← All products

Cerynix's flagship product · private preview

From requirements to evidence — ready for review.

The GRC & Compliance Platform brings NIS2, ISO/IEC 27001 and GDPR requirements, controls, risks, findings, corrective actions, management review and a signed Audit Room export into one traceable process. When review time comes, every conclusion can lead back to its source.

  • Self-hosted deployment
  • Signed releases
  • No compliance guarantees
Requirement assurance recordSample data
NIS2 · Article 21(2)(d)

Supply-chain security

Applicable · customer-facing software service

ControlSupplier security reviewCTRL-SUP-04
Accountable ownerSecurity leadReview due 30 Sep
Evidence3 linked recordsLatest reviewed 12 Jul
Review outcomeVerified with observation1 corrective action open
SourceDecisionEvidenceReport
ScopeControlsEvidenceAssuranceFindings & CAPAManagement reviewAudit Room

The operational problem

Audit preparation should not begin with a folder search.

01

The requirement is separated from the work

Obligations sit in spreadsheets while controls, decisions and remediation live in other tools.

02

Evidence loses its context

A file alone does not show its owner, scope, collection date, review state or when it expires.

03

The report cannot explain itself

Manual reports drift from their source records and are difficult to reproduce at the next review.

One connected record

Follow the evidence, not the interface.

Cerynix preserves the path from an obligation to the material a reviewer inspects. Each step has an owner, status and history.

  1. 01Scope

    Record the source, framework clause and applicability decision.

  2. 02Controls

    Describe how the requirement is implemented; assign an accountable owner.

  3. 03Evidence

    Link records with source, version and validity; supersede without losing history.

  4. 04Assurance

    One honest status: unassessed → self-asserted → evidence-backed → reviewed.

  5. 05Findings & CAPA

    Root-cause analysis to an effectiveness-reviewed corrective action.

  6. 06Management review

    A human-authored ISO/IEC 27001 Clause 9.3 record of inputs and decisions.

  7. 07Audit Room

    Export a signed, offline-verifiable package for an independent reviewer.

The reviewer outcome

Give reviewers the record behind the conclusion.

Cerynix structures the information needed to inspect scope, implementation, evidence and unresolved work. It supports an informed review; it does not decide whether your organization is compliant.

  • Scope and applicability decisions
  • Control assessments and Statement of Applicability
  • Risk register and treatment plan
  • Evidence index with version history and reviewer sign-off
  • Nonconformities, root-cause analysis and corrective actions (CAPA)
  • Management review record (ISO/IEC 27001 Clause 9.3)
  • Signed Audit Room export with an offline integrity verifier
  • Tamper-evident audit trail with on-demand integrity verification
CAssurance review materials
SAMPLE

Sample organization · Review period Q3 2026

Review index

  1. 01
    Scope & applicabilityApproved decisions and exclusions
    12 records
  2. 02
    Control matrixImplementation and ownership
    Current
  3. 03
    Evidence indexSource, version and review state
    84 records
  4. 04
    Findings & CAPARoot cause, corrective actions, effectiveness
    6 open
  5. 05
    Management reviewClause 9.3 record, human-authored
    Current
  6. 06
    Audit Room exportSigned package, offline-verifiable
    Verified

Illustrative index — exports are generated as individual supported report formats; counts do not describe a real customer.

Supported now

One evidence base, mapped to the requirements you use.

Mappings help teams reuse relevant work. They do not constitute certification or a legal applicability decision.

EU directive

NIS2

Scope, security-measure obligations, controls, incidents, evidence and remediation in one operating record.

International standard

ISO/IEC 27001:2022

Requirements and Annex A controls with assessments, evidence, a versioned Statement of Applicability, and Clause 9.3 management review.

Security subset

GDPR security readiness

A focused control library for security and accountability work that overlaps with the assurance programme.

Deployment and data control

Run the assurance record in your environment.

The on-prem edition installs with Docker Compose and keeps the application database and evidence storage under customer control.

Read the installation guide
Customer-controlled data
Operate the database and evidence storage in your own environment.
Verified distribution
The installer verifies the signed release bundle before extraction.
Encrypted recovery
Documented backup, restore and recovery procedures keep recovery explicit.
Offline licence validation
The core self-hosted licence can be verified without mandatory phone-home.

Security, without badge theatre

Controls you can inspect. Boundaries we state plainly.

Tenant isolation

Every tenant-scoped query is authorized at the application layer and enforced again by PostgreSQL row-level security, forced on every tenant table as defense-in-depth and verified in CI as a non-superuser role.

Tamper-evident ledger

Sensitive actions are recorded in an append-only, SHA-256 hash-chained audit ledger; a verification endpoint recomputes the chain on demand.

Signed releases

Container images are cosign-signed keyless via GitHub OIDC with build provenance and an SBOM; the self-hosted bundle ships minisign-signed with its own SBOM.

Offline licensing

License keys are Ed25519-signed by us and verified locally by your instance — no license server, no mandatory phone-home.

Read the full security page

Built around accountability

One record, three perspectives.

Run

Security & compliance leaders

Coordinate scope, owners, evidence, risks and corrective work across the programme.

Review

Internal auditors & consultants

Inspect the chain behind each conclusion and follow unresolved findings to action.

Decide

Executives

Review risks, overdue remediation and management decisions without losing the source context.

A concrete next step

Bring one requirement. Leave with the evidence path.

In a focused walkthrough, map one of your real obligations to a control, owner, evidence requirement and review record. No generic sales deck.

Request a working session