🛡 Security governance, risk & compliance

The signal
in the noise.

CyberAssure helps consultants guide clients through Cyber Essentials Plus, ISO 27001, and UK GDPR — with AI-generated policies, automated gap analysis, and audit-ready evidence packs.

CE+ aligned
ISO 27001:2022
UK GDPR / DPA 2018
NCSC Cyber Essentials Plus
Cyber insurance ready
Consultant portal
Manage every client from one workspace

Full GRC platform — from tech intake through audit sign-off. AI-powered throughout.

  • Tech intake & AI gap analyser
  • 22 AI-generated policies (CE+ · ISO 27001 · GDPR)
  • Evidence pack builder & audit report
  • Branded policy documents with version control
  • Pre-audit readiness checker
Sign in →
Client portal
Your secure workspace for the audit journey

Track tasks, review policies, upload evidence, and ask AI anything — in plain English.

  • 4-week task tracker (Mon–Wed client, Thu–Fri review)
  • Policy viewer & AI refinement tool
  • Evidence upload by control area
  • Open gap tracker with resolution workflow
  • Non-technical AI assistant
Sign in →
Frameworks

One platform,
three frameworks.

CyberAssure combines CE+, ISO 27001, and UK GDPR into a single operational governance framework — so nothing slips through the gaps.

🛡
Cyber Essentials Plus

NCSC-accredited technical controls across five domains: firewalls, secure configuration, user access, malware protection, and patch management. Verified by independent assessment.

IASME · CyberSmart
📋
ISO 27001:2022

Full Annex A clause mapping on every policy — from A.5 (Policies) through A.8 (Technology). Every generated document explicitly references the relevant ISO controls.

Annex A controls mapped
⚖️
UK GDPR / DPA 2018

Seven dedicated privacy policies including DPIA procedure, SAR handling, ROPA, AI governance, and data breach response — all aligned to ICO guidance and UK post-Brexit requirements.

ICO aligned · Post-Brexit
How it works

From intake to audit-ready
in four weeks.

A structured 4-week programme — Monday to Wednesday client tasks, Thursday to Friday consultant review — with AI doing the heavy lifting.

01
Tech intake & scoping

Complete the structured tech intake covering identity platforms, MDM, AV/EDR, cloud, and patching. AI analyses the stack and identifies platform-specific evidence requirements.

02
AI gap analysis

Answer 20 questions across all five CE+ control areas. Claude generates a prioritised gap register with severity ratings, risk scores, and suggested resolutions.

03
Policy & evidence pack

Generate up to 22 policies tailored to the client's actual tech stack. Build branded, version-controlled policy documents. Client uploads evidence via their portal.

04
Pre-audit check & sign-off

Run the AI pre-audit checker for a 0–100 readiness score. Exec signs off policies. Generate the complete audit report for submission to IASME, CyberSmart, or your chosen certifier.

Two portals

Built for consultants
and clients alike.

Clean separation between consultant tools and client workspace — each with role-appropriate access, AI assistance, and a shared source of truth.

For consultants
CyberAssure Consultant Portal
📋

Multi-client dashboard

Manage all clients from one view. Track progress, audit dates, open gaps, and pack readiness across your entire book.

🤖

AI-powered throughout

Tech intake analysis, gap generation, 22 policy drafts, pre-audit checking, and a CE+/ISO/GDPR knowledge assistant — all powered by Claude.

📄

Branded document builder

Generate complete policy documents with your client's logo, brand colour, header, footer, version history, and exec signature block — audit-ready HTML.

Audit report & sign-off

Complete evidence pack with asset register, gap analysis, policy index, declarations, and a shareable auditor link.

For clients
CyberAssure Client Portal
📅

4-week task tracker

Clear Mon–Wed tasks, progress bars, and a simple checklist. Clients always know exactly what to do next.

📁

Evidence upload by control area

Upload files directly against the relevant CE+ control area. Your consultant sees everything in real time.

📑

Policy viewer & AI refinement

Read, refine with AI, download, and track sign-off for each of your organisation's policies.

💬

Non-technical AI assistant

"What does MFA mean?", "What will the auditor test?" — plain-English answers, no jargon.

Security & trust

Enterprise-grade access control
from day one.

SSO, MFA, and role-based access control — so sensitive client data stays exactly where it should.

🔐
SSO via Google & Microsoft

Sign in with your existing Google Workspace or Microsoft 365 account. OAuth 2.0 / OpenID Connect — no new passwords to manage.

📱
MFA enforced

Multi-factor authentication is required for all consultant accounts. Client accounts inherit MFA from their SSO provider. CE+ compliant out of the box.

👤
Role-based access

Consultants see all their clients. Clients see only their own workspace. Auditors get a read-only share link with no login required.

🔒
Data isolation

Each client workspace is logically isolated. Consultants cannot see other consultants' clients. All data is encrypted in transit and at rest.

📋
Audit logging

Every action is logged with timestamp, user, and IP. Policy versions are tracked with full history. Sign-off events are immutable.

🇬🇧
UK data residency

All data stored in UK data centres. UK GDPR and DPA 2018 compliant. ICO-ready data processing records available on request.

Ready to get started?
Your first audit is closer than you think.

Join consultants across the UK using CyberAssure to deliver faster, better-documented CE+ audits.

Consultant portal → Client portal →