01 · Information Security Management System · ISO/IEC 27001
Purplecop One GRC
The whole GRC estate in one product. Frameworks, controls, evidence, risk, vendors, audit and awareness — every one of them a module on the same control library and the same evidence store, and every one of them AI-assisted.
14 modules, all included
Every module on one control library.
Frameworks75+ frameworks mapped once and reused everywhere.
ControlsOne control library. Test a control once, satisfy every framework mapped to it.
PoliciesAI-drafted policy, versioned, approved and mapped to the controls it satisfies.
EvidenceCollected automatically, timestamped, reused across every framework.
Risk RegisterScored, owned and tracked, fed by everything else in the product.
TPRMOnboard, assess, score and continuously monitor every vendor.
SecurEnd.AIAttack-surface discovery and cyber risk quantification. The offensive half.
DSPMDiscovers, classifies and protects sensitive data wherever it lives.
Audit ManagementInternal and external audit run end to end, with the auditor in the workspace.
CSATMaturity benchmarking against NIST CSF 2.0, ISO 27001 and the regulator packs.
LMSRole-based awareness training with per-user risk scores. Built in-house.
Phishing SimulationLive campaigns whose results feed the human-risk score directly.
Trust CenterThe public face of the posture, kept current by the evidence store.
Asset ManagementThe estate the controls actually apply to, discovered and owned.
5 AI agents, inside these modules
Every agent suggests. A person still decides.
Each one takes a single repetitive job inside a module you already use, quotes the sentence it based its answer on, and hands it to a person. None of them can change a record. A deterministic file checker inspects every upload before any of them sees it.
AGT-01
Evidence Examiner
lives in Evidence
Reads a document against the requirement and says whether it really proves the control — then quotes the exact sentence that made it decide.
About 12,000 documents a year get opened and asked the same question.
Never marks evidence approved. Never moves the workflow forward.
AGT-02
Policy Drafter
lives in Policies
Finds the right template out of the 1,605 we already own and tailors it to that customer’s departments, systems and review cycle.
It never writes a policy from scratch. A two-day job becomes twenty minutes.
Never publishes. Never approves. Never starts the sign-off.
AGT-03
Risk Challenger
lives in Risk Register
Once a month, compares every risk rating against how its controls are actually performing, and raises a challenge where the two disagree.
A register that has quietly gone out of date gets caught between audits instead of during one.
Never changes a rating. It raises a task for the risk owner.
AGT-04
Audit Reviewer
lives in Audit Management
Acts as a sceptical outside auditor on one requirement and gives a second opinion before the real auditor arrives.
Customers usually find out what an auditor thinks when the auditor tells them. By then it is on the record.
Never writes to the audit record. Never overrides your own conclusion.
AGT-05
Questionnaire Responder
lives in Trust Center
Drafts an answer to every question in a security questionnaire from your live compliance data — and refuses to answer where the proof is missing.
A 300-question questionnaire takes minutes instead of the week a security engineer normally loses to it.
Never sends an answer to the buyer. Never publishes to your Trust Center page.