, while the group security function sees one rolled-up picture.
SAML SSO and SCIM
Federate with Okta, Entra ID or any SAML 2.0 provider. SCIM keeps joiners, movers and leavers in step without a ticket.
Custom roles
Define exactly what a subsidiary analyst, a platform owner, an auditor and a board observer can each see and do.
Residency and keys
Select EU, UK, US or Canada at tenant creation, and supply your own encryption key material for stored findings and evidence.
Audit trail export
Every access, state change and export is recorded and streamed to your SIEM with stable identifiers.
Named architect
One named security architect who knows your estate, plus a quarterly programme review against commitments you set.
Sixteen weeks to a programme, not a pilot
The shape most groups follow. It is a plan, not a promise — we adjust it with you in week one.
- Phase 1 · Weeks 1–4Connect and inventory
Read-only roles across cloud, DNS and identity for the first two business units. First sweep and a written coverage gap list.
- Phase 2 · Weeks 5–10Ownership at scale
Ownership workshops per business unit, CMDB reconciliation, and an escalation ladder for assets nobody claims.
- Phase 3 · Weeks 11–16Paths and choke points
Crown jewels labelled with the data office, paths modelled, and the first three choke points scheduled into existing change windows.
- Phase 4 · Quarter 2Programme operation
SLAs agreed per team, ticketing wired both ways, assurance pack generated, board reporting moved onto the live model.
“The model did not tell us we were bad at security. It told us exactly which three changes to make first, and we could schedule those.”
The questions that decide the contract
Yes, and most should. Scoping gives each subsidiary its own working view and its own SLAs, while the group function gets a rolled-up score and the ability to drill in when it needs to.
A new scope is created for the acquired estate, discovery runs against it, and it stays reported separately until you decide to fold it into the group view. Asset counts are trued up at the next renewal, not mid-term.
The assurance pack, the sub-processor list, the data-flow diagrams and a DPA. All four are ready to send on request, and the trust centre answers most questions before the call.
No, and we would rather say so early. The platform is multi-tenant SaaS with regional residency. If self-hosting is a hard requirement, we are not the right fit.
Full export through the API in an open format, no export fee, and deletion within 30 days of written confirmation. This is written into the standard agreement.
Bring us your hardest scoping problem
Three subsidiaries on different clouds, an acquisition nobody has inventoried, an OT estate that cannot be probed. Those are the conversations we are best at.
Illustrative product data. Nothing on this site performs a live scan.