Six modules. One workspace.
Each CAvex module answers a practical governance need and connects back to risk, controls, evidence, assurance, and decisions.
A living register with real scoring
Score risks on inherent and residual impact, watch them move across a live heatmap, and route treatment to the right owner with due dates that don't slip.
- ✓5×5 likelihood / impact heatmap with drill-down
- ✓Inherent vs. residual scoring and risk appetite thresholds
- ✓Treatment plans linked directly to controls and evidence
Map once. Prove compliance everywhere
Maintain a single control library cross-walked to every framework you care about. Satisfy a control once and watch coverage update simultaneously.
- ✓40+ pre-built frameworks with automatic cross-mapping
- ✓Operating-effectiveness status with owner and source
- ✓One-click auditor export packages
Author, version, and attest policies
Author, version and distribute policies with attestation tracking and automatic renewals. Link policies to controls and evidence.
- ✓Version history with approval workflows
- ✓Employee attestation tracking
- ✓Automatic renewal reminders
Run audits end-to-end
Run internal and external audits end-to-end — requests, evidence, findings and reports in one workspace.
- ✓Structured audit request workflows
- ✓Evidence bundling for fieldwork
- ✓Finding tracking and remediation
Assess, tier, and monitor vendors
Assess, tier and continuously monitor vendors with automated security reviews and evidence collection.
- ✓Vendor tiering and risk scoring
- ✓Automated security questionnaire flows
- ✓Continuous monitoring integrations
Evidence that collects itself
Connect your stack once; CAvex collects, freshness-checks and maps evidence to controls on a schedule.
- ✓18+ native integrations
- ✓Scheduled freshness checks
- ✓Automatic control mapping
Uncover risk. Prove controls.
See your real compliance posture in a 30-minute walkthrough tailored to your stack.