A risk register your auditor can follow
Start from a risk library instead of a blank page, score each risk on a 5x5 scale with labels you define, and treat it through one of four approval-gated paths.
Inherent and residual, side by side
Each risk carries a 5x5 score before treatment and after, so the effect of your controls is visible, not assumed.
- A risk library to start from
- 5x5 scoring with customizable labels
- Inherent and residual scores per risk
- Risks linked to the controls that treat them
- Exportable reports
Four paths, each with an approval
Every treatment decision goes through an approval step, so the register reflects decisions someone actually made.
Mitigate
Reduce the risk with controls, and link the risk to the controls that treat it.
Transfer
Move the risk to another party, with the decision recorded and approved.
Accept
Take the risk knowingly, with an approval step so acceptance is a decision, not a default.
Avoid
Stop doing the risky thing, documented like every other treatment.
Vendor risk
A vendor registry with lifecycle tracking, configurable scoring, assessment cycles with approvals, and a portal vendors can answer without an account.
Vulnerability management
Findings from AWS Inspector, Snyk, and Tenable in one inventory, prioritized transparently, with SLA deadlines from your own policy.
Audit management
Run your audits where the evidence lives, from SOC 2 and ISO 27001 to the rest of your frameworks, with structured requests and exportable workpapers.
See Viglyn on your stack
A 30-minute walkthrough on your stack. Walk away knowing exactly how fast you could be audit-ready. No commitment.