Real-time security maturity score — updates as you improve controls
—
Loading
Your score is calculated from 7 security dimensions.
Improve your controls, resolve risks, and keep assets patched to increase your score.
Share link:
Score Breakdown
Score History
Score is recorded each time you visit this page. Improve controls to see your score rise.
Daily Tasks
Your ISMS responsibilities — ISO 27001 · NIST 800-53 · COBIT
0 of 0 completed0%
Risk Register
Incident Log
ISO 27001 A.16
Incident Response Playbooks
Step-by-step guided response for active security incidents
Active security incident?
Select the type of incident below to get immediate step-by-step guidance. Starting a playbook automatically creates an incident record and starts the SLA clock.
Vulnerability Risk live
Vulnerabilities ranked by business risk — CVSS × exploitability × asset criticality
Click to load CVEs...
Security Controls
ISO 27001:2022 Annex A — Track which controls you have in place
ISO 27001 domain coverage
Implementation % per Annex A domain
CurrentTarget
—
Loading controls...
Show:
Gap Assessment
Multi-framework compliance coverage
Policy Library
ISO 27001 Cl.5.1, Cl.7.5 — Information security policies
Policy Gaps Detected
Loading gap analysis…
Policy Gap Analysis
Coverage of the 20 policies typically expected for ISO 27001:2022 certification.
Loading gap analysis…
Edit Policy
Policy saved!
Risk Heatmap
ISO 27005 — Risk evaluation matrix
Risks above appetite threshold
Asset Inventory
ISO 27001 A.5.9 — All information assets
Asset Intelligence
▼
⏳ Loading asset intelligence...
Technology Stack
Tell Sentra what technology you use — get specific, actionable advice
Why does this matter?
When Sentra knows you use Microsoft 365 + FortiGate + VMware,
it gives you specific menu paths and commands instead of generic advice.
This saves hours of searching and makes guidance immediately actionable.
🏢 Organisation Profile
Tech stack saved! Sentra will now give you specific advice.
Change Management
ISO 27001 A.8.32 — Control of changes
Problem Management
ITIL 4 · ISO 27001 A.5.27 — Learning from incidents
A.5.28 Collection of evidence — every lifecycle, sign-off, and case-linking action, who did it and when
Time
Actor
Action
Entity
Before
After
Report Generator
Sentra-powered professional reports — reads your live data
Previously Generated Reports
Type
Title
Generated By
Date
Actions
NIST 800-53 Coverage
Derived from your ISO 27001 Annex A implementation · Rev 5
—
Overall NIST 800-53 Coverage
📊 Dual Framework Comparison
Coverage by NIST Family
Certification Readiness
ISO 27001:2022 — Your path to certification
Projected certification timeline
Loading...
—
Overall readiness
0%25%50%75%100% Ready
Priority Actions
ISO 27001 Clause Readiness
Industry Benchmarks
How you compare to your industry peers
ℹ️
Benchmarks based on public research. Loading sources...
Supplier Register
ISO 27001 A.5.19-5.22 — Third-party security risk management
Regulatory Compliance
Gap analysis against applicable regulations
Training & Awareness
ISO 27001 Cl.7.2 · Track security training completion and phishing simulations
SLA Dashboard
ITIL 4 — Service Level Management · Real-time SLA tracking
SLA Targets
Open Incidents — SLA Status
Admin Panel
Organisation settings, team, and security
Organisation Settings
Settings saved!
Change Management Rules
Account Information
AI Interaction Analytics
Click refresh to load analytics
All Organisations
Platform Tier
Current tier:
Team Members
Pending Invitations
Multi-Factor Authentication (MFA)
Active Sessions
Email Notifications
Loading preferences...
User Action Log
Token Usage —
Monthly tokens used
0
Today's Chat Usage
Weekly Comprehensive Analyses
Resets every Monday · Comprehensive = full org analysis questions
Usage History (Last 6 months)
All Organisations Usage
Security Authority Configuration
The Security Authority approves risk treatment plans and accepts
residual risk. Per ISO 27005, this must be a named individual with
appropriate authority.
Approves risks scoring 8+ (above appetite)
Notified for risks scoring 15+ (optional)
Risks above this score need approval (default: 12)
Complete these 5 steps to get the most from Sentra.
You only need to do this once — it applies to your whole team.
