ProductsControlRegistry

ControlRegistry Invited beta Live

The governed control library: every framework, every control, and the common controls between them, read through one API.

DeliverySigned snapshot
ScoringAEGIS maps
AccessAPI-first
Frameworks15
What it is

ControlRegistry is the shared substrate: a superset control library where each framework's controls project from common controls, with graded STRM credit between them. Approve evidence once and the equivalent control is credited across every framework it maps to.

It is served as a governed, versioned asset: the backbone every product inherits. The only way to read the data is the ControlRegistry API.

How it works

The same steps for every reader. The last one is what you end up holding.

  1. 1Pick your frameworksISO 27001, SOC 2, PCI DSS, NESA. Fifteen to choose from.
  2. 2Controls projectEach framework's controls resolve onto the common set beneath them.
  3. 3Evidence onceApprove against a common control rather than once per framework.
  4. 4Credit is gradedFull, partial or none, each with a strength. Never an automatic pass.
  5. 5A signed snapshotVersioned and hashed. Your other products carry a copy of it.
See it

Screens from the running product, against a demonstration organisation. No customer data appears here.

Common controls
The common control library: 129 common controls across 26 domains, every one carrying authored guidance, with the framework controls that map to each.
One governed set of common controls, and every framework written against it.
A control
An ISO 27001 control page showing the published control text, the common control that carries it, that it is shared with three frameworks, and the guidance, requirements and real-world incidents behind it.
Each control states what it is, what carries it, and every framework it reaches.
How mappings are made
The STRM page: 1,517 candidate mappings between 129 common controls and 1,359 framework controls across 15 frameworks, with 1,105 analysed one control at a time and 412 placed at domain level, using the NIST IR 8477 relationship vocabulary.
1,517 mappings, and the page says which were analysed one at a time and which were placed at domain level.
Key capabilities
Common-control supersetOne governed library per domain; each framework projects off it.
Graded STRM creditFull, partial or no inheritance, each with a strength; never an automatic pass.
Per-control wikiScenarios, risks and real-world incidents, readable per control.
API-firstThe only way in is the ControlRegistry API. That is the differentiator.
What it produces

The artefacts, and who receives each one.

The signed library snapshotVersioned, hashed, and carried by every product that reads it, so the library being unreachable stops nothing.Goes to your platform team
The cross-framework mapWhich control in one framework answers which in another, and how strongly.Goes to your compliance lead
The control positionWhat you have claimed, with its evidence and its graded strength, control by control.Goes to your external auditor
Where it sits
SecureEdge GRCeverything, together
The three arms · assess, treat, proveeach one on its own
ControlRegistrythe library they all read
The library
15 frameworks1,359 controlsGovernedAPI-first
Release plan · design → development → live
DesignDevelopmentLive
FeatureMilestoneScope
Dark library UI (framework + control wiki)v1.0In MVP v1.0
AC pilot cross-framework mapsv1.0In MVP v1.0
Library asset + snapshot pipelinev1.1Planned
Live pull-credit UXv1.1Planned
The Vault + public APIv2.0Planned
Governance model (SoD / four-eyes)v2.0Planned

Milestones are roadmap targets, not shipped dates. Target for MVP v1.0: Live since Aug 2026. The stage above is the honest position today: Live.

What this establishes. These products prepare you for certification and audit. They do not award either. Every figure is derived from what your organisation reports, and is a documented position rather than an independent verification.

Priced per framework, per year

Provisioning is white-glove, never self-serve, and scope follows the due diligence review. If you would rather run it inside your own network, say so and we will talk about that too.

Talk to us