NVector OS — 11 unified modules Core kernel active Zero third-party sync lag

The whole compliance function,
in one system.

Know what is required. Do it. Prove it. Watch what could go wrong, handle it when it does, and report on all of it. 11 synchronised modules, sharing one set of immutable records.

Book a demo Explore 11 modules

8 frameworks mapped Immutable audit trail One control library

  • Controls1,248 active
  • Cross-walk8 norms, 1:N
  • Attestations100% verified
  • Breach SLA0 missed clocks
  • Auditor accessScoped read-only
  • AI governanceHuman signed off

All 11 synchronised modules

Eleven registers, one single source of truth.

Select a module to inspect how it works and what it produces.

Module 01 FAIR compatible

A register that sorts itself by what actually matters.

Risks are scored on likelihood and impact and banded automatically into Low, Medium, High or Critical. Each carries an owner, a treatment decision, the controls that mitigate it and the indicators that show whether it is improving.

  • Likelihood and impact scoring with automatic severity bands
  • Named owners and treatment plans with due dates
  • Formal risk acceptance with expiry dates, not informal sign-off
  • Linked to the controls that reduce it
5 × 5 heatmap matrix 3 critical · 11 high · 24 med · 52 low
M-04
H-09
H-12
C-01
C-02
L-08
M-07
H-03
H-08
C-03
L-02
L-14
M-11
M-19
H-06
RSK-882 — unencrypted backup replicas Mitigated by CTRL-ENC-04 · Owner: SecOps Infrastructure
Critical

Module 02 Breach SLA telemetry

The regulatory clock runs where everyone can see it.

Serious incidents come with a reporting deadline measured in hours, and they rarely arrive during office hours. NVector starts the countdown at detection, escalates as the window closes, and records whether notification was made in time.

  • Countdown anchored to the detection time you record
  • Escalation before the deadline, not after it
  • Full incident lifecycle from triage to lessons learned
  • Corrective actions raised directly from the incident
Regulatory clock Strict 72-hour SLA
Notification window remaining 41:18:09 hours : minutes : seconds
Auto-detected by SIEM (T-0) Level-2 legal escalation active

Module 03 Cross-walk core

Do the work once, satisfy every framework it touches.

A single library of plain-language controls sits above your frameworks. Each one is mapped to the specific clause it satisfies in every rulebook you have switched on, and the mapping records whether that coverage is full or partial. Mark a control implemented and every requirement it fully satisfies closes with it.

  • Work one library instead of several overlapping requirement lists
  • Coverage cascades automatically to every framework it satisfies
  • Partial mappings stay open until the remaining work is done
  • Adding a framework starts partly complete, because the work is already done
CTRL-ENC-04 — at-rest AES-256 storage volumes One envelope control across every production cluster
Operational
ISO/IEC 27001:2022 A.8.24 Cryptography
SOC 2 CC6.1 Logical perimeter
NIST CSF 2.0 PR.DS-1 Data at rest
NCA ECC ECC-2-7 Crypto specs

Module 04 Attestation hub

Policies that are current, approved and provably read.

Draft, review, approve, publish and attest — with electronic sign-off recorded and the next review date scheduled. Procedures sit with the policies they implement, so the document set stays whole rather than scattered across drives.

  • Full policy and procedure lifecycle with approval routing
  • Staff attestation, recorded per person
  • Scheduled review dates, so nothing quietly goes out of date
  • Version history showing what changed and who approved it
POL-SEC-01 — information security policy v4.2 Current
Approved by the Chief Information Security Officer Electronic sign-off recorded and timestamped
Read-and-understood attestation 412 / 412 staff

Module 05 SHA-256 immutability

Proof attached to the control it proves, ready before the examiner asks.

Every document is linked to the requirement it evidences, classified by sensitivity, and visible only to the roles cleared for that level. Validity periods are tracked, so evidence that has aged out is flagged by the system rather than discovered by an auditor.

  • Documents linked directly to the controls they support
  • Sensitivity classification with role-based access
  • Expiry tracking on evidence that goes stale
  • Every view and download recorded in the audit trail
Vault integrity Every item hashed on upload
iam_mfa_enforcement_2026.json Valid 341 days
SHA-256 7d49b2f15e8bb241c8f12a970e0a6d0c2e3f4a5b… Control CTRL-IAM-02
q4_penetration_test_signed.pdf Expires in 28 days
SHA-256 3a98c52e4f01bc89472ef8194adcb54817e052d… Control CTRL-NET-11

Module 06 SLA engine

Every obligation becomes somebody’s job, with a date on it.

