The requirement is separated from the work
Obligations sit in spreadsheets while controls, decisions and remediation live in other tools.
Cerynix's flagship product · private preview
The GRC & Compliance Platform brings NIS2, ISO/IEC 27001 and GDPR requirements, controls, risks, findings, corrective actions, management review and a signed Audit Room export into one traceable process. When review time comes, every conclusion can lead back to its source.
Applicable · customer-facing software service
The operational problem
Obligations sit in spreadsheets while controls, decisions and remediation live in other tools.
A file alone does not show its owner, scope, collection date, review state or when it expires.
Manual reports drift from their source records and are difficult to reproduce at the next review.
One connected record
Cerynix preserves the path from an obligation to the material a reviewer inspects. Each step has an owner, status and history.
Record the source, framework clause and applicability decision.
Describe how the requirement is implemented; assign an accountable owner.
Link records with source, version and validity; supersede without losing history.
One honest status: unassessed → self-asserted → evidence-backed → reviewed.
Root-cause analysis to an effectiveness-reviewed corrective action.
A human-authored ISO/IEC 27001 Clause 9.3 record of inputs and decisions.
Export a signed, offline-verifiable package for an independent reviewer.
The reviewer outcome
Cerynix structures the information needed to inspect scope, implementation, evidence and unresolved work. It supports an informed review; it does not decide whether your organization is compliant.
Illustrative index — exports are generated as individual supported report formats; counts do not describe a real customer.
Supported now
Mappings help teams reuse relevant work. They do not constitute certification or a legal applicability decision.
Scope, security-measure obligations, controls, incidents, evidence and remediation in one operating record.
Requirements and Annex A controls with assessments, evidence, a versioned Statement of Applicability, and Clause 9.3 management review.
A focused control library for security and accountability work that overlaps with the assurance programme.
Deployment and data control
The on-prem edition installs with Docker Compose and keeps the application database and evidence storage under customer control.
Read the installation guideSecurity, without badge theatre
Every tenant-scoped query is authorized at the application layer and enforced again by PostgreSQL row-level security, forced on every tenant table as defense-in-depth and verified in CI as a non-superuser role.
Sensitive actions are recorded in an append-only, SHA-256 hash-chained audit ledger; a verification endpoint recomputes the chain on demand.
Container images are cosign-signed keyless via GitHub OIDC with build provenance and an SBOM; the self-hosted bundle ships minisign-signed with its own SBOM.
License keys are Ed25519-signed by us and verified locally by your instance — no license server, no mandatory phone-home.
Built around accountability
Coordinate scope, owners, evidence, risks and corrective work across the programme.
Inspect the chain behind each conclusion and follow unresolved findings to action.
Review risks, overdue remediation and management decisions without losing the source context.
A concrete next step
In a focused walkthrough, map one of your real obligations to a control, owner, evidence requirement and review record. No generic sales deck.
Request a working session