Skip to content
AudiDesk

AI-powered security & compliance assessment platform

Turn your software inventory into an actionable security audit and GRC assessment.

AudiDesk ingests the inventory you already export — by file or by scheduled connector — scores it with a deterministic rule engine, and produces the findings, registers, drafted documents and reports an assessment actually requires, in English, French and Arabic.

Request access

Access is by invitation while early workspaces are onboarded.

The pipeline

From evidence to verified closure, one domain model

This is the literal shape of the product, not a slogan. Every screen, register, and report in AudiDesk is a stage of this pipeline.

  1. 01

    Evidence

    Inventory files, scanner reports, directory exports, benchmark reports, document evidence and scheduled connector syncs — six sources, one evidence model.

  2. 02

    Analyze

    Names normalized, lifecycle matched, shadow IT flagged against your catalogue.

  3. 03

    Score

    A versioned rule engine weighs the facts. No language model in the loop.

  4. 04

    Finding

    Framework-mapped, severity-ranked, promotable into the risk register.

  5. 05

    Remediation

    Every finding names what closes it: artifact, owner, target date — and the artifact can be drafted from a template.

  6. 06

    Verify

    The next snapshot closes what was fixed, and records why.

  7. 07

    Report

    Seven reports and the Statement of Applicability, as printable HTML and editable DOCX, in the language your reader needs.

Where evidence comes from

Six sources, one evidence model

Controls, reports and verification consume evidence without caring where it came from. That is why adding a source adds a producer, not a second product — and why one assessment can hold as many of these as you have, for one assessment against your plan.

01

Inventory file upload

An ESET PROTECT export, or a generic CSV or Excel inventory. Semicolon-delimited files, byte-order marks and console-localized column headers are handled; anything the header fingerprint cannot place, you map by hand once and AudiDesk remembers.

Generic uploads carry no vulnerability data, so they feed lifecycle status, shadow IT and inventory controls only. The upload screen states this before you commit.

02

Vulnerability and patch report

A Microsoft Defender vulnerability export or a Tenable Nessus scan, as CSV, TSV or an Excel workbook — the format is read from the file itself, so a renamed export still works. Defender states each update alongside whether it is installed; Nessus states host-scoped CVEs, and where it names no updates the run says so rather than reporting a patched estate.

You name the scanner rather than us guessing: Defender and Nessus both write a severity and a CVE column on different scales, and guessing wrong would score your estate against the wrong one.

03

Identity and access export

An Active Directory user export from a PowerShell command the screen gives you, or a scheduled pull from Microsoft Entra. Dormant accounts, dormant privileged accounts, shared accounts, stale service accounts, guest exposure and password-policy gaps come out of it.

A directory export carries no multi-factor data, so every account is reported with an unknown MFA state rather than a passing one. Entra, through the connector, does carry it.

04

Benchmark / hardening report

One row per control per device: host, benchmark, version, control, result, and the expected and observed values where the producer states them. CSV, TSV, Excel or JSON. A CIS-CAT or other assessor export is mapped onto the published AudiDesk benchmark schema column by column.

This is the source that answers the question a device-compliance verdict cannot: not “does a platform judge this device compliant” but “does it match the baseline you set”. A skipped, inapplicable or errored check is reported as the assessor’s silence — never as a pass.

05

Document evidence

Policies, procedures, diagrams and screenshots uploaded against the controls they support, each with a sensitivity class, a malware scan and a validity period, so evidence going stale reappears as a gap rather than quietly ageing.

This is the source that closes the distance between the controls an inventory can evidence and the 93 an ISO 27001 assessment requires — and evidence requests are how you get it out of the people who actually hold it.

06

Live connectors

A scheduled pull from ESET Connect, Microsoft Intune, SentinelOne, Lansweeper or Microsoft Entra ID, hourly through weekly. Snapshots arrive on their own, verification runs on its own, findings open and close, and drift alerts name what changed since the last one.

  • ESET Connect
  • Microsoft Intune
  • SentinelOne
  • Lansweeper
  • Microsoft Entra ID

Credentials never enter the database: a connector record holds the name of a secret, and only the sync worker reads its value. What a connector can evidence is what it actually reports — ESET adds vulnerabilities, Intune adds device configuration compliance, Entra adds directory accounts with a real multi-factor state; SentinelOne and Lansweeper feed lifecycle status, shadow IT and inventory controls the way a generic file does.

Connectors are the continuous-monitoring tier

Everything else on this page is a point-in-time assessment: you supply evidence, AudiDesk assesses it, you deliver the result. Live connectors are what turn that into ongoing monitoring — snapshots on a schedule, drift alerts when new shadow IT appears, when a product you run becomes known-exploited, when an end-of-life date passes or when evidence expires, and an overdue view of every finding past its remediation target. It ships, and it is a distinct tier, priced separately.

