We read your AWS account.
Then we tell you what it is.
A relationship graph of your estate, the ISMS artefacts an auditor asks for, and evidence that never shows "not assessed" as "passed". Self-hosted. Read-only.
We discovered 800 resources in your AWS estate across 6 regions. They organize into 15 logical workloads and 1 inferred owner. The biggest workloads are ECS Cluster (web app), S3 Cluster (data tier), and IAM Cluster (serverless pipeline). 799 resources (over 99%) have no inferred owner — adding owner/team tags would dramatically improve traceability. We flagged 100 orphaned resources with no connections, 30 critical hot spots — start there for your first cleanup pass.
17 verified from AWS configuration · 76 not assessed, awaiting manual evidence.
1 critical · 4 high · 7 medium. Down from 20 last week.
214 time-stamped items. 36 auto-attached this week.
All 93 ISO 27001 Annex A controls are in scope on this example account: 17 scanner-checked, 76 awaiting manual evidence.
Fix: block public ACLs + enable bucket owner enforced. Draft fix →
Fix: rotate 3 keys, notify owners, attach evidence. Draft fix →
Fix: restrict inbound 22 to bastion CIDR / SSM only. Draft fix →
Fix: enable automated backups, 7-day retention min. Draft fix →
Fix: enable log-file integrity validation on trail. Draft fix →
ISO 27001 : 2022
SOC 2 · Type II
Where would you like to start?
Every answer is pulled from your own records — scans, controls, policies, evidence — and points straight back to where it came from.
GitHub
Jira
GitLab
Bitbucket Cloud
Okta
Google Workspace
Microsoft 365
1Password Business
Training Tracker
Vendor Risk Management
Access Reviews
Internal Audit Program
Management Review
Auditor Portal
Read-only · Auditor access tokenSecurity Questionnaires
Encryption is required by the Information Security Policy and mapped to control A.8.24.
Awareness training is mandated by the Security Awareness Training Policy and mapped to control A.6.3.
Pre-employment screening is required by the HR Security Policy and mapped to control A.6.1.
Control A.8.13 requires backups; a testing schedule is on file but not yet linked to a completed test record.
Nothing on file to cite — this one needs a written answer.
Every screen in this sidebar opens — all 31, grouped the way the product groups them, by the clause of the standard each one serves.
Most tools tell you a bucket is unencrypted.
We tell you who can reach it, by what path, and what changed.
Reachability, not just findings
We build a graph of your AWS account and resolve the relationships between resources — not only what exists, but what reaches what. IAM policy grants and security-group paths are both first-class edges, so "which identities can reach this bucket" is one hop, with the path attached.
On an example account: 800 resources, 2,000 relationships, zero dangling edges. Each artifacts bucket resolves to 30 roles with access.
The artefacts an auditor asks for
A full ISMS, not a scanner with a dashboard: Statement of Applicability, risk register, policy pack with approvals, evidence management, training records, incidents, corrective actions, internal audit, management review, access reviews, vendor management, a trust centre and an auditor portal. Security questionnaires are answered from your own evidence, with citations.
"Not assessed" is not "passed"
Controls are marked relevant separately from assessed, and a check that cannot run reports not assessed rather than a green zero. You always know the difference between "we checked and it is fine" and "we did not check". Most tools in this category blur that line.
What isops.ai does not do.
Narrow and provable beats broad and unfalsifiable — especially in this market.
AWS only
The collector is AWS-native. Other clouds are not at parity and we do not claim they are. This is a deliberate trade: depth in one cloud, with a relationship graph, over breadth without one.
Not a check-count play
15 scanners, not hundreds of checks. Open-source scanners cover far more individual checks and are free — if raw check volume is what you need, use one. Our value is the graph the findings hang on and the ISMS around it.
Scan-based, not real-time
Discovery runs when you run it, and each scan replaces the previous graph. We do not claim continuous monitoring.
We do not certify you
An accredited auditor does that. isops gets you audit-ready and gives the auditor something to read.
Three steps to audit-ready.
Connect AWS
Read-only IAM role or profile. 15-minute setup. The scanner never writes: the only writes are a remediation you explicitly approve, and — if you deploy the optional scheduled-scan stack — the scan reports it stores in your own S3 bucket and the notifications it publishes to your own SNS topic.
Scan & score
15 scanners, across IAM, storage, compute, data, secrets, logging and network. Critical findings surface first.
Ship evidence
Mapped to ISO 27001 and SOC 2 from the findings themselves. GDPR, HIPAA, PCI DSS and NIST 800-53 are available as mapping references.
Built with teams shipping today.
isops.ai is being built alongside a small cohort of design partners — security and platform leads at fintech, healthtech, and B2B SaaS companies preparing for SOC 2, ISO 27001, or HIPAA audits. We ship the product against their real evidence backlogs, not a roadmap deck.
discovered into the graph
Assessed frameworks and mapping references.
ISO/IEC 42001 — the AI management system standard. All 38 Annex A controls across the nine families, from AI policy through third-party and customer relationships. As the EU AI Act's obligations land, an AIMS is becoming a precondition for selling AI software rather than a differentiator.
What we automate, honestly: 3 of the 38 controls can be partially evidenced by scanning. 42001 is a management-system standard — whether an AI system harms a group is answered by an assessment and a named owner, not an API call. What isops gives you is the structure, the evidence trail and the audit-readiness around those decisions.
Most dashboards have two colours. That’s the bug.
Green means checked and clean. Red means checked and failing. So what colour is a resource nothing has ever looked at? On most tools it is green — because it has no findings, and no findings renders as success. That is not a cosmetic choice. It is a dashboard telling an auditor you verified something you never examined.
| Asset group | Resources | Risk | Open findings |
|---|---|---|---|
| Security Groups | 75 | 45 OPEN | 45 |
| IAM Roles | 150 | CLEAN | 0 |
| DynamoDB Tables | 50 | NOT ASSESSED | — |
| API Gateways | 15 | NOT ASSESSED | — |
The same rule runs through the product. A control with no automated check sits in Not assessed against a denominator of all 93, never quietly dropped to flatter the percentage. A questionnaire question with nothing on file comes back unsupported rather than answered. A change view with no earlier scan says it is a baseline, not that nothing changed. Every one of those is a place a number could have been made to look better, and wasn’t.
Questions, answered.
How long does setup take?
Under an hour for the first scan. Run the Docker image in your account, add a read-only IAM role ARN or AWS profile under Settings → Cloud accounts, and start the first scan. No agents in your workloads; nothing is written unless you approve a remediation.
What AWS permissions do you need?
Read-only. Specifically: SecurityAudit plus a few scoped Describe* and List* calls. See Security and architecture in the docs.
Where is my data stored?
In your environment. isops is self-hosted — it runs inside your own AWS account from the Docker image we ship, so credentials and evidence never leave your perimeter. Encryption at rest and in transit follow your account's configuration.
Can you replace my existing GRC tool?
For AWS workloads — yes. Posture, evidence and audit packs are first-class. The manual side is covered too: policies, risk register, vendor risk, training, incidents and internal audit all live in the platform. See the docs for the full capability list.
How does pricing work?
Flat annual fee. No per-seat charges. Scales with AWS account count. Book a demo for a quote.
What exactly does the platform cover?
An infrastructure graph of your AWS account, 15 scanners mapped to ISO 27001, ISO 42001 and SOC 2, and the full ISMS workspace — Statement of Applicability, risk, policies, evidence, CAPA, internal audit and an auditor portal. The documentation walks through all of it.
Retire the compliance spreadsheet.
30-minute demo. Real AWS account. Your first audit pack exported before we're done.