One platform. Not twelve tools.
Mapped once. Inherited by every customer.
Frameworks, controls and policy templates are curated centrally and versioned. Adopting one is a reference, not a fork: when a new circular lands, we map it one time and you see the new version through your overlay, adopting it deliberately rather than being silently changed.
The canonical catalog
40+ frameworks across nine African markets and the international standards: 1,200+ requirements resolved to 132 shared controls through 1,700+ cross-mappings, maintained centrally by our curation team.
Adoption by reference
Which items you've adopted, your customisations, owners and evidence. A reference to the catalog, never a fork of it.
Controls, resolved
Your working controls are the catalog read through your overlay: implement once, and it counts toward every framework it maps to.
The machinery every module shares.
The modules are views onto one connected data model, not separate apps that sync. These systems run underneath all twelve, which is why a control you implement once counts everywhere.
Automation that runs itself
A definition-driven scheduler runs your programme's cadence so nothing depends on someone remembering, raising work items when something needs a human.
Connect your stack
Read-only collectors auto-evidence controls from systems you already run. A broken connection raises an integration-health issue; it never silently flips a control red.
Identity & access
Roles modelled on the Three Lines of Defence, maker/checker enforced per item, one identity to one workspace, and SSO provisioned just-in-time.
Built for outside parties
Auditors, examiners and vendors work in their own time-boxed workspace, never in your live data. The full story lives in Audit Hub.
Reporting & your work
Board and Exco rollups, exportable posture reports, a compliance calendar, and a “what needs me” inbox, all reading from the same data the programme runs on.
Simple to reason about. Safe to trust.
One deployable, one database, a modular monolith you can fully reason about and defend. The kind of architecture that survives a security review instead of explaining itself away.
The full security architecture, and how it's tested, is written up for your security team to review.
Read the security architecture- Architecture
- Modular monolith, one deployable, one database
- Data
- PostgreSQL 16, forward-only reviewed migrations
- Storage
- Private object storage, signed URLs only, never a public object
- Footprint
- Postgres, an object store, one worker, one VM
Compliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.