The Platform

One product. SemperWise One™

We build a single platform, not a catalogue. 28 modules across four capability groups, on one data model and one dashboard — so security, compliance and risk stop being three separate systems that disagree with each other.

Why one platform instead of five tools

The standard enterprise security stack is a scanner, a compliance tool, a risk register in a spreadsheet, a ticketing integration and a reporting layer somebody built in a BI tool. Each is defensible on its own. Together they produce a specific and expensive failure: the same asset exists as five different records, none of them agree, and a meaningful part of somebody's job becomes reconciling them.

SemperWise One™ is built as one product on one data model for exactly that reason. A vulnerability found by scanning, the control it affects, the risk it feeds, the ticket raised against it and the evidence produced when it is closed are all the same object seen from different angles — not five records that have to be kept in step by hand.

Protect 01 Comply 02 Govern 03 Intelligence 04 One data model · one dashboard nothing to integrate between modules AWS cloud Private cloud On-premises

Capability Groups

Four groups. One dashboard.

Start with the group that solves today's problem and enable the rest as you grow — same platform, same login, same evidence. No migration, no re-implementation.

01 — Protect Attack surface

Protect

Continuous discovery, automated testing and vulnerability management that prioritises by real business impact — not just CVSS scores.

24/7Monitoring
AutoDiscovery
APIFirst
Protect modules
02 — Comply Frameworks

Comply

ISO 27001, SOC 2, HIPAA, GDPR and DPDP mapped to live controls. Evidence collects itself and audits stop being an annual fire drill.

0Spreadsheets
LiveEvidence
MultiFramework
Comply modules
03 — Govern Risk & trust

Govern

One living risk register, third-party assessments and access governance — with the workflow to actually close what you find.

1Risk register
360°Vendor view
ZeroTrust ready
Govern modules
04 — Intelligence AI layer

Intelligence

The AI layer that reads your evidence, drafts your answers and reports to the board in language the board actually uses.

AICopilot
BoardReady
LiveReporting
Intelligence modules
Interface concept for SemperWise One™. Figures shown are illustrative — the platform is in active development, and each module is marked live or coming soon above.

Inside the Platform

28 modules. Switch on what you need.

The full module list as it stands. Modules marked "coming soon" are still in development — everything else is part of the current platform scope.

01 Protect 6 modules

  • Attack Surface Management
  • VAPT Automation
  • Vulnerability Management
  • Asset Inventory
  • Security Knowledge Base
  • Threat Detection & Monitoring Coming soon

02 Comply 6 modules

  • Compliance Automation
  • Continuous Controls Monitoring
  • Evidence Collection
  • Policy Generator
  • Compliance Calendar
  • Internal Audit Management

03 Govern 6 modules

  • Risk Register
  • Third-Party Risk Management
  • Vendor Assessment
  • Workflow Automation
  • Ticketing Integration
  • Identity & Zero Trust Coming soon

04 Intelligence 10 modules

  • AI Auditor
  • AI Compliance Copilot
  • AI Security Assistant
  • AI Chat Assistant
  • Document Intelligence
  • AI Recommendations
  • AI Reporting
  • Executive Dashboard
  • Board Dashboard
  • Customer Portal

Under the Hood

The engine behind the Protect modules.

Scanning is only useful if it sees enough. These are the published figures, refreshed as of 8 August 2026.

10,046 Detection rules Version-aware checks across 50 technology packs.
356,454 CVEs scored daily Every published CVE ranked by real-world exploit probability.
13,532 Active test templates Refreshed continuously as new techniques are published.
1,662 Known-exploited flaws The CISA KEV catalogue, tracked and matched automatically.

Full detection coverage

Built On AWS

Cloud-native, architected on AWS.

SemperWise One™ is a multi-tenant SaaS platform built on AWS. The same codebase deploys to our AWS cloud, to a customer private cloud, or on-premises where regulation demands it.

AWS cloud

Our managed SaaS runs on AWS, so capacity scales with scanning and monitoring load rather than being provisioned up front.

Elastic by design

Attack-surface discovery, continuous controls monitoring and AI analysis are bursty workloads — the architecture scales out and back down with them.

Private cloud

The same platform deploys into a customer-controlled cloud account when data residency requires it.

On-premises

A self-hosted deployment for regulated environments that cannot use shared infrastructure.

How It Runs

Continuous, not point-in-time.

Every module and every engagement follows the same six-stage loop, so findings from a one-off assessment feed the same register the platform monitors.

  1. 01

    Discover

    Assets, exposures and shadow IT mapped automatically across cloud and on-premise.

  2. 02

    Assess

    Automated VAPT, config review and control testing scored by business impact.

  3. 03

    Protect

    Prioritised remediation guidance routed into the tools your teams already use.

  4. 04

    Comply

    Controls mapped to ISO, SOC 2, HIPAA, GDPR and DPDP with evidence attached.

  5. 05

    Monitor

    Continuous controls monitoring and drift detection between formal audits.

  6. 06

    Assure

    Board-ready reporting, attestation packs and a defensible audit trail.

Questions

The platform — answered.

What is SemperWise One™?

SemperWise One™ is a cloud-native SaaS platform, architected on AWS, that unifies security, compliance, risk and AI governance in one dashboard. It covers 28 modules across four capability groups — Protect, Comply, Govern and Intelligence — on a single data model, so there is nothing to integrate between them and no reconciliation between tools.

Is it one product or a suite?

One product. Everything else is a module inside it, sharing one data model, one login and one set of evidence. This matters more than it sounds: in a suite of separately-acquired tools, an asset in the scanner and the same asset in the compliance register are two different records that drift apart. Here they are the same record.

Which modules are live today?

The platform section on this page marks every module as live or coming soon, and we keep it accurate rather than aspirational. As of now, 25 of 28 modules are live, with Threat Detection & Monitoring and Identity & Zero Trust still in development. We would rather show you that honestly than have you discover it during an evaluation.

Can we deploy it in our own environment?

Yes. The same codebase deploys to our managed AWS cloud, into a customer-controlled private cloud account where data residency requires it, or on-premises for regulated environments that cannot use shared infrastructure. This is a deliberate design decision — a meaningful share of Indian healthcare, financial services and government work simply cannot use multi-tenant SaaS.

Do we need the platform to use your services?

No. The services practice stands entirely on its own and many clients only ever use it. The platform is what makes continuous work practical to deliver — attack surface monitoring, continuous controls monitoring, managed vulnerability management — so clients on those services get access as part of the engagement.

Does it integrate with our existing tools?

Yes. Findings route into Jira, ServiceNow and standard service desks, cloud accounts connect read-only for continuous configuration monitoring, and everything is available through an API. Findings also export as SARIF and JSON so they load into code-scanning dashboards natively.

Next step

See it running against your environment.

A demo against a real target you control tells you more in thirty minutes than any deck. We will show you what it finds, including the parts that are still in development.