0 of 5 complete
❓
1
Describe Risk
2
Sentra Analysis
3
Review & Approve
Describe the Risk
Sentra is analysing your risk…
Identifying threats, controls, and remediation steps
Review & Approve
✨ AI-recommended · Edit any field before saving
Risk Score
Category
ISO 27001 Controls ✨ Auto-mapped
Business Impact
Evidence Required
Remediation Tasks ✨ AI-generated
Risk saved!
Edit Risk
▼
Status is derived from the lifecycle stage below the risk card — use the stage buttons or Accept Risk to change it.
Risk updated!
Accept Risk
Management sign-off — this records who accepted the residual risk and why. Restricted to CEO, CISO, Security Manager, and Super Admin.
Assign Risk Owner
Per ISO 27001 Cl.6.1.2 and ISO 27005, each risk must have
a named individual accountable for treatment.
External Owner (not in team)
They will receive an email invitation with platform access
💡 ISO 27005: The risk owner is responsible for
approving the risk treatment plan and accepting residual risk.
Log Security Incident
Incident logged!
Close Incident
ISO 27001 A.16.1.6 requires documented lessons learned before closure. Sentra has drafted this from the incident record — review and edit before confirming.
Incident closed!
Update Monthly KPIs
KPIs updated!
Add Asset
Asset saved!
📤 Import Assets from CSV
Upload a CSV file to bulk import assets.
Download the template to see the required format.
Step 1 — Download the template
Fill in your assets using the template CSV.
Required fields: name, asset_type
SENTRA AI DRAFT — auto-fill from an incident or risk
✨ Sentra is drafting your change request...
Change request submitted!
Did this change update a control?
Change completed: . If this change implemented or improved an Annex A control, update it now.
Add Change Rule
Rule saved!
Invite Team Member
They'll receive an email to set up their account.
Invitation sent!
Create Policy from Template
Select a standard ISO 27001 policy template. Claude AI will draft the complete policy for your organisation automatically.
New Policy
Policy created!
Ask a CISO Expert
Get expert advice from a certified CISO consultant. $120/hr billed in 30-minute increments. You will receive a detailed written response within 24 hours.
$120
per hour
30 min
minimum
24hr
response time
What happens next: Your question is reviewed by our CISO consultant team. You will receive a detailed, actionable response within 24 hours. For urgent requests, we aim to respond within 4 hours.
Question submitted! You will receive a response within 24 hours.
Previous consultations
Loading...
Upgrade required
Generate Report
Choose the reporting period. Defaults to the last 30 days.
Claude is reading your security data and writing your report...
This can take up to a minute for longer reports.
Report
Add Risk — ISO 27005 Framework
1. Risk Identification
2. Risk Analysis
Inherent Risk (before controls)
Inherent Score: 9
Control Effectiveness
Residual Risk (after controls)
Residual Score: 9
3. Risk Treatment
4. Risk Monitoring
Risk saved to register!
Upgrade your plan
Choose the plan that fits your organisation
🔹 Basic
$29/mo
Small business · Basic compliance
AI vCISO Chat
Simple risk register
Incident log
5 essential policies
CVE alerts
Annex A controls
NIST mapping
Ask CISO Expert
⭐ Most Popular
Professional
$99/mo
ISO certification · 100-500 staff
Everything in Essentials
Full ISO 27005 risk register
All 93 Annex A controls
NIST 800-53 mapping
Gap assessment + radar chart
Asset inventory
Ask CISO Expert — $120/hr
Audit management
🏆 Best Value
Advanced
$299/mo
Full GRC team · CISO · 500+ staff
Everything in Professional
NIST + SOC2 + PCI-DSS mapping
Supplier GRC module
Legal & regulatory register
Report generator
Priority CISO Expert + 1 free session/mo
Management review module
🏢 Enterprise
$999/mo
Large enterprise · MSSP · Unlimited
Everything in GRC Pro
White-label (logo + domain)
Multi-organisation management
API access + SSO
Unlimited users
Dedicated CISO + weekly sessions
Dedicated support SLA
Auto-detected Risks
Claude analysed your assets, CVEs, control gaps, and incidents. Review each risk and add the ones that apply to your organisation.
New Problem Record
Problem record created!
Edit Problem
Problem updated!
New Workflow Case
A case tracks the full lifecycle of a related incident, problem, change, risk, and control gap in one place.
Workflow case created!
Case
Add to Case
or create a new case
Configure SLA Targets
Set response and resolution time targets per priority level.