Suppliers, assets, controls, documents, and owners stay visible.
Security operations for lean teams
Operate the work. Keep the proof attached.
Aeptus connects the request, the work, its owner, and the proof across suppliers, assets, controls, documents, risk, and reporting.
Decisions and follow-up work converge instead of disappearing between tools.
Proof keeps its source, owner, status, and review context.
People keep judgement. Repeated checks and hand-offs can run for them.
The Aeptus operating core
Bring the mess. Turn it into governed work.
Aeptus ingests facts from people, files, and connected systems, normalizes them into shared objects, and uses that context to run work and prepare inspectable proof.
What comes in
What goes out
The customer controls access, the connected model, and the final decision. Aeptus provides normalized context, permissions, provenance, and operational actions.
A security request becomes operational work
One buyer question crosses half the company.
Keep the buyer request, required change, accountable owner, and supporting evidence in one visible chain.
Receive the request
Keep the question, buyer context, due date, and requested proof together.
Find the affected operation
Link the request to policies, systems, identities, suppliers, and owners.
Resolve what is missing
Create review work, record exceptions, and retain the decision trail.
Collect first-party evidence
Bring configurations, logs, attestations, and documents into the same context.
Prepare the proof
Package the approved answer and its evidence so the buyer can inspect its basis.
Automate the next cycle
Schedule the check, evidence refresh, owner decision, and output instead of rebuilding the chain.
One operation across every security surface
Keep the work connected from request to proof.
Move from the buyer question to the owner, current evidence, approved answer, and next recurring check without rebuilding context.
See what needs attention
A working view, not a scorecard.
Posture, assigned work, notifications, and operating context in one starting point.
Prioritise and route work, then notify the right owner when conditions change.
Know the third parties in the chain
Supplier context that survives the questionnaire.
Directory, profiles, risk, privacy, evidence, and relationships stay attached to each supplier.
Schedule reviews, request evidence, refresh signals, and open follow-up when information expires.
Know the internal estate
Assets, vulnerabilities, and ownership together.
Track assets, owners, findings, scans, and testing campaigns in the same context.
Run checks, create remediation work, refresh ownership, and collect resulting evidence.
Operate the security rule
A control is work with an owner and evidence.
Definitions, occurrences, reviews, exceptions, drills, and evidence stay connected.
Create occurrences, ask owners, gather evidence, escalate overdue work, and record outcomes.
Keep policy and proof connected
Documents that participate in the operation.
Policies, templates, contracts, imports, and sealed proof packs remain tied to work.
Refresh documents, propose structure, chase approvals, and assemble requested proof.
Make the decision inspectable
Risk rules explain how the result was reached.
Governed rules, calculation, templates, history, and scoring policy expose the decision path.
Re-evaluate when data changes, then open or update the governed finding.
Turn live work into a usable answer
Reporting for the person who forwards the result.
Operational dashboards, board packs, regulatory evidence, and custom reports retain source context.
Generate recurring reports, deliver them, and flag stale or incomplete source evidence.
Carry the repeated work
A workflow is a completed operational outcome.
Templates, visual building, run health, integrations, APIs, and MCP connect the product map.
Count the successful workflow outcome, not every internal step or stored record.
Evidence continuity
Proof should remember where it came from.
Keep evidence connected to its source, owner, date, governed object, and related decision.
Source → governed object → inspectable output
Automation is a layer
People keep the judgement. Aeptus carries the repetition.
Automation becomes useful when rebuilding a repeated check, hand-off, evidence refresh, or report is the expensive option.
Inspect and update manually
Use every product surface without hiding it behind automation.
Turn a repeated path into a workflow
Choose trigger, steps, owners, decisions, and outcome.
Connect systems that hold the facts
Integrations, APIs, and MCP move governed context in and out.
Meter completed automated work
Successful workflow execution is the commercial unit, not storage or internal steps.
Concrete capabilities
See what your team can operate in Aeptus.
Explore the capabilities for answering requests, maintaining first-party evidence, and preparing reusable proof.
Home See what needs attention. Posture, assigned work, notifications, and operating context in one starting point.
Current posture, work, and exposure.
Outstanding actions owned by the signed-in person.
Live changes and acknowledgements across modules.
Find routes, settings, and records from one surface.
Suppliers Know the third parties in the chain. Directory, profiles, risk, privacy, evidence, and relationships stay attached to each supplier.
Filter, edit, export, and act across suppliers.
Risk, documents, agreements, incidents, and history.
DPA status, renewals, and third-party data handling.
Relationships and regional exposure across suppliers.
Assets Know the internal estate. Track assets, owners, findings, scans, and testing campaigns in the same context.
Browse, import, edit, and export internal assets.
Prioritised findings and remediation context.
On-demand and recurring discovery against assets.
Pentesting and adversary simulation across scopes.
Controls Operate the security rule. Definitions, occurrences, reviews, exceptions, drills, and evidence stay connected.
Scope, schedule, triggers, mappings, and versions.
Owner certification, sign-off, remediation, and proof.
Cross-framework validation and review work.
Incident and continuity exercises with linked proof.
Documents Keep policy and proof connected. Policies, templates, contracts, imports, and sealed proof packs remain tied to work.
Policies, standards, procedures, templates, and provenance.
Library entries, variables, sections, and update review.
Terms, obligations, renewals, and playbooks.
Point-in-time packages of controls, evidence, and documents.
Risk Make the decision inspectable. Governed rules, calculation, templates, history, and scoring policy expose the decision path.
Conditional logic and outcomes for evaluated entities.
On-demand scoring with matched-rule contributions.
Governed draft, approval, and deprecation lifecycle.
Match results, timing, and decision audit trail.
Reporting Turn live work into a usable answer. Operational dashboards, board packs, regulatory evidence, and custom reports retain source context.
Posture, compliance, exposure, and remediation signals.
Narrative and live data in a board-ready output.
Evidence packages aligned to named frameworks.
Reusable widgets, views, and export formats.
Automations Carry the repeated work. Templates, visual building, run health, integrations, APIs, and MCP connect the product map.
Reusable starting points for security operations.
Triggers, steps, decisions, outcomes, and simulation.
Reliability and status across active workflows.
Programmatic and agent-facing access to governed context.
Start with the operation. Automate it when it repeats.
Join early access to help shape how first-party evidence becomes buyer-ready proof.