Product

A virtual CISO, not a checklist

vCISO.AI runs the work a security leader runs: program, policies, evidence, frameworks, and the questions in between. Here is what that looks like.

Security program builder

Start with a plan, not a blank page

Onboarding asks about your company, your stack, and your goals. Your AI vCISO turns the answers into a gap analysis, a control set sized to your business, and a phased roadmap with owners and due dates.

  • Gap analysis against SOC 2 and ISO 27001 on day one
  • Roadmap phased from foundation to audit ready
  • Readiness score that updates as you work
Gap analysis Done
66 controls assessed from your answers
1. FoundationComplete
2. PoliciesIn progress
3. ImplementationUp next
AI policy writer

Policies written for your company, not a template dump

Each policy is drafted in your context with the controls it covers mapped right in the document. Review, edit, and approve with a real lifecycle: draft, review, approved, published, with versions and annual review dates.

  • Twenty standard policies, from Access Control to Vendor Management
  • Every policy shows the SOC 2 and ISO 27001 requirements it satisfies
  • Version history and approval trail your auditor will ask for
Access Control Policy AI draft v1
Control mapping
SOC 2 CC6.1CC6.3ISO A.5.15A.8.5
Review: annual Approve
Evidence automation

Upload once, count it everywhere

Drop in a screenshot, export, or report. AI reads it, suggests the controls it satisfies with a confidence level, and tracks validity windows so Type 2 evidence never silently expires.

  • AI mapping from artifact to controls, you accept or reject
  • Validity windows and expiring evidence alerts
  • Connectors for AWS, GitHub, Okta and more are rolling out
okta-mfa-policy.pngUploaded just now
Analyzed
Multi factor authenticationCC6.1 · A.8.5
high
Authentication standardsA.5.17
medium

Valid for 180 days, expiry tracked for Type 2

Cross framework mapping

One control set. Both frameworks.

SOC 2 criteria and ISO 27001 controls map into one shared control library. Implement a control once and it counts toward every requirement it satisfies in both frameworks. Adding a framework reuses most of the work you already did.

  • 61 SOC 2 criteria and 93 ISO 27001 Annex A controls, cross mapped
  • Per framework readiness scoring from the same control set
  • No duplicate evidence, no second spreadsheet
SOC 2CC6.1 Logical access
SOC 2CC6.6 Boundary auth
Multi factor authentication Implemented once
ISO 27001A.8.5 Secure authentication
ISO 27001A.5.17 Authentication info
Questionnaire automation

Stop answering the same questionnaire by hand

Paste the security questionnaire a prospect sent you. Your vCISO drafts every answer from your real program, cites the controls and policies that back each one, and flags anything it cannot support so you never send a claim you cannot stand behind.

  • Answers grounded in your controls, policies, and evidence
  • Honest flags when the program does not support a yes
  • Review, edit, approve, and export to CSV
Acme Corp security review42 questions
Do you enforce MFA?Yes
cc.access.mfa
Is data encrypted at rest?Yes
cc.crypto.at-rest
Annual penetration testing?Partial
needs review

Drafted from your program, you review and export

Trust Center

Prove your security without the back and forth

Publish a public trust center on your own branded URL that shows your frameworks, controls, and policies in real time. Send the link instead of filling out the next questionnaire, and let prospects request your reports right there.

  • Live posture pulled straight from your program
  • Gated document requests that capture every lead
  • Your branded subdomain, powered by vCISO.AI
Security at Acme Trust Center
SOC 2Audit ready
ISO 27001In progress
Controls implemented54
Request SOC 2 report
Powered by vCISO.AI
vCISO chat and human handoff

Ask your vCISO. Escalate to ours.

The chat knows your program: your controls, your policies, your evidence, your roadmap. Ask what is left before the audit or tell it to update a task. When you need a pentest or a human expert, it hands you to vCISO.com.

  • Answers grounded in your actual compliance data
  • Can update tasks and point you at gaps
  • One click handoff to human practitioners at vCISO.com
What is left before our SOC 2 audit?
Checked control status Read the roadmap

Three things: finish quarterly access reviews, upload backup restore evidence, and publish the Incident Response Plan. All three are on your roadmap this month.

Need a pentest? Hand off to the humans at vCISO.com

From zero to audit ready

Three steps. Most of the work is not yours.

1. Tell us about your company

A short onboarding covers your stack, team, and goals. Your AI vCISO turns it into a gap analysis and a phased roadmap.

2. Review and approve

It drafts your policies and tasks. You approve them, assign owners, and knock out the roadmap together.

3. Walk into the audit ready

Every control has its policy and evidence attached, across SOC 2 and ISO 27001 at the same time.

Automated evidence, from the tools you trust

Connectors are rolling out now. Manual evidence upload with AI mapping works today, so nothing blocks your audit.

AWS

IAM policies, CloudTrail logging, encryption settings, and backup configuration, pulled as evidence.

Google Cloud

Google Cloud

Project IAM, audit logs, and storage encryption mapped to your access and logging controls.

Microsoft Azure

Entra ID access reviews, activity logs, and security defaults collected on a schedule.

GitHub

GitHub

Branch protection, review requirements, and dependency alerts as change management evidence.

Okta

Okta

MFA enforcement, user lifecycle, and app assignments for your identity controls.

Google

Google Workspace

2 step verification, group membership, and offboarding evidence straight from your directory.

Coverage in numbers

61

SOC 2 criteria covered

93

ISO 27001 controls mapped

One control set behind both frameworks. Do the work once and most of it carries straight into your second audit.

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

Product

Getting started

Did not find what you were looking for? Talk to us.

Your security program starts today.

Sign up, answer a few questions, and get your free gap analysis and roadmap. Pay when you are ready to do the work.