Cyverse Audit Manager is a 100% white-label GRC SaaS platform built for cybersecurity consulting firms that manage multiple clients and certification projects simultaneously. Consultancies deploy the platform under their own brand — logo, colors, domain — in under 24 hours. End clients never see the Cyverse name.
Core capabilities: native MAGERIT v3 risk engine with probability × impact heat map and automatic risk generation from assets, ISO 27001:2022 GAP analysis (155 questions across 4 domains), dynamic Statement of Applicability linked to the risk engine with evidence per control, evidence repository with approval workflow and traceability, AI-assisted policy and document generation, internal awareness and training module, treatment plan with task ownership and deadlines, executive dashboard, and automated PDF/Word report generation branded for the consultancy.
Frameworks supported: ISO 27001:2022 (full 93 Annex A controls), ENS — Esquema Nacional de Seguridad (Básico/Medio/Alto), NIS2. Multi-tenant architecture with database-level client isolation. Roles: Consultant, External Auditor, Reader. Deployment in under 24 hours with guided onboarding. Non-compete clause included: Cyverse never contacts the consultancy's registered clients.