Financial services
Three-line-of-defense workflows. Severity gates wired into change-management. Evidence packages exported per-quarter for FFIEC and DORA. External auditors get a signed, read-only portal, not platform access.
SecurityVault is in design-partner release. Partners run the platform under NDA, so we do not publish logos, names or figures yet. Reference calls are available to qualified prospects with a partner's consent.
The sectors we designed for. Descriptions are of the operating model, not of named customers.
Three-line-of-defense workflows. Severity gates wired into change-management. Evidence packages exported per-quarter for FFIEC and DORA. External auditors get a signed, read-only portal, not platform access.
HIPAA Security Rule mapped to live evidence; HITRUST obligations as a custom framework. PHI-touching systems flagged in the ontology; deployment gates block changes to PHI services without a documented privacy review.
US federal control baselines and CMMC 2.0 Level 2 mapped for the defense supply chain (mappings, not authorizations). Sovereign-region deployment topology with no telemetry to the SecurityVault control plane.
Multi-tenant deployment-gate workflow that scales to ~12k builds/day. Policy-as-code authored alongside service code. Tenant boundary tests run nightly with signed evidence.
A small cohort, a direct line to the engineers, and honest terms.
The platform self-hosted or hosted, weekly working sessions with the people building it, roadmap influence, and pricing locked for the first term.
Real scanners, real findings, candid feedback, and permission to fix what breaks in front of you. A reference call only ever with your written consent.