Our product
Governance you can prove.
One data foundation for compliance, risk management and internal audit, with the evidence already attached.
Governance dashboard
Executives stop waiting for the report.
Eight headline tiles: users, active and critical risks, assets, overdue items, policies due for review, projects, projects at risk. Residual risk distribution with a trend series at three, six and twelve months.
- Top risks ranked by residual score, each carrying its register ID
- Twelve modules in one navigation
01
Five domains on one data foundation.
Strategy & portfolio
IT strategy, investment portfolio, project and programme management.
Risk management
Risk ledger, assessment, response plans, acceptance records, KRI monitoring.
Compliance & audit
Policy management, regulatory reports, inspection binder, audit trail.
Infosec & assets
Asset ledger, auto-discovery, SBOM/AIBOM, vulnerability blast radius, vendors.
Organisation & access
Departments, roles, users, per-department access control.
02
Running today.
shachi unifies strategy, risk, compliance and information security into one living system, delivering the organisation a real-time view of its own health.
Regulatory reporting
The inspection binder is one click.
Requirements held per recipient, from company history and org charts through to individual filings, each with an owner, a deadline, its evidence and a last-confirmed date. Weeks of assembly becomes a download.
- Five states counted live: not started, in progress, ready, submitted, out of scope
- Overdue items surface rather than bury
- The same ledger produces JSDA, JPX and FSA formats
Audit trail
Who did what, when, for every action.
Time, user, action, target entity and IP address. The detail view shows what changed and to what; administrator actions are recorded on the same terms and remain verifiable. This is the answer to "Excel change history is untraceable", the objection internal audit raises first.
- Filtered search by action, entity type, user and period
- Tenant isolation: no other institution's evidence can appear in your log
Asset register
Comprehensive means comprehensive.
findn Discovery (macOS, Windows, Linux) finds devices on the network, structurally preventing the manual-entry gaps that make a ledger untrustworthy. CycloneDX and SPDX bills of materials are imported, so affected assets resolve the moment a vulnerability is published. The asset and risk ledgers cross-reference in both directions; linkage is 100%.
- End-of-service alerts at thirty, ninety and one hundred eighty day horizons, per asset
- AIBOM has no settled international standard yet: implemented on CycloneDX's description model, and says so
Risk ledger
The assessment itself becomes evidence.
Residual likelihood against impact, five by five. What remains is not only the conclusion but also when, by whom, how it was assessed, and who accepted the residual. Overdue assessments surface rather than bury, which removes the round of queries and reconciliation between internal audit and risk management before every inspection.
- Assessor, date and accepting owner are recorded on every entry
- An audit can start from the asset side or the risk side
Projects & investment
Stalled projects stop hiding.
Overdue approval gates are detected and listed without anyone chasing them. Budget against committed and actual spend, investments ordered by NPV, three portfolios (core systems, growth, transformation). Projects attach to the risk ledger, so cyber-response work such as a passkey rollout is trackable from the risk side.
- Stage-gate deadline detection, automatic
- Investments ordered by NPV across three portfolios
03
One set of data.Separate views and privileges.
Compliance and Internal Audit stay separated as independent functions, with divided privileges, and still reference the same facts. Independence does not have to mean duplication.
What this removes
- Reconciling two departments' spreadsheets before an inspection
- Arguing about which copy of the risk register is current
- Rebuilding the same submission for a second recipient
What this preserves
- Independence of the third line, enforced in the access model
- Each department's own terminology and column set
- Tenant isolation: no other institution's evidence is ever adjacent
The ledger is the product. The formats are just views.
04
Why the linkage matters
A vulnerability is published. What happens next?
Advisory lands
A CVE is published against a component.
SBOM is queried
CycloneDX and SPDX bills of materials are already imported, so the component is searchable.
Assets resolve
Every asset containing it is listed, with owner, environment and criticality.
Risks attach
Because linkage is 100%, each asset already carries its risk entries.
Evidence writes itself
The query, the decision and the approver are logged, and appear in the next binder.
Without linkage
Someone emails the vendor list. Someone else greps a spreadsheet. Three days later a partial answer arrives, and none of it is evidence.
With linkage
The answer is a query, and the query is itself a record: timestamped, attributed and reusable at the next inspection.
