Vendor risk management, access governance, hardware/software asset inventory, compliance framework testing, finding remediation, and incident response — aligned to ISO 27001, NIST CSF 2.0, and SOC 2.
A single platform that gives the CISO a unified view across third-party risk, access governance, asset management, control effectiveness, and incident response.
CISOs, security analysts, compliance officers, IT asset managers, access governance leads, and incident response teams.
Manage vendor risk assessments with SOC2/ISO27001 tracking, DPA addenda, access reviews and revocations, privileged access inventory, hardware/software asset lifecycle, framework control testing, finding remediation workflows, and NIST 800-61 incident response.
The CISO queries vendor risk posture, control effectiveness by domain, access review completion rates, incident severity trends, MTTR, and finding backlogs — all in plain English.
Purpose-built data models, workflows, and views — generated by the VeloIQ™ framework and refined for the vertical.
Vendor profiles, risk assessments, DPA addenda tracking. SOC2 expiry monitoring, ISO 27001 certification flags, data classification per vendor.
Access reviews (quarterly/annual/triggered), revocations (offboarding, role change, incident), privileged access inventory with expiry alerts.
Hardware and software assets with status lifecycle, criticality ratings, license expiry tracking, and decommissioning validation.
Frameworks mapped to ISO 27001 Annex A / NIST CSF / SOC 2 TSC. Control test scheduling, effectiveness scoring, and finding generation.
NIST SP 800-61r2 incident lifecycle — reported, investigating, contained, eradicated, recovering, closed. Severity, root cause tracking, and MTTR metrics.
VeloIQ™ Sovereign Guard ships as a complete, working application — not a template you still have to build.
Arrives with realistic sample data plus a clean production-ready schema. Explore the app instantly, then switch to the clean database when you go live.
5 pre-configured NL chats — vendor risk analytics, access governance, asset inventory, control effectiveness, and incident response. Query SOC2 expiry risk, review completion rates, finding trends, and MTTR in plain English.
One veloiq run and the full application is live: REST API, React frontend, admin back-office, and AI console — all on your own infrastructure.
Automated smoke and regression suites ship with the app, so every deployment can be validated before users touch it.
Measurable outcomes for every role in your organization — from daily operators to strategic decision-makers.
Controls are mapped to ISO 27001 Annex A, NIST CSF, and SOC 2 TSC. Every test result and finding is traceable to its framework requirement.
NIST 800-61r2-aligned incident lifecycle with automated escalation of critical incidents. Track MTTR, root cause patterns, and containment times.
Scheduled and triggered access reviews with completion tracking. Privileged access expiry alerts catch stale admin accounts before auditors do.
Single dashboard shows vendor risk ratings, SOC2 report expiries, DPA coverage gaps, and pending risk assessments — updated in real time.
Data models and metadata that speak your industry’s language — because compliance and interoperability start with the schema.
| Area | Standard | Models mapped |
|---|---|---|
| ISMS | ISO/IEC 27001:2022 | Annex A controls for vendor management (A.5.19–A.5.22), access control (A.5.15–A.5.18), asset management (A.5.9–A.5.14), and incident management (A.5.24–A.5.27) |
| Cybersecurity | NIST CSF 2.0 | Identify (ID.AM, ID.RA), Protect (PR.AA, PR.AT), Detect (DE.AE, DE.CM), Respond (RS.MA, RS.AN), Recover (RC.RP) — full mapping |
| Trust | SOC 2 (TSC 2017) | Security, Availability, Confidentiality — controls mapped to CC-series criteria |
| Incident | NIST SP 800-61r2 | Incident response lifecycle: preparation, detection & analysis, containment/eradication/recovery, post-incident activity |
Every VeloIQ™ vertical application is versioned source code — not a locked SaaS. Fork, extend, integrate, or white-label.
Each module is a self-contained VeloIQ™ unit with its own models.py, generated GUI views, and REST API. Add or remove modules as your needs evolve.
Bring in IQVigilant for NL analytics, exception alerts, and personalization — or install other VeloIQ™ extensions from the community. Configured declaratively in veloiq.toml.
Add custom business logic in custom_api.py, override page templates per model:action, or add SQLAdmin views for advanced administration.
Switch from the shipped SQLite to PostgreSQL, MySQL, or Snowflake with a single connection string change. Schema migrations are tracked via Alembic.
AI-ready with 1-User Natural Language · 10 Exception Alerts · 100 Personalization — learn about IQVigilant capabilities
Get in touch with the VeloIQ™ team to discuss deployment, customization, and licensing.