File upload never goes away. Nobody hands over API credentials during an evaluation, and a one-off engagement needs a one-off path.

What ships in the platform

Annex A controls
93ISO/IEC 27001:2022 Annex A controls modeled from day one, each with its own status, owner, justification, evidence and effectiveness record.
Live connectors
5Sources that sync on their own schedule — ESET Connect, Microsoft Intune, SentinelOne, Lansweeper and Microsoft Entra ID. Between them they carry inventory, device configuration compliance and directory accounts.
Document templates
14Policy, procedure, standard, form and checklist templates a remediation artifact can be drafted from.
Languages
3Languages for the interface and every generated report — English, French and right-to-left Arabic.

What you get

Reports are views over the assessment, not the product

The finding, control, risk and evidence model is the system of record. Nothing is stored: every document is re-rendered from its snapshot, so it always matches the data it cites — regenerate any of them, at any time, in any of the three languages.

Seven reports

  1. 01

    Software Risk Score

    Every product ranked by deterministic risk, with the inputs behind each score.

  2. 02

    Vulnerability & Exposure

    CVE-level exposure with known-exploitation flags, likelihood scores, and affected assets.

  3. 03

    EOL / EOS

    What is out of support, what is approaching it, and where it is installed.

  4. 04

    Shadow IT

    Software absent from your approved catalog, weighted by risk category.

  5. 05

    ISO 27001 assessment

    All 93 Annex A controls as your organization assessed them — and an explicit register of everything not assessed.

  6. 06

    GRC

    Governance, risk, and compliance in one document: policy register, risk register, control coverage.

  7. 07

    Executive GRC

    The one-page posture summary with trend against the previous snapshot.

Statement of Applicability

All 93 Annex A controls with applicability, justification, implementation status, linked evidence and effectiveness, exported as a printable register. An exclusion with no stated justification is flagged, because that is an ISO defect rather than a formatting one.

Drafted policies and procedures

Fourteen templates spanning policies, procedures, standards, forms and checklists. Prose is drafted into fixed named sections behind a document-control block, and it becomes your policy at the moment a named person approves it.

Framework crosswalk

One assessment read through more than one lens. ISO/IEC 27001:2022 Annex A carries the live control library; SOC 2, NIST CSF 2.0 and CIS Controls v8 are reached through a crosswalk from it.

  • ISO/IEC 27001:2022
  • NIST CSF 2.0
  • CIS Controls v8
  • SOC 2

Crosswalk coverage is mapping coverage: it says which ISO controls reach a framework, not that the framework has been assessed, and it is always reported with its unmapped remainder. NIS2, CIS v8 IG1, GDPR Article 32 and the Saudi NCA ECC go further — each has a requirement board that names, requirement by requirement, what the platform can say and what it cannot reach at all. DORA is named in the product as planned and carries nothing yet.

Features

The engine underneath

01

Five evidence domains, one finding model

Software inventory, vulnerability and patch reports, identity and access, endpoint security and operating-system configuration all normalise onto the same findings, controls and remediation plans — so an end-of-life product, a missing update, a dormant privileged account and a non-compliant device are numbers you may legitimately compare. Vendors are adapters, not products: ESET, Defender, Nessus, Entra, Intune, SentinelOne and Lansweeper feed the domains, and nothing downstream learns which one spoke.

02

One assessment, as many sources as you have

An assessment is the container, not the file. Attach an inventory export, a scanner report, a directory export and a hardening report in one go — or add the next one a week later — and it stays one assessment against your plan however many sources it holds. Every source states how it reached us, and the whole assessment is reported at the strength of its weakest one: a connector pull is machine-attested, an upload is a declaration, a typed answer is an assertion.

03

Coverage stated, never implied

Before you export anything, the platform says what the evidence on hand can and cannot support: which domains are present, which are missing, which are older than a quarter, and how many of the controls reachable from data your sources actually reach. The denominator is the controls data can evidence — never all 93, because the rest need a policy, a record or an interview, and no upload changes that. It also names the single source that would add the most, and says nothing when nothing would.

04

Deterministic scoring

A versioned rule engine turns facts into a number: vulnerability severity, known exploitation, exploitation probability, lifecycle status, how widely a product is installed, how critical you have marked the machines it sits on, and whether it was approved at all. Its lifecycle and exploitation facts come from self-mirrored catalogs — endoflife.date, Microsoft Product Lifecycle, CISA KEV and FIRST EPSS — never from a live call in the middle of a request. It is ordinary code, and it is the credibility spine of the product.

05

A 93-control ISO 27001 library

All 93 Annex A controls exist in the model, grouped by theme, each carrying its own status, owner, justification, linked evidence and a separate effectiveness record. Inventory-evidenced controls arrive as automated proposals you confirm or override; descriptions are original paraphrases authored in English, French and Arabic — never machine-translated.

