Skip to content

CHAIOS

Sentry — Features

Beta — free to start

0 modules. One compliance programme.

Governance, risk, and compliance — fully connected. Every risk links to a control, every control links to a framework, every framework links to your SoA. No more spreadsheets trying to hold it all together.

6 modules

Governance

Define your ISMS scope, manage policies, and keep your people accountable.

Dashboard

Compliance posture at a glance — risk heatmap, SoA coverage %, open issues, treatment status, and recent activity.

Scope

Define your ISMS scope with 10 structured sub-sections: context, interested parties, RACI matrix, boundaries, objectives, and communication plan.

Documents

Policy and document library (policies, standards, procedures, templates, records) with evidence links to controls and personnel acknowledgement tracking.

Personnel

ISMS roles and responsibilities, competency matrix with gap analysis, and training record linkage. Track 13 predefined ISMS roles + custom roles.

Management Review

Meeting management, structured review inputs and outputs, action tracking, committee records, and continual improvement trail.

Training

Awareness, competency, certification, and induction programmes — with completion records, delivery methods, and compliance tracking per person.

5 modules

Risk

Identify, assess, treat, and monitor risks across your entire organisation.

Risk Register

Multi-tier registers (enterprise → operational → project) with 5×5 likelihood/impact scoring, heat maps, and 9-category taxonomy. Parent/child risk trees (Pro).

Risk Treatment

Link controls to risks, assign treatment decisions (treat/accept/transfer/avoid), and track action plans with owners, due dates, and effectiveness assessments.

Supply Chain

Vendor registry with criticality classification, data classification tracking, security assessments, inherent risk calculation, and historical assessment records.

Incidents

Full incident lifecycle (reported → contained → resolved → closed) with severity levels, regulatory notification tracking, personal data assessment, and root cause analysis.

Business Continuity

BCP, DRP, COOP, and Crisis plan management with asset recovery targets (RTO/RPO/MTPD), continuity testing, and test outcome records.

8 modules

Compliance

Map controls, track obligations, manage audits, and stay framework-ready.

Controls & Frameworks

Frameworks include Right Fit For Risk (RFFR), ISO 27001:2022, ISM, NIST CSF, PCI DSS and SOC 2 — with custom and pre-defined cross-framework mappings.

Registers

Asset, Cloud, Application, and Document registers — plus unlimited custom registers with flexible column schemas (text, number, date, select, boolean, URL).

Issues

Non-conformance and corrective action tracking (Clause 10.2) with severity levels, board and list views, root cause analysis, and risk linkage.

Statement of Applicability

Per-control applicability and justification, implementation status tracking, coverage dashboard, and multi-framework editable SoA (Pro).

Reports & Export

PDF and Excel exports of your SoA, risk register, and treatment plans — with your organisation's branding (Pro). Word export also supported.

Audits

Internal, external, and regulatory audit management — with scope definition, finding tracking per audit, and remediation status through to closure.

Compliance Management

Legal, regulatory, and contractual obligation tracking with a compliance calendar covering 10+ event types: audits, pen tests, DR testing, backups, training, and more.

Change Management

Change requests with full CAB workflow, risk assessment, rollback planning, test outcomes, and an auditable ISMS change control trail.

How modules work together

Three workflows that only work when everything's connected.

Risks link to controls. Controls link to frameworks. Findings link to issues. No copy-pasting between tools.

Workflow 01Risk Register + Treatment + Controls + SoA

Turn every identified risk into a tracked treatment plan.

Risk without treatment is just a list of worries. Sentry links each risk to treatment decisions, control assessments, and action plans — so you always know what's being done about it, and by whom.

