Professional assurance & onboarding

The software is the easy part.

The platform is usable on day one because the frameworks and the control library ship with it. What takes the time is getting your own controls, evidence and history into it, and making sure the people who have to keep it current actually can. That is what these engagements are for.

  • Time to value

    Usable day one

    The control library ships with the product

  • Configuration

    No code changes

    Frameworks are data, not a release

  • Integrity

    Immutable trail

    Every change recorded with before and after

  • Oversight

    A named contact

    One person accountable for the engagement

Engagement models

Four ways we work with you

Each one has a duration and a list of what you receive. Take any of them on its own, or the first with any of the others.

Two to four weeks 01 · Core

Implementation

Get the platform running against the frameworks you report on, with what you already have loaded into it. Cloud deployments are usable on day one; this is the work that makes them useful.

Deliverables

  • Your frameworks switched on and mapped to the control library
  • Existing policies, procedures and evidence loaded and linked
  • Roles and approval chains scoped to your organisational units
  • The people who will use it trained on their part of it

Ask about this engagement

One to three weeks 02 · Assessment

Framework readiness review

Where you actually stand against a framework, requirement by requirement. The output is the remaining work as owned tasks with dates, not a percentage on a slide.

Deliverables

  • A position on every requirement, with the evidence behind it
  • Gaps written as tasks against named owners
  • An inventory of the evidence you hold and what has aged out
  • A report you can take to a committee without rewriting it

Ask about this engagement

Included with implementation 03 · Migration

Migration from spreadsheets

Almost everyone arrives from spreadsheets, email threads and folders of PDFs. That baseline is the starting point, not something to throw away and retype.

Deliverables

  • Risk register imported with your scoring preserved
  • Your control set mapped onto the shared library
  • Evidence filed against the control it proves
  • A written record of anything that could not be mapped cleanly

Ask about this engagement

One to two weeks, before the date 04 · Pre-audit

Examination support

Rehearse the examination before the examiner arrives. Most findings are not surprises about your security; they are gaps in what you can show and how quickly.

Deliverables

  • Evidence completeness checked against the scope being examined
  • Expired and missing evidence flagged and refreshed
  • Auditor access scoped to read-only on the right records
  • Sample requests answered from the platform rather than by email

Ask about this engagement

Execution sequence

Four phases, in that order

The shape is the same whichever engagement you take. Only the third phase varies much in length, and it varies with how much you already have.

  1. Scope

    One call. Which frameworks you report against, how many people need access, where it has to run, and how much you already have written down.

    One call

  2. Configure

    Frameworks switched on, organisational units and roles set up, approval chains agreed. Nothing here is a code change, so it moves in days rather than months.

    Two to four days

  3. Load

    Your policies, register and evidence go in and get linked to the controls they support. This is the week that decides whether the platform is useful to you.

    One to two weeks

  4. Hand over

    Training for the people who will live in it, then we step back. It stays your programme; we are not a seat at your compliance function.

    Sign-off, then it is yours

Isolation architecture

Four deployments, one product

The same platform and the same 8 frameworks in every case. What changes is where the data sits and whether AI assistance is available at all.

Security and deployment in detail
Tier 01

Cloud

Where it runs
Hosted and managed by NVector
AI assistance
Available
Typically chosen by
Small and mid-size institutions

Hosted and managed by us

Tier 02

Cloud without AI

Where it runs
Hosted and managed by NVector
AI assistance
Disabled — nothing leaves for inference
Typically chosen by
Strict data-sharing policies

Nothing leaves for inference

Tier 03

On-premise

Where it runs
Your data centre, your controls
AI assistance
Optional, using your own provider key
Typically chosen by
Data residency requirements

Your hardware, your controls

Tier 04

Air-gapped

Where it runs
Fully isolated, no internet at all
AI assistance
Local model only
Typically chosen by
Government and critical infrastructure

No internet connection at all

Where we stop

What is included, and what is not

The second list matters more than the first. A vendor that will not say where it stops is a vendor you will argue with later.

Included

  • Configuration, content loading and framework mapping
  • Training for administrators and for control owners
  • All frameworks that ship with the product, at no extra licence cost
  • Import of your existing register, controls and evidence
  • A named contact for the duration of the engagement

Not included

  • We do not act as your compliance function. The decisions stay yours.
  • We do not write your policies. We version, route and evidence the ones you own.
  • We do not issue certifications or audit opinions — we are not an assessor.
  • We do not resell audits. Your examiner is your choice and our access is read-only.