Skip to content
Product

Six modules. One workspace.

Each CAvex module answers a practical governance need and connects back to risk, controls, evidence, assurance, and decisions.

Risk register

A living register with real scoring

Score risks on inherent and residual impact, watch them move across a live heatmap, and route treatment to the right owner with due dates that don't slip.

  • 5×5 likelihood / impact heatmap with drill-down
  • Inherent vs. residual scoring and risk appetite thresholds
  • Treatment plans linked directly to controls and evidence
Explore →
Risk Register42 open
Third-party concentration — payments
Vendor Risk · RSK-014
Inherent 20Residual 12Mitigate · on track
Privileged access sprawl — core banking
Cyber · RSK-031 · 4 controls linked
Inherent 25Residual 15Mitigate · overdue
Recovery testing coverage — data centers
Resilience · RSK-047
Inherent 12Residual 8Mitigate · on track
RESIDUAL TREND · 6 MONTHS
▼ improving
Controls & frameworks

Map once. Prove compliance everywhere

Maintain a single control library cross-walked to every framework you care about. Satisfy a control once and watch coverage update simultaneously.

  • 40+ pre-built frameworks with automatic cross-mapping
  • Operating-effectiveness status with owner and source
  • One-click auditor export packages
Explore →
Control health412 passing26 retest due14 failing
Quarterly access review
IAM-042 · 6 evidence items
NCA ECCISOJUN 12Passing
Patch management SLA
CTL-118 · linked to RSK-031
NCA ECCSAMAISOAPR 03Retest due
Backup restoration test
BCM-012 · 4 evidence items
SAMADORAJUN 28Passing
Policy management

Author, version, and attest policies

Author, version and distribute policies with attestation tracking and automatic renewals. Link policies to controls and evidence.

  • Version history with approval workflows
  • Employee attestation tracking
  • Automatic renewal reminders
Explore →
Policy library38 published4 in review
Information Security Policyv4.2 · owner: CISO office · 12 linked controlsPublished
Data Protection & Privacy Policyv2.1 · owner: DPO · mapped to PDPLPublished
Acceptable Use Policyv3.0 draft · 2 of 3 approvalsIn review
Audit management

Run audits end-to-end

Run internal and external audits end-to-end — requests, evidence, findings and reports in one workspace.

  • Structured audit request workflows
  • Evidence bundling for fieldwork
  • Finding tracking and remediation
Explore →
Assessment workspaceQ2 readiness review18/24 complete
NCA ECC domain self-assessment
Owner: GRC · due JUL 15
In progress
Vendor security questionnaire — CloudCo
Owner: Procurement · 12 of 15 answered
In progress
Control owner attestation — IAM controls
Owner: IT · completed JUN 28
Complete
Vendor & third-party risk

Assess, tier, and monitor vendors

Assess, tier and continuously monitor vendors with automated security reviews and evidence collection.

  • Vendor tiering and risk scoring
  • Automated security questionnaire flows
  • Continuous monitoring integrations
Explore →
Vendor register9 critical tier148 total
Cloud hosting provider
Core infrastructure · ISO 27001 certified
CriticalA−JUL 21
Payment processor
2 open findings · remediation due AUG 05
CriticalBSEP 12
HR & payroll platform
Processes personal data · PDPL scope
HighAOCT 02
Evidence automation

Evidence that collects itself

Connect your stack once; CAvex collects, freshness-checks and maps evidence to controls on a schedule.

  • 18+ native integrations
  • Scheduled freshness checks
  • Automatic control mapping
Explore →
Evidence workspaceQ2 collection324/380 approved
Approved 274In review 50Expiring 12
Access review export — Q2IAM-042 · approved · reused in 3 frameworksApproved
Firewall ruleset reviewNET-007 · awaiting reviewerIn review
Get started

Uncover risk. Prove controls.

See your real compliance posture in a 30-minute walkthrough tailored to your stack.