Security operations for lean teams

Operate the work. Keep the proof attached.

Aeptus connects the request, the work, its owner, and the proof across suppliers, assets, controls, documents, risk, and reporting.

Home Suppliers Assets Controls Documents Risk Reporting Automations
Start with what exists

Suppliers, assets, controls, documents, and owners stay visible.

Work from one queue

Decisions and follow-up work converge instead of disappearing between tools.

Attach evidence as work happens

Proof keeps its source, owner, status, and review context.

Automate the repetition

People keep judgement. Repeated checks and hand-offs can run for them.

The Aeptus operating core

Bring the mess. Turn it into governed work.

Aeptus ingests facts from people, files, and connected systems, normalizes them into shared objects, and uses that context to run work and prepare inspectable proof.

What comes in

Human answers and decisions
CSV and spreadsheet imports
Policies, contracts, and evidence
APIs, webhooks, and SaaS tools
Cloud, identity, and security systems

Aeptus operational context

One governed model of the work.

Designed for provenance
01 Ingest

Receive structured and unstructured facts without forcing one entry path.

02 Normalize

Map fields, clean values, resolve duplicates, and retain the source.

03 Govern

Connect suppliers, assets, controls, owners, decisions, and evidence.

04 Operate

Run reviews, tasks, approvals, evidence collection, and recurring workflows.

05 Prove

Prepare answers, proof packs, and reports from current approved context.

What goes out

Internal operating views
Buyer questionnaire answers
Proof packs and evidence sets
Board and management reports
Audit and external reports

The customer controls access, the connected model, and the final decision. Aeptus provides normalized context, permissions, provenance, and operational actions.

A security request becomes operational work

One buyer question crosses half the company.

Keep the buyer request, required change, accountable owner, and supporting evidence in one visible chain.

01

Receive the request

Keep the question, buyer context, due date, and requested proof together.

02

Find the affected operation

Link the request to policies, systems, identities, suppliers, and owners.

03

Resolve what is missing

Create review work, record exceptions, and retain the decision trail.

04

Collect first-party evidence

Bring configurations, logs, attestations, and documents into the same context.

05

Prepare the proof

Package the approved answer and its evidence so the buyer can inspect its basis.

06

Automate the next cycle

Schedule the check, evidence refresh, owner decision, and output instead of rebuilding the chain.

One operation across every security surface

Keep the work connected from request to proof.

Move from the buyer question to the owner, current evidence, approved answer, and next recurring check without rebuilding context.

See what needs attention

A working view, not a scorecard.

Pre-launch product map

Posture, assigned work, notifications, and operating context in one starting point.

Security pulse Current posture, work, and exposure.
Tasks Outstanding actions owned by the signed-in person.
Notifications Live changes and acknowledgements across modules.
Search Find routes, settings, and records from one surface.
Automation lever

Prioritise and route work, then notify the right owner when conditions change.

Evidence continuity

Proof should remember where it came from.

Keep evidence connected to its source, owner, date, governed object, and related decision.

Cloud configuration
Asset + control
Buyer-ready proof
Identity log
Access review
Review decision
Owner attestation
Exception + task
Proof pack context

Source → governed object → inspectable output

Automation is a layer

People keep the judgement. Aeptus carries the repetition.

Automation becomes useful when rebuilding a repeated check, hand-off, evidence refresh, or report is the expensive option.

01

Inspect and update manually

Use every product surface without hiding it behind automation.

02

Turn a repeated path into a workflow

Choose trigger, steps, owners, decisions, and outcome.

03

Connect systems that hold the facts

Integrations, APIs, and MCP move governed context in and out.

04

Meter completed automated work

Successful workflow execution is the commercial unit, not storage or internal steps.

Concrete capabilities

See what your team can operate in Aeptus.

Explore the capabilities for answering requests, maintaining first-party evidence, and preparing reusable proof.

Home See what needs attention. Posture, assigned work, notifications, and operating context in one starting point.
Security pulse

Current posture, work, and exposure.

Tasks

Outstanding actions owned by the signed-in person.

Notifications

Live changes and acknowledgements across modules.

Search

Find routes, settings, and records from one surface.

Suppliers Know the third parties in the chain. Directory, profiles, risk, privacy, evidence, and relationships stay attached to each supplier.
Supplier directory

Filter, edit, export, and act across suppliers.

Supplier profiles

Risk, documents, agreements, incidents, and history.

Privacy workflows

DPA status, renewals, and third-party data handling.

Supply-chain map

Relationships and regional exposure across suppliers.

Assets Know the internal estate. Track assets, owners, findings, scans, and testing campaigns in the same context.
Asset inventory

Browse, import, edit, and export internal assets.

Vulnerabilities

Prioritised findings and remediation context.

Security scans

On-demand and recurring discovery against assets.

Campaigns

Pentesting and adversary simulation across scopes.

Controls Operate the security rule. Definitions, occurrences, reviews, exceptions, drills, and evidence stay connected.
Control definitions

Scope, schedule, triggers, mappings, and versions.

Occurrences

Owner certification, sign-off, remediation, and proof.

Control reviews

Cross-framework validation and review work.

Readiness drills

Incident and continuity exercises with linked proof.

Documents Keep policy and proof connected. Policies, templates, contracts, imports, and sealed proof packs remain tied to work.
Managed documents

Policies, standards, procedures, templates, and provenance.

Template lifecycle

Library entries, variables, sections, and update review.

Contracts

Terms, obligations, renewals, and playbooks.

Proof packs

Point-in-time packages of controls, evidence, and documents.

Risk Make the decision inspectable. Governed rules, calculation, templates, history, and scoring policy expose the decision path.
Risk rules

Conditional logic and outcomes for evaluated entities.

Risk calculator

On-demand scoring with matched-rule contributions.

Finding templates

Governed draft, approval, and deprecation lifecycle.

Execution history

Match results, timing, and decision audit trail.

Reporting Turn live work into a usable answer. Operational dashboards, board packs, regulatory evidence, and custom reports retain source context.
Executive dashboards

Posture, compliance, exposure, and remediation signals.

Board packs

Narrative and live data in a board-ready output.

Regulatory reports

Evidence packages aligned to named frameworks.

Report builder

Reusable widgets, views, and export formats.

Automations Carry the repeated work. Templates, visual building, run health, integrations, APIs, and MCP connect the product map.
Automation library

Reusable starting points for security operations.

Visual builder

Triggers, steps, decisions, outcomes, and simulation.

Run health

Reliability and status across active workflows.

API and MCP

Programmatic and agent-facing access to governed context.

Start with the operation. Automate it when it repeats.

Join early access to help shape how first-party evidence becomes buyer-ready proof.

Join early access