Remediation, evidence collection, policy review and audit findings all raise tasks against a named owner. Recurring obligations regenerate on their own schedule, so the work that has to happen every quarter is not something anybody has to remember.

  • Tasks raised directly from controls, risks, incidents and findings
  • Named owners, due dates and escalation when they slip
  • Recurring tasks for obligations that repeat on a cycle
  • Approval chains where a second pair of eyes is required
Open obligations Generated from controls and findings
Quarterly access reviews Owner: Identity Operations
Due in 4 days
Backup restoration drill Owner: Platform Lead
Escalated
Supplier re-assessment Owner: Compliance Analyst
Due in 18 days

Module 07 In-scope inventory

You cannot protect, or evidence, what you have not written down.

An inventory of systems, applications, data stores and the people accountable for them. Assets carry classification and criticality, and they connect to the risks, controls and vulnerabilities that touch them — which is what turns a list into scope.

  • Inventory of systems, applications and data stores
  • Classification, criticality and a named owner on every asset
  • Linked to the risks and controls that apply to it
  • Scope for audits and assessments drawn from the inventory
In-scope inventory Classification drives the control set
AssetEnvironmentTierControls
prod-rds-customerPrimary regionTier 118 enforced
identity-tenantSaaS identityTier 112 enforced
payments-clusterDedicated enclaveTier 124 enforced

Module 08 Examiner portal

Turn examination season into a report, not a project.

Scope internal audits, request evidence from control owners, record findings and drive them to closure. Every change in the platform is written to an immutable trail with before and after values, so the history stands up to scrutiny.

  • Internal audit projects with evidence requests and findings
  • Corrective and preventive actions tracked to closure
  • An immutable audit trail of every change, with before and after values
  • Findings raise tasks against named owners automatically
Finding 04 — credential rotation exceeded its window 94 days → 30-day automated rotation. Evidence re-attached.
Remediated
Controls tested114 / 114
Open findings0
TrailImmutable

Module 09 8 norms built in

Switch a rulebook on and its requirements are already there.

The regulatory content ships with the product. Turn on a framework and its full requirement set appears, mapped to the control library, with a live coverage position per requirement — so you can see where you stand on day one rather than after a content project.

  • Requirement sets loaded and mapped, not built by you
  • Live coverage position per framework, domain and requirement
  • Run several frameworks at once against one body of work
  • Your own internal standards can sit alongside the published ones
Readiness by framework Recalculated as controls close
ISO/IEC 27001 96%
NIST Cybersecurity Framework 100%
NCA Essential Cybersecurity Controls 100%
SAMA Cyber Security Framework 94%

Module 10 SLA governor

Findings that carry a deadline and an owner, not just a severity.

Track vulnerabilities against the assets they affect, with severity, remediation owner and a due date driven by your own policy. Overdue items surface against the control and the framework requirement they put at risk, rather than sitting in a scanner nobody opens.

  • Findings tracked against the affected asset
  • Remediation deadlines driven by your severity policy
  • Overdue items visible against the controls they undermine
  • Exceptions recorded formally, with an expiry date
Remediation SLA 1 breaching
Remote code execution — CVSS 9.8 prod-rds-customer · detected 6 days ago
SLA breached
Privilege escalation — CVSS 7.4 payments-cluster · owner assigned
9 days left
Outdated TLS suite — CVSS 5.1 edge-gateway · accepted with expiry
Accepted

Module 11 Board pack builder

The board pack builds itself from the data you already keep.

Compliance position, risk profile, incident history, overdue work and audit status, generated from live data and exportable for a board paper or a regulator. The number in the report is the number in the platform, because it is not rebuilt by hand each quarter.

  • Board-ready reporting generated from live data
  • Compliance position by framework, domain and owner
  • Exportable for regulators, auditors and committee papers
  • Dashboards for the day-to-day, reports for the record
Board pack Generated from live records
Compliance96%
Open risks14
Overdue3
Quarterly board pack Position, risk profile, incidents, overdue work
Ready
Regulator examination export Scoped to the frameworks you select
Ready

See it against your own frameworks

Thirty minutes in the live platform, using the rulebooks you actually report against.