Solutions/By industry

Same operating system.
Industry-shaped edges.

The same platform, applied to the regulators, attack patterns and asset types of your sector. Framework mappings, Rego policy templates and the finding ontology are shared; what changes is which controls, exposures and workloads matter most.

Nine sectors

Where each sector starts.

Which shipped framework mappings apply, which policy templates matter first, and where custom frameworks fill the sector-specific gap.

Financial services

Banks, insurers, capital markets

DORA, PCI DSS v4, SOX ITGC and NIS2 ship mapped; FFIEC and OCC expectations are expressed as custom frameworks cross-walked to NIST 800-53.

  • DORA ICT-risk controls mapped to evidence
  • SOX ITGC continuous controls
  • PCI DSS v4 for payment flows
  • Third-party risk (TPRM) with vendor portal
  • Attack paths across identities and data stores
SharedOntology & engine
CustomFrameworks supported
Healthcare & life sciences

Hospitals, payers, biotech

HIPAA Security Rule ships mapped; HITRUST, GxP and 21 CFR Part 11 obligations are modelled as custom frameworks over the same evidence.

  • HIPAA safeguards mapped to cloud and code evidence
  • Data-store classification (PHI) in the ontology
  • DSPM findings linked to the workloads that read them
  • Custom frameworks for HITRUST and GxP obligations
  • Human-only disposition with reason codes
SharedOntology & engine
CustomFrameworks supported
US Federal & Public Sector

Civilian, defense, intelligence

NIST 800-53 Rev. 5 and the FedRAMP Moderate baseline ship as mappings. Fully self-hosted deployment keeps every byte inside your boundary. No authorization is held or claimed.

  • NIST 800-53 Rev. 5 control mapping
  • FedRAMP Moderate baseline mapping (no authorization)
  • Self-hosted or your-cluster scan band
  • Cosign-signed images, admission webhook
  • Hash-chained audit log for assessors
SharedOntology & engine
CustomFrameworks supported
Technology & SaaS

Multi-product platforms, AI labs

For platforms with thousands of services across multi-cloud. Engineer-first workflows: PR-based policy, signed builds, ephemeral environments.

  • Multi-cloud posture (AWS · Azure · GCP)
  • PR gates with auto-launched per-language scanners
  • SOC 2 + ISO 27001 mappings on one evidence chain
  • Supply-chain checks: typosquat, confusion, provenance
  • Blast radius from package to ingress
SharedOntology & engine
CustomFrameworks supported
Retail & consumer

Omnichannel, marketplaces, payments

PCI DSS v4 and CCPA/CPRA ship mapped. Continuous re-evaluation keeps control status current between assessments.

  • PCI DSS v4 continuous re-evaluation
  • CCPA / GDPR data-classification mapping
  • External attack surface discovery (EASM)
  • API discovery and DAST on storefront APIs
  • Exposure edges on internet-facing workloads
SharedOntology & engine
CustomFrameworks supported
Energy & utilities

Power, oil & gas, water

OT asset context from Claroty, Nozomi and Tenable OT connectors joins the same graph as IT findings. NERC CIP and IEC 62443 are modelled as custom frameworks.

  • OT connectors: Claroty, Nozomi, Tenable OT
  • Custom frameworks for NERC CIP and IEC 62443
  • Network zones as ontology entities
  • Fully self-hosted deployment option
  • Scan band inside your own cluster
SharedOntology & engine
CustomFrameworks supported
Media & entertainment

Studios, streaming, gaming

Content-security obligations such as TPN and MPA are modelled as custom frameworks; the platform supplies the code, image and cloud evidence behind them.

  • Custom frameworks for TPN and MPA controls
  • Data-asset classification for pre-release content
  • Image 360 for render and pipeline workloads
  • Secrets detection with git history
  • SIEM export to your existing SOC
SharedOntology & engine
CustomFrameworks supported
Industrial & manufacturing

Discrete, process, automotive

IEC 62443 and TISAX obligations as custom frameworks; supply-chain checks and SBOMs for the software you ship inside products.

  • SBOM generation, upload and diff
  • Typosquat and dependency-confusion checks
  • OT connectors for plant networks
  • Custom frameworks for TISAX and IEC 62443
  • Workload-to-image lineage for product firmware pipelines
SharedOntology & engine
CustomFrameworks supported
Higher education & research

Universities, research consortia

HECVAT v3 ships mapped; FERPA and CUI handling are modelled as custom frameworks cross-walked to NIST 800-53.

  • HECVAT v3 questionnaire responses from evidence
  • Custom frameworks for FERPA and CUI
  • Data-store classification for student data
  • SSO via OIDC/SAML with SCIM provisioning
  • Self-hosted option for research networks
SharedOntology & engine
CustomFrameworks supported
Frameworks shipped

Fourteen mapped frameworks.
Custom for the rest.

Mappings are cross-walked pair-wise from published crosswalks and closed transitively, so a control satisfied in one framework lights up its equivalents. Anything not listed is expressed as a custom framework with the same control model. SecurityVault holds no certification of its own.

SOC 2
AICPA TSC
ISO 27001
2022
NIST 800-53
Rev 5
NIST CSF
2.0
PCI DSS
v4.0
HIPAA
Security Rule
GDPR
Article map
CCPA / CPRA
California
CIS Controls
v8
NIS2
EU
DORA
EU
SOX ITGC
Audit
FedRAMP
Moderate · map only
HECVAT
v3
Custom
Your controls
Cross-walk
Transitive
What every sector gets

One platform, applied.

01

Control mappings

Fourteen shipped frameworks cross-walked to each other, plus custom frameworks with preventive, detective, corrective and compensating control types and an evidence frequency per control.

GRC console · API
02

Policy templates

Rego policy templates and a visual builder that compiles to Rego. Evaluation fails closed; every decision is Ed25519-signed.

OPA · Rego
03

Auditor portal

Read-only, invitation-based access for auditors with signed evidence and its own key authority. Questionnaire responses are generated from the same evidence.

Signed · revocable
04

Deployment choice

Hosted, your-cluster scan band, or fully self-hosted. Same charts, same signed images, same trust boundaries.

Helm · Cosign
05

Finding ontology

Every sector reads the same graph: which commit, which image, which workload, which identity, which data store. Attack paths and blast radius come from it.

52 entity types · 32 verbs
06

Regulatory feed

Regulatory change ingestion with impact assessment against your mapped controls, so a framework revision shows up as work items, not a surprise.

GRC · regulatory
Sector demo

Bring your regulator's
hardest question.

A 30-minute session on your sector: which mappings apply today, which controls need a custom framework, and how a scan result becomes evidence for both.