29 production connectors live + 25+ source categories supported via universal framework
15 pre-seeded compliance frameworks (~895 controls — 7 audit-grade + 8 scaffold-grade)
Both dashboards — full end-to-end UI
Auditor portal with framework-scoped, time-bound, read-only access
Hybrid-SaaS Docker agent with HMAC-signed reporter
Drill-down reverse-WebSocket tunnel with 60s tokens
Multi-tenant data plane with cross-tenant isolation tests
White-label per-tenant theming end-to-end
Composite scoring engine (CVSS · EPSS · KEV · tier)
4 live external intelligence feeds
SHA-256 evidence integrity hash on every artifact
Per-tenant Fernet-encrypted credential vault
16 license modules (Core + 15 capability), with three-layer enforcement
Standalone Compliance deployment — runs without the URIP risk layer
Risk acceptance workflow with HoD approval
Bidirectional ticketing into ManageEngine SDP, Jira and ServiceNow
Intelligence Engine — 5 live services (normalisation, fingerprinting, applicability, remediation fetch, connector runner)
Auto-Remediation Phase 2 — gated execution via CrowdStrike RTR (OAuth2 Bearer), Ansible, Fortinet, CyberArk
Trust Center — public NDA-gated posture page with time-bound, hashed access tokens and self-serve procurement access
VAPT Vendor Portal — closed-loop pentest workflow with single-use JWT invitations
DSPM, AI Security, ZTNA, Attack Path Prediction, Cyber Risk Quantification (FAIR) — 5 strategic modules at MVP-scaffold depth
6 framework PDF report templates — SOC 2 management, ISO 27001 SoA, HIPAA risk analysis, GDPR Article 30 register, PCI DSS AOC inputs, India DPDP DPIA
LMS connectors — security-awareness-training telemetry surfaces as compliance evidence (ISO 27001 A.6.3 + SOC 2 CC1.4)
BGV connectors — background-verification status surfaces in HIPAA / India DPDP evidence (HIPAA §164.308(a)(3))
Auditor activity heatmap — GitHub-style 4-level grid showing every auditor action with calendar-day buckets
Word Cloud Threat Map — board-friendly D3 visualisation of top APTs, TTPs, and targeted sectors
Async task queue — Celery + Redis beat schedule (connector-pull 15min, scoring 60min, control-check 6h)
Risk ↔ Control event bus — compliance.control.failed auto-creates linked URIP risks
Immutable per-tenant audit log on every action
9 versioned policy templates with e-sign workflow
Vendor risk — questionnaires, criticality, contract alerts
Drift detection on connectors (no silent failure)