How it works

From unknown exposure to a board-ready answer.

Three steps, no black boxes. Every score traces back to a specific rule, and every rule traces back to a specific clause.

Step 01

Discover your data estate

Every finding starts with an accurate inventory. Add systems, vendors, locations, data assets, and data flows manually, or import an entire estate at once from a spreadsheet.

  • Six tracked entity types — Institution, System, Vendor, Location, Data Asset, and Data Flow — form a graph, not a flat list.
  • Bulk XLSX import validates every row before anything is saved — one bad row rejects the whole file, so you never get a silently incomplete inventory.
  • Read-only AWS and Azure connectors discover systems, storage, and encryption-key locations directly from your cloud accounts — no write access ever granted.

Step 02

Evaluate against nine cited rules

Your inventory is checked against a versioned regulation pack — nine rules covering the CBN circular and the parallel NDPA cross-border regime, each one citing its exact legal basis.

  • Rules are data, not hardcoded logic — when the CBN issues new interpretive guidance, the pack updates without a product rebuild.
  • Every finding names the specific system, vendor, or data flow that triggered it, and the exact clause it violates.
  • Grey-area categories (derived analytics, tokenised card data, fraud-model features) are flagged advisory, not silently judged — you document your own position.

Step 03

Remediate with a clear path

Findings become a weighted readiness score, a severity-ranked gap register, and a migration critical path — plus a tamper-evident evidence pack for when an examiner asks.

  • A single unresolved critical finding caps your readiness score — high finding counts can never mathematically outweigh one unfixed critical violation.
  • Evidence is content-hashed (SHA-256) at upload time — a changed file gets a new record, never an overwrite, preserving the audit trail.
  • Remediation tasks can point at a compliant hosting target once a finding requires physically migrating data.

See the full rule set behind every finding.