06

Crosswalk to NIST CSF 2.0, CIS v8 and SOC 2

One assessment read through more than one lens. ISO 27001:2022 Annex A is the live library — the one a workspace actually answers. NIS2 Article 21(2), CIS v8 IG1, GDPR Article 32 and the Saudi NCA ECC each have a requirement board that reads those answers through their own requirements, with the requirements nothing reaches listed by identifier rather than averaged away. SOC 2 and NIST CSF 2.0 are reached through a crosswalk only, reported as mapping coverage. DORA is planned. No board is a conformity assessment, and none of them shows a single readiness percentage.

  • ISO 27001:2022
  • NIST CSF 2.0
  • CIS Controls v8
  • SOC 2 TSC
  • NIS2
  • DORA
07

Evidence library

Policies, procedures, network diagrams and screenshots stored against the controls they support, each with a sensitivity class, a malware scan, an upload date and a validity period. Expired evidence reappears as a gap — and an evidence request puts the ask on a named person with a due date instead of in an email thread.

08

Remediation artifacts

Every open finding gets a plan: the artifacts that close it, an owner role, and a target date taken from the severity SLA unless an owner commits to their own. Fourteen templates then draft the policy, procedure, standard, form or checklist an auditor will ask to see, with prose written into named slots and a document-control block on the front.

09

Live connectors

Scheduled pulls from ESET Connect, Microsoft Intune, SentinelOne, Lansweeper and Microsoft Entra ID, hourly through weekly. Each feeds the domain it actually knows about: ESET carries vulnerabilities as well as inventory, Intune carries device configuration compliance and encryption state, Entra carries directory accounts and their multi-factor state. A connector record holds the NAME of a secret and never its value — only the sync worker reads the credential — and every run leaves its status, device count and error behind in a sync history.

10

Drift detection and the overdue view

Between two snapshots the engine names what changed: new shadow IT, a newly known-exploited CVE, a support date crossed or approaching, evidence expired, a new critical finding, posture declined. Each change is either immediate or digest-worthy, and every open finding past its remediation target gets counted against the SLA that produced the target.

Every block above ships in the current build. What does not: DORA, which needs the vendor register first, and selectable data residency. Both are named inside the product as planned rather than implied, and the status on each surface says which is which.

The workspace

Everything an engagement needs between the upload and the report

Findings alone do not close an engagement. These are the surfaces the same model drives — each one a view over a single assessed state rather than a separate tool with its own copy of the truth.

  • 01

    Statement of Applicability

    All 93 controls with applicability and justification, exportable as a printable register. Exclusions with no stated reason are flagged.

  • 02

    Control assessment

    Automated proposals to confirm or override, progress per theme, and an owner and target date on every control.

  • 03

    Control effectiveness

    Recorded apart from implementation: a rating, a test method from inquiry to re-performance, a date and a tester. Controls whose findings keep returning are flagged.

  • 04

    Evidence library

    Sensitivity class, malware scan, validity period and supersession. Evidence that expires reappears as a gap.

  • 05

    Evidence requests

    One ask per control, addressed to a named person with a due date. A withdrawn request stays in the trail rather than vanishing.

  • 06

    Risk register

    Likelihood × impact on a matrix you can filter, treatment decisions, and residual risk after existing controls.

  • 07

    Policy register

    Owners, versions, approval dates and review cycles, with overdue reviews surfaced rather than buried.

  • 08

    Remediation center

    A plan per open finding: required artifacts, owner role, target date, and how far the artifacts have actually got.

  • 09

    Drift alerts and SLA

    Seven kinds of change between snapshots, split into immediate and daily digest, plus every open finding past its target.

  • 10

    Roles and invitations

    Owner, auditor and viewer; email invitations with their delivery status; ownership transfer that cannot leave a workspace ownerless.

  • 11

    Audit log

    Append-only and read-only: every change to controls, evidence, registers, memberships and connectors, machine-initiated ones included.

  • 12

    Portfolio and search

    Every workspace you belong to on one screen, and one keystroke to search findings, controls and products.

  • 13

    Plan and billing

    Plan limits on endpoints, workspaces, seats, assessments, reports and connectors, changed through Stripe — card details never reach AudiDesk.

  • 14

    Support requests

    Raised from the top bar with workspace, plan and role attached. The status shown is the support team's own, never one this app invents.

Data residency is the one surface here that is named without being selectable: this release stores every workspace in the region its settings page shows, and regional choice is reserved for engagements that require it contractually.

Who it serves

Three practices, one engine

01

IT service providers

A portfolio of isolated client workspaces with posture, open criticals and last snapshot at a glance — kept current by scheduled connector syncs and drift alerts instead of a quarterly upload.

