AWS-native ISMS · ISO 27001 · ISO 42001 · SOC 2

We read your AWS account.
Then we tell you what it is.

A relationship graph of your estate, the ISMS artefacts an auditor asks for, and evidence that never shows "not assessed" as "passed". Self-hosted. Read-only.

Read-only AWS Runs in your AWS account AWS-native by design
Discovery Intelligence · output from an example account

We discovered 800 resources in your AWS estate across 6 regions. They organize into 15 logical workloads and 1 inferred owner. The biggest workloads are ECS Cluster (web app), S3 Cluster (data tier), and IAM Cluster (serverless pipeline). 799 resources (over 99%) have no inferred owner — adding owner/team tags would dramatically improve traceability. We flagged 100 orphaned resources with no connections, 30 critical hot spots — start there for your first cleanup pass.

800 resources · 2,000 relationships · 0 dangling edges

Every screen in this sidebar opens — all 31, grouped the way the product groups them, by the clause of the standard each one serves.

The stack you already trust
AWS ISO 27001 SOC 2 PCI-DSS GDPR NIS2
Platform

Most tools tell you a bucket is unencrypted.

We tell you who can reach it, by what path, and what changed.

Reachability, not just findings

We build a graph of your AWS account and resolve the relationships between resources — not only what exists, but what reaches what. IAM policy grants and security-group paths are both first-class edges, so "which identities can reach this bucket" is one hop, with the path attached.

On an example account: 800 resources, 2,000 relationships, zero dangling edges. Each artifacts bucket resolves to 30 roles with access.

s3://example-artifacts → 30 roles · via policy_grants

The artefacts an auditor asks for

A full ISMS, not a scanner with a dashboard: Statement of Applicability, risk register, policy pack with approvals, evidence management, training records, incidents, corrective actions, internal audit, management review, access reviews, vendor management, a trust centre and an auditor portal. Security questionnaires are answered from your own evidence, with citations.

"Not assessed" is not "passed"

Controls are marked relevant separately from assessed, and a check that cannot run reports not assessed rather than a green zero. You always know the difference between "we checked and it is fine" and "we did not check". Most tools in this category blur that line.

Scope

What isops.ai does not do.

Narrow and provable beats broad and unfalsifiable — especially in this market.

AWS only

The collector is AWS-native. Other clouds are not at parity and we do not claim they are. This is a deliberate trade: depth in one cloud, with a relationship graph, over breadth without one.

Not a check-count play

15 scanners, not hundreds of checks. Open-source scanners cover far more individual checks and are free — if raw check volume is what you need, use one. Our value is the graph the findings hang on and the ISMS around it.

Scan-based, not real-time

Discovery runs when you run it, and each scan replaces the previous graph. We do not claim continuous monitoring.

We do not certify you

An accredited auditor does that. isops gets you audit-ready and gives the auditor something to read.

How it works

Three steps to audit-ready.

01

Connect AWS

Read-only IAM role or profile. 15-minute setup. The scanner never writes: the only writes are a remediation you explicitly approve, and — if you deploy the optional scheduled-scan stack — the scan reports it stores in your own S3 bucket and the notifications it publishes to your own SNS topic.

$ isops scan --profile prod --mode compliance
02

Scan & score

15 scanners, across IAM, storage, compute, data, secrets, logging and network. Critical findings surface first.

→ 15 scanners · 93 controls
03

Ship evidence

Mapped to ISO 27001 and SOC 2 from the findings themselves. GDPR, HIPAA, PCI DSS and NIST 800-53 are available as mapping references.

✓ evidence.pdf · ISO27001-A.pdf
Design partner program

Built with teams shipping today.

isops.ai is being built alongside a small cohort of design partners — security and platform leads at fintech, healthtech, and B2B SaaS companies preparing for SOC 2, ISO 27001, or HIPAA audits. We ship the product against their real evidence backlogs, not a roadmap deck.

Apply for the next cohort →
27
AWS resource types
discovered into the graph
15
AWS scanners
93
ISO 27001 controls tracked
38
ISO 42001 controls
Frameworks

Assessed frameworks and mapping references.

ISO
ISO 27001:2022
93 Annex A controls · 17 auto-verified
42001
ISO 42001:2023
38 Annex A controls · AIMS
SOC
SOC 2 Type II
Trust Services Criteria
GDPR
GDPR
Data processing evidence · mapping reference
PCI
PCI DSS
12 requirements · mapping reference
NIS2
NIS2
Essential entities · mapping reference
HIPAA
HIPAA
Security Rule · mapping reference
DORA
DORA
ICT risk requirements · mapping reference

ISO/IEC 42001 — the AI management system standard. All 38 Annex A controls across the nine families, from AI policy through third-party and customer relationships. As the EU AI Act's obligations land, an AIMS is becoming a precondition for selling AI software rather than a differentiator.

What we automate, honestly: 3 of the 38 controls can be partially evidenced by scanning. 42001 is a management-system standard — whether an AI system harms a group is answered by an assessment and a named owner, not an API call. What isops gives you is the structure, the evidence trail and the audit-readiness around those decisions.

The difference

Most dashboards have two colours. That’s the bug.

Green means checked and clean. Red means checked and failing. So what colour is a resource nothing has ever looked at? On most tools it is green — because it has no findings, and no findings renders as success. That is not a cosmetic choice. It is a dashboard telling an auditor you verified something you never examined.

Exposure · All assets scope 800 of 800 resources · 20 asset groups all listed
Asset groupResourcesRiskOpen findings
Security Groups75 45 OPEN45
IAM Roles150 CLEAN0
DynamoDB Tables50 NOT ASSESSED —
API Gateways15 NOT ASSESSED —
Read the third and fourth rows. Those 65 resources have zero findings — and isops refuses to call them clean, because no scanner covers their resource type. They are grey, they report a dash rather than 0, and they are counted separately from what passed. An empty findings column and a clean bill of health are different claims, and only one of them is true here.

The same rule runs through the product. A control with no automated check sits in Not assessed against a denominator of all 93, never quietly dropped to flatter the percentage. A questionnaire question with nothing on file comes back unsupported rather than answered. A change view with no earlier scan says it is a baseline, not that nothing changed. Every one of those is a place a number could have been made to look better, and wasn’t.

FAQ

Questions, answered.

How long does setup take?

Under an hour for the first scan. Run the Docker image in your account, add a read-only IAM role ARN or AWS profile under Settings → Cloud accounts, and start the first scan. No agents in your workloads; nothing is written unless you approve a remediation.

What AWS permissions do you need?

Read-only. Specifically: SecurityAudit plus a few scoped Describe* and List* calls. See Security and architecture in the docs.

Where is my data stored?

In your environment. isops is self-hosted — it runs inside your own AWS account from the Docker image we ship, so credentials and evidence never leave your perimeter. Encryption at rest and in transit follow your account's configuration.

Can you replace my existing GRC tool?

For AWS workloads — yes. Posture, evidence and audit packs are first-class. The manual side is covered too: policies, risk register, vendor risk, training, incidents and internal audit all live in the platform. See the docs for the full capability list.

How does pricing work?

Flat annual fee. No per-seat charges. Scales with AWS account count. Book a demo for a quote.

What exactly does the platform cover?

An infrastructure graph of your AWS account, 15 scanners mapped to ISO 27001, ISO 42001 and SOC 2, and the full ISMS workspace — Statement of Applicability, risk, policies, evidence, CAPA, internal audit and an auditor portal. The documentation walks through all of it.

Retire the compliance spreadsheet.

30-minute demo. Real AWS account. Your first audit pack exported before we're done.