AC-04Privileged access review
Review elevated access, confirm accountable owners and retain the same proof for every mapped requirement.
- Owner
- AMAlex Morgan
- Review cadence
- Quarterly
- Evidence
- Q3 access review.pdf
Run frameworks, risks, policies, vendors, evidence and audits in one calm workspace. Every owner knows what is next. Every answer keeps its proof.
Every framework. Every owner. One live picture.
This quarter ⌄Map one control to every obligation it satisfies. The owner, implementation and proof stay shared, even as the framework list grows.
AC-04Review elevated access, confirm accountable owners and retain the same proof for every mapped requirement.
Thirteen connected modules run on the same living model of your organisation. Scope the program, operate the work and arrive at proof without rebuilding context between tools.
Deploy ISO 27001, SOC 2 or NIST in minutes: controls, owners and maturity tracking included. Cross-mapping carries every implemented control into the next framework you adopt.
One control, many frameworks
WorkspaceBring evidence into the same workspace through native connectors for core cloud, identity and engineering systems. Extend everything else through the CSFaaS API and MCP, without breaking the audit trail.
Connect Claude, ChatGPT, Gemini, Mistral or any MCP-capable client to live CSFaaS context. The same row-level permissions still decide what each person can see and do.
Which controls need attention before our ISO 27001 audit?
Three controls need attention before your next review.
AC-04Privileged access reviewDue in 4 daysBC-02Recovery evidenceEvidence missingTP-07Supplier reviewDue in 8 daysGive security, legal, IT, leadership and external reviewers one shared place to move the program forward, without turning everyone into a GRC specialist.
A clear standard for who can access what.
This policy defines how access to Acme information systems is granted, reviewed and revoked.
System owners review privileged access at least once every quarter.Sarah All decisions are recorded and linked to supporting evidence.
Under six core sections sit 155 capability-level choices. Start with a sensible shape, then keep only the workflows, fields and scoring logic your organisation actually uses.
Choose the capabilities your team needs.
From an empty workspace to a defensible program, without a single spreadsheet.
Choose your frameworks, import your catalogs, declare your systems and set your risk appetite. Your program scaffolds itself around them.
Assign owners, treat risks, review controls, collect evidence. Every change is logged at the database level and the right people are notified, automatically.
Auditors, clients and the board read from the same live posture you do. Export when asked. Be ready always.
Tenant separation is enforced by PostgreSQL row-level security on every table, not by application code that can forget to check.
TLS for every connection, encryption at rest for every byte. Your evidence never travels or sleeps in the clear.
TOTP two-factor authentication and role-based permissions, scoped per workspace and per module.
Files live in workspace-scoped storage, versioned, and are only ever served through time-limited signed URLs.
Activity events are emitted by the database, not by scripts: a record of who changed what that cannot be skipped.
Data residency in the EU with GDPR-aligned processing. Your compliance platform is itself compliant.
The full GRC platform is free for your first 2 users. After that it is a flat €79 per user, with optional add-ons for full audit history and extra storage. Connect your own AI over MCP, included with every seat. No per-framework fees, no hidden tiers.
Everything included, for up to 2 users.
For your whole team. The first 2 users are always free.
Tailored to your organization
Two users free. Only pay for the rest.
2 free + 3 paid users
Keep your full audit trail for the whole team. The free plan shows the last 7 days.
5 GB is included free. Add more whenever you need it.
Our operating partner DarkProtect deploys and runs CSFaaS end to end: the platform, the program and the people behind it.
Meet DarkProtectCSFaaS deployed and operated for you: continuous evidence, live posture.
ISO 27001, SOC 2, NIST CSF, GDPR, DORA and NIS2 programs that pass review.
Penetration testing, cloud and configuration review, and threat modeling.
Senior security leadership on demand: strategy, reporting and ownership.
If your question is not here, book a demo and bring the awkward version. Those are usually the useful ones.
Yes. CSFaaS is designed around one shared control library, so the work you complete for one framework can be reused wherever requirements overlap.
No. It gives them a cleaner operating system: live ownership, evidence, review history and audit workflows. You can run it yourself or pair it with DarkProtect services.
Workspace separation is enforced in PostgreSQL through row-level security. Evidence is stored privately and served through time-limited signed links.
Yes. The Platform API and OAuth-enabled MCP server expose the same governed workspace data and respect each user’s live permissions.
The full platform is free for the first two users, with no credit card required. Pro is €79 per additional user each month, or €790 yearly.
Manage multiple workspaces, clients, and business units with complete data isolation.
Streamline compliance across ISO 27001, NIST, GDPR, and 40+ frameworks automatically.
Data-driven decisions with live dashboards, analytics, and audit-ready reports.
Full data portability: pull everything over the API anytime, integrate seamlessly, scale without restrictions.
Perfect for startups to enterprises, including managed service providers.
Built-in collaboration tools with granular permissions and real-time workflows.
Tailor policies, workflows, and controls to meet your specific requirements.
Start free, scale affordably, no hidden costs or surprise fees.
Continuous updates with new frameworks and evolving compliance features.
Frameworks decoded, regulations translated, practice over theory, from the team behind the platform.

CSFaaS shipped 55 improvements in four weeks, covering AI-powered prompt automation, MCP hardening, CyFun integration, risk workflows, auditability, permissions, scalability, UX and education. Together, these updates reflect a platform becoming more mature, reliable and operational release after release, with major new capabilities coming next.
Read article
Anthropic has announced plans to mark content generated or processed by Claude as part of its commitments under the EU AI Act and the Code of Practice on Transparency of AI-Generated Content. For new Claude models launched in the EU on or after August 2, 2026, Anthropic says marking will be supported from launch. The approach relies on two complementary mechanisms: embedded watermarks in text and signed provenance metadata for files.
Read article
CyFun® does more than build on the NIST Cybersecurity Framework. It turns cybersecurity guidance into something assessable, measurable and auditable. By distinguishing between documentation and implementation maturity, CyFun® helps organisations move from knowing what they should do to demonstrating what they actually do.
Read articlePut the program, the work and the proof in one place. Start with two users free, or bring us your current stack for a focused walkthrough.
No credit card required. Ready when you are.
@Sarah Evidence is attached. Ready for your review.
Resolved