AI tools

Built for the GRC practitioner who ships.

Not chatbots. Not dashboards. Single-purpose tools that take a real input from your day and return a real output you can paste into a deliverable.

Control Mapper

Paste any control. Get every framework mapping in seconds.

Cross-maps NIST 800-53, CMMC, ISO 27001, SOC 2, HIPAA, FedRAMP, ISO 42001, NIST AI RMF, GDPR, DPDPA, and more — with relationship typing and evidence guidance.

Open mapper

Maturity Card

Generate a shareable compliance maturity score.

Five-question assessment that produces a visual posture card across CMMC, ISO 27001, SOC 2, FedRAMP, and AI governance. Share it with your team or auditor.

Run assessment

SPRS Calculator

110-practice CMMC scoring with POA&M projection.

Click through every NIST 800-171 practice, mark met / not met / POA&M, and get a live SPRS score with projected uplift. LocalStorage saves your work.

Open calculator

SSP Narrator

Generate present-tense SSP narratives in your voice.

Paste a control and your system context. Get assessment-ready SSP language with placeholders for evidence references. CMMC, FedRAMP, ISO 27001 templates.

Generate narrative

Evidence Grader

Adequacy check before the auditor sees it.

Upload a screenshot, log excerpt, or policy clip. Get a per-objective adequacy verdict with red flags an assessor would call out.

Grade evidence

CCA Interview Simulator

Practice the assessor questions before they ask.

Lead CCA-grade interview simulator across all 14 CMMC families. 320 assessment objectives, real interview questions, expected answers.

Open simulator

Risk Translator

Technical findings into board language, instantly.

Paste a finding. Get board-ready language, dollar impact estimates, priority rating, and a one-sentence brief ready for your next exec meeting.

Translate finding

Security Auditor Agent

Open-source Anthropic agent. Audits your system. Download and own it.

Try the live demo or download the YAML — a Claude Opus agent with file-system access (read/grep/glob) that conducts security audits, compliance gap analysis, and risk evaluations with Critical/High/Medium/Low findings.

Try or download