Skip to content

CHAIOS

Sentry

Beta — free to start

GRC without the complexity.

Sentry is the compliance product of the CHAIOS suite — 22 modules across governance, risk, and compliance, built for organisations that need to stay on top of their obligations without drowning in spreadsheets.

Manage your compliance programs — Right Fit For Risk (RFFR), ISO27001, ISM, NIST CSF, PCI DSS, SOC2 — with custom and pre-defined cross-framework mappings.

Compliance Managers
GRC Analysts
Information Security Professionals
Auditors

A look inside

A complete GRC programme, not a spreadsheet.

From your compliance dashboard to the risk register, control library, Statement of Applicability and audit tracking — every module connected.

Compliance posture

0%

controls implemented

Risk heat map

Audits

Internal audit · Q3In progress
16 / 25 findings closedDue 30 Sep
CHAIOS Sentry — Risk, reimagined

One engine, from control gap to closed risk.

Your residual risk recalculates itself as your controls, findings and incidents change. The register comes to you.

Threat & business risks
Control gaps from your SoA
01
Identify
Threats + control gaps
02
Assess
Inherent → residual
03
Treat
Treat · Accept · Transfer · Avoid
04
Monitor
Continuous, not annual
Three feedback loops keep it live
Gap closure — control implemented, risk auto-closes
Effectiveness challenge — findings build up, re-assess
Realised risk — incident triggers post-incident review
Continuous re-assessment
Threat & business risks
Control gaps from your SoA
01
Identify
Threats + control gaps
02
Assess
Inherent → residual
03
Treat
Treat · Accept · Transfer · Avoid
04
Monitor
Continuous, not annual
Monitor continuously feeds back to Assess — not on a calendar.
Three feedback loops keep it live
Gap closure — control implemented, risk auto-closes
Effectiveness challenge — findings build up, re-assess
Realised risk — incident triggers post-incident review
Always-on guardrails
Running quietly in the background — so nothing slips.
Appetite & tolerance
Breaches flagged & escalated automatically.
Decay & attestation
Overdue reviews surface for one-tap sign-off.
Residual trajectory
A sparkline of how each risk has moved.
Attention digest
One view of what needs you today.
Cross-framework mapping

One control. Every framework.
One status, everywhere.

Implement a control once — it satisfies ISO 27001, the ISM, Essential Eight, SOC 2 and NIST at the same time, and that status flows straight into your SoA, risks and audits.

Control
Your control
implemented · evidence attached
Implemented once
Satisfies, automatically5 / 5 frameworks
ISO 27001 — Annex ASatisfied
ISM (ACSC)Satisfied
Essential Eight (ML1–ML3)Satisfied
SOC 2Satisfied
NIST CSF / 800-53Satisfied
One status — flows everywhere
Statement of Applicability
Applicability & gaps, kept current.
Risk register
Control-gap risks auto-surfaced.
Audits & evidence
Assurance scope, already mapped.
Australian frameworks

RFFR, the ISM and Essential Eight —
out of the box, in one SoA.

Global GRC tools weren't built for Australian government supply chains. Sentry combines ISO 27001:2022, the ISM, Essential Eight and DEWR's RFFR into one live Statement of Applicability — assess each control once, not four times.

RFFRRight Fit For Risk composes Australia's frameworks into one live SoA
ISO 27001:2022
Annex A controls
+
ISM (ACSC)
technical controls
+
Essential Eight
ML1–ML3
+
RFFR fundamentals
DEWR requirements
=
One live Statement of Applicability
assess each control once, not four times
● LIVE
Australian guardrails, built in
ISM classification scoping
up to OFFICIAL: Sensitive
Essential Eight maturity
carried from the ISM
Data-sovereignty aware
AU residency posture
Closed-loop assurance

From finding to fixed — and proven.

Schedule an audit, raise findings, turn each into a tracked corrective action, and verify it's closed — with the evidence accruing automatically as you go.

Central Calendar
schedules
Risk register
effectiveness
Plan
internal · external · ad-hoc
Audit
framework or ad-hoc
Finding
observation → major NC
Corrective action
ISO 10.2 · root cause
Verify & close
effectiveness review
Plan
internal · external · ad-hoc · on Central Calendar
Audit
framework or ad-hoc
Finding
observation → major NC · flags risk
Corrective action
ISO 10.2 · root cause
Verify & close
effectiveness review · proven
Evidence accrues at every step
Findings → corrective actions
Every finding stays on rails — nothing slips.
ISO 10.2 traceability
Root cause to verified closure.
Audit-ready export
Full report to XLSX in one click.
Third-party risk

Know your suppliers —
down to each application.

Most tools track a vendor as a single row. Sentry gives every vendor a full profile and a managed record for each application they run — so third-party risk reflects reality, not a checkbox.

N
Vendor
Northwind Cloud
Evidence on file
Trust centreSOC 2ISO 27001Contract / DPA
3 applications in scope
A record per application
Billing Platform
SSP · owners · baseline config
PROTECTED
Data Warehouse
SSP · owners · baseline config
OFFICIAL: Sens
Auth Gateway
SSP · owners · baseline config
OFFICIAL
Security & risk assessment
data types → inherent → controls → residual
Inherent riskbefore controls
mitigating controls & certifications
Residual riskdefensible & rated
Joined to your ISMS — vendors and their in-scope applications tie back into your SoA and controls, not beside them.

22 modules · 3 governance groups

Everything your GRC programme needs.

Governance

6 modules

Define your ISMS scope, manage policies, and keep your people accountable.

  • Dashboard
  • Scope
  • Documents
  • Personnel
  • Management Review
  • Training

Risk

5 modules

Identify, assess, treat, and monitor risks across your entire organisation.

  • Risk Register
  • Risk Treatment
  • Supply Chain
  • Incidents
  • Business Continuity

Compliance

8 modules

Map controls, track obligations, manage audits, and stay framework-ready.

  • Controls & Frameworks
  • Registers
  • Issues
  • Statement of Applicability
  • Reports & Export
  • Audits
  • Compliance Management
  • Change Management

Framework coverage

CHAIOS does not provide licensed framework content. Users must purchase their own licensed resources and material from the relevant standards bodies.

Right Fit For Risk (RFFR)ISO 27001:2022ACSC ISMNIST CSFPCI DSSSOC 2

Start your compliance programme today.

Sentry is in Beta and free to start — no credit card needed. Your feedback during the Beta directly shapes what we build next.