Our product

shachi

Governance you can prove.

One data foundation for compliance, risk management and internal audit, with the evidence already attached.

Demo environment · sample data · English localisation on request

Governance dashboard

Executives stop waiting for the report.

Eight headline tiles: users, active and critical risks, assets, overdue items, policies due for review, projects, projects at risk. Residual risk distribution with a trend series at three, six and twelve months.

  • Top risks ranked by residual score, each carrying its register ID
  • Twelve modules in one navigation

01

Five domains on one data foundation.

  1. Strategy & portfolio

    IT strategy, investment portfolio, project and programme management.

  2. Risk management

    Risk ledger, assessment, response plans, acceptance records, KRI monitoring.

  3. Compliance & audit

    Policy management, regulatory reports, inspection binder, audit trail.

  4. Infosec & assets

    Asset ledger, auto-discovery, SBOM/AIBOM, vulnerability blast radius, vendors.

  5. Organisation & access

    Departments, roles, users, per-department access control.

02

Running today.

shachi unifies strategy, risk, compliance and information security into one living system, delivering the organisation a real-time view of its own health.

Demo environment · sample data · English localisation on request

Regulatory reporting

The inspection binder is one click.

Requirements held per recipient, from company history and org charts through to individual filings, each with an owner, a deadline, its evidence and a last-confirmed date. Weeks of assembly becomes a download.

  • Five states counted live: not started, in progress, ready, submitted, out of scope
  • Overdue items surface rather than bury
  • The same ledger produces JSDA, JPX and FSA formats
Demo environment · sample data · English localisation on request

Audit trail

Who did what, when, for every action.

Time, user, action, target entity and IP address. The detail view shows what changed and to what; administrator actions are recorded on the same terms and remain verifiable. This is the answer to "Excel change history is untraceable", the objection internal audit raises first.

  • Filtered search by action, entity type, user and period
  • Tenant isolation: no other institution's evidence can appear in your log
Demo environment · sample data · English localisation on request

Asset register

Comprehensive means comprehensive.

findn Discovery (macOS, Windows, Linux) finds devices on the network, structurally preventing the manual-entry gaps that make a ledger untrustworthy. CycloneDX and SPDX bills of materials are imported, so affected assets resolve the moment a vulnerability is published. The asset and risk ledgers cross-reference in both directions; linkage is 100%.

  • End-of-service alerts at thirty, ninety and one hundred eighty day horizons, per asset
  • AIBOM has no settled international standard yet: implemented on CycloneDX's description model, and says so
Demo environment · sample data · English localisation on request

Risk ledger

The assessment itself becomes evidence.

Residual likelihood against impact, five by five. What remains is not only the conclusion but also when, by whom, how it was assessed, and who accepted the residual. Overdue assessments surface rather than bury, which removes the round of queries and reconciliation between internal audit and risk management before every inspection.

  • Assessor, date and accepting owner are recorded on every entry
  • An audit can start from the asset side or the risk side
Demo environment · sample data · English localisation on request

Projects & investment

Stalled projects stop hiding.

Overdue approval gates are detected and listed without anyone chasing them. Budget against committed and actual spend, investments ordered by NPV, three portfolios (core systems, growth, transformation). Projects attach to the risk ledger, so cyber-response work such as a passkey rollout is trackable from the risk side.

  • Stage-gate deadline detection, automatic
  • Investments ordered by NPV across three portfolios

03

One set of data.Separate views and privileges.

Compliance and Internal Audit stay separated as independent functions, with divided privileges, and still reference the same facts. Independence does not have to mean duplication.

What this removes

  • Reconciling two departments' spreadsheets before an inspection
  • Arguing about which copy of the risk register is current
  • Rebuilding the same submission for a second recipient

What this preserves

  • Independence of the third line, enforced in the access model
  • Each department's own terminology and column set
  • Tenant isolation: no other institution's evidence is ever adjacent

The ledger is the product. The formats are just views.

04

Why the linkage matters

A vulnerability is published. What happens next?

  1. Advisory lands

    A CVE is published against a component.

  2. SBOM is queried

    CycloneDX and SPDX bills of materials are already imported, so the component is searchable.

  3. Assets resolve

    Every asset containing it is listed, with owner, environment and criticality.

  4. Risks attach

    Because linkage is 100%, each asset already carries its risk entries.

  5. Evidence writes itself

    The query, the decision and the approver are logged, and appear in the next binder.

Without linkage

Someone emails the vendor list. Someone else greps a spreadsheet. Three days later a partial answer arrives, and none of it is evidence.

With linkage

The answer is a query, and the query is itself a record: timestamped, attributed and reusable at the next inspection.

See shachi in a demo

We'll walk you through the demo environment and how it fits your IT governance, FISC and audit work.

Reception hoursWeekdays 9:00-18:00 (JST)

Request a demo