Our whole pitch is that we assess honestly. This page states exactly how — how evidence is graded, what “manual assessment required” means, how coverage is measured, and why every report can be verified independently. If you only read one page before a demo, read this one.
Watch it run on sample docs →Every control is assessed against the artefacts you actually provide — uploaded documents and connector-collected evidence — not against a self-attestation.
A control with insufficient evidence is never passed. It is marked manual assessment required and surfaced — the honest state, never a fabricated green.
Verdicts are measured against the whole control catalogue, so “80% compliant” means 80% of the real catalogue — not 80% of a convenient subset.
The same evidence yields the same verdict. Reasoning is grounded in the evidence and the control text — not a probabilistic guess dressed up as a result.
Every report carries a validation run id and a SHA-256 integrity anchor chained into a ledger, so an auditor, a regulator or your client can verify a CyberSentien report is genuine and unmodified.
For ISO/IEC 27001, SOC 2 and ISO 42001 we map your evidence to a readiness / crosswalk view. We get you audit-ready; an accredited certifier issues the certificate. We don't claim to certify.
CyberSentien produces evidence-grounded verdicts and reports. Accountability for a control — and for the decision to accept a risk — stays with your organisation.
We go consultant-grade where we go deepest (ISM/IRAP, Essential Eight) and badge Tier-A breadth honestly elsewhere. We never overstate depth to win a logo on a slide.
For IRAP, an ASD-endorsed assessor does the endorsement. CyberSentien gets your evidence and rationale to the depth and structure an assessor expects — it doesn't replace them.
Run the engine on a synthetic sample library spanning strong evidence to poor, and watch it stay honest no matter what it's fed.