02

Cybersecurity consultants

Point-in-time engagements end to end: the Statement of Applicability, evidence requests tracked against named people, effectiveness tests recorded per control, and DOCX deliverables you edit before delivery.

03

Internal IT teams

An executive dashboard of your own posture, a remediation center with owners and target dates, an overdue view against the severity SLA, and the policy and risk registers a compliance program needs between audits.

Trilingual by design

English. Français. العربية.

Every screen, report, and generated document ships in all three languages, including full right-to-left Arabic — with Latin digits and Gregorian dates for CVE IDs, versions, and scores, because auditors quote them verbatim.

This page is the demonstration. Switch it:

EN

Why the numbers hold up

Honest by construction

The same inventory always produces the same audit

Scores, findings, and lifecycle statuses come from a versioned, deterministic rule engine — never a language model. Every finding records the exact ruleset version that produced it, so last quarter's audit re-runs to the byte.

rulesetVersion · scoring/v1

Scope is stated, never inflated

A software inventory produces automatic proposals for seven of the 93 Annex A controls; every evidence source this platform reads, supplied together, reaches sixteen. The rest are yours to answer with evidence — they need a policy, a record or an interview, and no upload changes that. A proposal stays a proposal until someone confirms or overrides it, anything unanswered stays Not assessed, and each assessment states its own coverage before you export it. The ISO report is an assessment, not a certification.

AI drafts prose; it never computes

Language models are confined to narrative and to policy and procedure drafts — always labeled, always written into a fixed template, always gated on a named approver. No score, severity, control status or effectiveness rating is ever model-generated.

Evidence is scanned, classified, and kept out of AI context

Every upload is quarantined until a malware scan clears it, and a file the scanner rejects is never usable as evidence. Confidential items and anything unscanned are excluded from AI-assisted drafting, and the region a workspace's model calls run in is a setting that workspace owns.

Pricing

Pricing is quoted per engagement

Estate size, the number of client workspaces you run, and which tier you need all move the number, and a price list that ignored them would be wrong for almost everyone. Tell us what you are assessing and we will quote it.

Assessment

Quoted per engagement

Point-in-time. You supply an inventory, AudiDesk assesses it, and you deliver the result.

What it includes

  • Inventory upload — ESET PROTECT exports and generic CSV or Excel
  • Normalization, end-of-life and end-of-support matching, shadow IT detection, and snapshot comparison that closes remediated findings by itself
  • Deterministic versioned scoring, with the ruleset version stamped on every finding
  • Findings, the risk register, the policy register and the remediation center
  • All 93 Annex A controls, the Statement of Applicability, and the Not assessed register stated in full
  • Evidence library with malware scanning and expiry, plus evidence requests assigned to named client staff
  • Seven reports and fourteen document templates — printable HTML and editable DOCX, in English, French or Arabic
  • Isolated client workspaces, three roles, email invitations, and an append-only audit log
Request access

Continuous monitoring

Quoted per engagement

Everything in Assessment, plus live connectors. Snapshots arrive on their own and posture stays current between audits.

What it includes

  • Everything in the Assessment tier
  • Live connectors — ESET Connect, Microsoft Intune, SentinelOne, Lansweeper and Microsoft Entra ID
  • Scheduled synchronization from hourly to weekly, with automatic snapshots and automatic verification passes
  • Drift alerts: new shadow IT, a newly known-exploited vulnerability, an end-of-life date crossed, evidence expired
  • Live posture on the executive dashboard, and as-of-last-sync provenance on every report
  • Findings past their remediation target as their own overdue view, measured against the severity SLA
  • Per-tenant connector credentials held in a secret manager, never in the database
  • Sync history, and the full audit trail of machine-initiated changes alongside human ones
Request access

No figures are published on this page, deliberately. A number quoted here that did not survive contact with your estate would be worse than no number at all.

There is no free tier and no self-service sign-up: access is by invitation while early workspaces are onboarded. Once a workspace exists, its plan is changed in-app through Stripe, and card details never reach AudiDesk.

Access is by invitation while early workspaces are onboarded.

Tell us about your practice and the inventory you already export, and we will come back to you.

Request access

Contact

Request access, or ask a question

Onboarding is by invitation while early workspaces are being set up. Tell us about your practice and the inventory you already export, and we will come back to you.

What are you assessing, and what would you like to know?

Cookie preferences

Necessary cookies keep AudiDesk working. Everything else is off until you switch it on, and you can change your preferences at any time from the footer.

Necessary

audidesk_consent

Required for AudiDesk to function. The only one we set records this choice, so you are not asked again on every visit. It holds no identifier and cannot be switched off.

Analytics

Google Analytics 4

Aggregated measurement of how AudiDesk is used — which pages are read, and from which country. Nothing is loaded and no analytics cookie is set unless you enable this; switching it off again deletes the ones already there.

How we describe this in the privacy policy