Security compliance and operations for space companies.
ISO 27001, NIS2 and GDPR mapped to one control set. Contractual security annexes answered from the same record. Technical gaps closed in the same platform.
One control set for every requirement.
The tools a space company needs to answer primes, agencies, tenders and auditors from one record.
Map a control once, satisfy every annex.
Live completion for ISO 27001, NIS2, GDPR and the security annexes in your contracts, all counting from one control set across every entity and jurisdiction.
The evidence pack generates on demand.
Auditor packs, customer questionnaires and board reports generated from live control state, in the format each prime or agency asks for.
Suppliers and systems, one inventory.
Subcontractors, components, corporate IT and operational systems with classification and ownership, where supply chain questions from a prime are answered and passed on.
See your weaknesses before a prime does.
Vulnerability findings, cloud checks and patch oversight, each with a recommended fix, each becoming evidence for the next annex.
Security events, triaged by business impact.
Agents stream events into the platform; what escalates is what matters to mission delivery, not what scored highest on a generic scale.
Sovereign by design.
Hosted on EU-owned infrastructure with European data residency. The models we run are open source, on our own hardware or served by European providers. Your data is never used to train a model.
The frameworks space companies are asked for.
ISO 27001
The certification named in tenders and prime supplier conditions. Controls, statement of applicability and evidence held in the platform.
NIS2
Reaches most space suppliers through customer contracts. The ten risk measures mapped to the same control set.
GDPR
Applies wherever Earth observation or user data includes personal data. Mapped to the same controls, evidenced once.
Start with the audit.
Fixed scope, priced by company size.
Security Audit
An independent vCISO Security Audit returns a ranked gap list against every framework in scope. The starting roadmap, and the document you show a customer.
Platform
GRC and Security Operations, switched on from day one. Annual contract, monthly billing, priced by employee band.
vCISO
A named security lead where a contract requires one. Scoping, risk decisions, audit-facing guidance, management reporting.