  1. 1
    Log the risk with full context Risk Register
    Category, description, owner, likelihood, and impact — all captured in one form. The 5×5 matrix scores the inherent risk automatically.
  2. 2
    Assign a treatment decision Risk Treatment
    Treat, accept, transfer, or avoid. Each decision gets a justification, an owner, and a due date — no ambiguity about what was decided or when.
  3. 3
    Link controls that address the risk Controls
    Pull from any active framework. Mark each control as ineffective, partial, or effective — Sentry calculates residual risk automatically.
  4. 4
    Update SoA implementation status SoA
    As controls are linked and assessed, the Statement of Applicability updates. Coverage percentage rises. Auditors see the evidence trail.

Risk heat map

Workflow 02Audits + Documents + Issues + Controls

Walk into any audit fully prepared.

Auditors ask for evidence. Sentry makes sure you have it — policies linked to controls, controls linked to risks, issues tracked to closure, and everything timestamped.

  1. 1
    Create the audit plan with scope Audits
    Set the audit type (internal/external/regulatory), define the scope, assign the auditor, and schedule it in the compliance calendar.
  2. 2
    Map evidence documents to controls in scope Documents
    Drag policies, procedures, and records onto the controls they evidence. Acknowledgement status shows who has read each document.
  3. 3
    Record findings as issues with owners Issues
    Each finding becomes an issue — severity, root cause, corrective action, and due date assigned. Nothing slips through as "verbal feedback".
  4. 4
    Track remediation to closure Issues
    Issues move through statuses in real time. A complete audit trail — finding, action, closure date — is ready for the next audit cycle automatically.

Audits

Internal audit · Q3In progress
16 / 25 findings closedDue 30 Sep
Workflow 03Incidents + Issues + Risk Register + Compliance

When something goes wrong, know exactly what to do.

Sentry's incident workflow keeps you calm and compliant — from the moment something is reported to root cause analysis, regulatory notification tracking, and lessons learned.

  1. 1
    Log the incident with severity and category Incidents
    Data breach, malware, unauthorized access, phishing, availability — pick the category. Flag personal data involvement for regulatory purposes.
  2. 2
    Triage, contain, and create remediation tasks Incidents
    Move through lifecycle stages: reported → triaged → contained → resolved → closed. Each stage is timestamped and attributed.
  3. 3
    Link to a risk or raise a new one Risk Register
    If the incident exposed a risk gap, link it or create a new risk entry. The risk register reflects your real-world security posture — not just planned ones.
  4. 4
    Track regulatory notification if required Compliance
    For notifiable data breaches or incidents requiring reporting, Sentry tracks notification obligations and timelines as a compliance obligation.

Compliance posture

0%

controls implemented

A growing catalogue of compliance frameworks.

Map your controls once — Sentry shows cross-framework coverage automatically. Add a new framework and see which of your existing controls already apply.

Right Fit For Risk (RFFR)

ISM & Essential 8 based

ISO 27001:2022

93 Annex A controls

ACSC ISM

800+ controls

NIST CSF

100+ subcategories

PCI DSS

340+ requirements

SOC 2

64 trust criteria

Free to start. Pro when you're ready.

The free plan gives you everything to get started. Pro unlocks advanced features for teams running a full compliance programme.

Free

All the essentials — no credit card required.

  • All 22 GRC modules
  • Single-tier risk register (1 register, up to 25 risks)
  • 1 active framework — permanent on Free
  • Up to 25 issues and 25 treatments
  • Statement of Applicability (view-only)
  • 1 project · unlimited tasks
  • Incident management & document library
  • 1 user

Pro

Coming soon

Full-programme features for compliance teams.

  • Unlimited risks, issues & treatments
  • Multi-tier risk registers (parent/child trees)
  • All supported frameworks + cross-framework mapping matrix
  • Editable multi-framework Statement of Applicability
  • Approvals & sign-off — in-app + tokenised external links
  • Unlimited projects & tasks
  • PDF, Excel & Word exports with org branding
  • 5 team seats included (add more any time)

Start with Sentry today.

Sentry is in Beta and free to start — every module included, no credit card needed. Your feedback helps shape what we build next.