Capability map
Every capability, grouped by the stage it serves.
Not an alphabetical feature list. Sentinel’s stages are a dependency chain — requirements, controls, evidence, gaps, actions, readiness, reporting — so each capability is filed under the stage it belongs to, with what that stage takes in and what it hands on. Where something belongs to a particular plan, the plan is named. Where something is not in the product, that is on this page too.
Self-service signup opens shortly — we will set you up in the meantime
- Policies18%87
- Evidence Ready18%79
- Risk Mgmt14%73
Readiness in the example workspace. Every panel on this page is rendered from the same fictional tenant, so no two sections can disagree about the same number.
What Sentinel does
Seven stages, plus the two things that are not stages.
AI assistance runs across every stage rather than sitting between two of them, and administration, access and residency sit underneath all of them. Filing them as steps would misdescribe the product, so they are filed as what they are.
Bringing requirements in
Where most programmes stall: somebody starts a spreadsheet from a PDF of the standard, and six weeks later that spreadsheet is the only copy and one person understands it.
- Takes in
- A framework, an insurer’s question set, a customer’s security review
- Hands on
- Requirement records in scope, with applicability decided
- Framework library
- ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), Cyber Insurance Readiness, NIST CSF 2.0, CIS Controls v8.1 arrive as requirement sets you put in scope. Nobody re-types a standard, and nobody maintains their own copy of it.
- Frameworks in scopeOne on Essentials
- One framework on Essentials; multiple on Full Platform. In the example workspace four frameworks contribute 224 requirement items.
- Requirements as records
- Each clause, criterion or safeguard is a record with a status, an owner, notes and links to the controls that satisfy it — so it can be assigned, discussed and reported on individually.
- Cross-framework mapping
- One control can satisfy requirements in more than one framework. Adding the second framework starts from what is already covered rather than from zero.
- Scoping and applicability
- Record why something is out of scope at the point you decide it. “Not applicable” becomes an answer with a reason attached rather than a blank you reconstruct a year later.
- Questionnaires and security reviews
- An insurer’s question set or a customer’s review is held in the same structure as a framework and draws on the same controls and evidence, so answering one moves the others forward.
- The structure the reviewer will cite
- Requirement sets keep the shape the framework publishes — functions, clauses, criteria, safeguard groups — so what you hand over lines up with what was asked for, not with your internal naming.
Managing controls
A control register is not hard to build. It is hard to keep true, and what keeps it true is that somebody specific is accountable for each line and can see their own subset without wading through everybody else’s.
- Takes in
- Requirements in scope
- Hands on
- A register where every line has an owner, a status and a last-tested date
- One control register
- Not one register per framework. A control exists once, with one owner and one status, and is referenced by every requirement it answers.
- Named owners
- A control is owned by a person, not a department or a shared inbox. A missing owner is treated as a reportable gap rather than a blank cell.
- Five views of the register
- Control Library, Framework Readiness, Test Schedule, Test History, Findings — the product’s own tabs. One register, read five ways, instead of five exports that drift apart.
- Implementation status
- A short, fixed vocabulary — Operating, Needs evidence, Not implemented — used everywhere. In the example workspace that is 18, 6 and 2.
- How it works here
- A plain-language description of the control as it actually operates in your organisation — the sentence an auditor or an underwriter reads. Not the standard’s wording pasted back at them.
- Linked evidence, both directions
- A control shows every item that evidences it and how fresh each one is. An item shows every control it supports. Attach once, and the link holds.
- Control testing and test historyFull Platform
- Record that a control was tested — who, when, and what came out of it — so an audit engagement reads a history instead of an assertion.
- Ownership and coverage views
- Filter by owner, framework, status, or by what has no evidence at all. The view a control owner opens is the subset they are accountable for.
- Bulk work inside the register
- Assign, re-scope and update in place. The moment the working copy leaves the tool for a spreadsheet, the register stops being the source of truth.
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
Evidence
Most organisations do have the evidence. What they do not have is a way of knowing which piece went stale, which control it was supporting, and who is meant to replace it.
- Takes in
- Controls that claim to operate
- Hands on
- Dated proof attached to them, and a list of what has gone stale
- One evidence library
- Policies, tickets, configuration exports, training records, reports, screenshots — held with the controls they support, instead of a drive where the newest filename wins.
- 7 statuses, one vocabulary
- Accepted · Approved · Under Review · Pending · Draft · Expired · Missing. The same words in the library, in the register and in the report, so two screens cannot describe one item differently.
- Expiry on every item
- Each item carries a date it stops being current. That is what turns “we have a penetration test” into “our penetration test expires in five weeks”.
- Expiring soon
- A view of what goes stale next, before somebody external finds it first. An expired item stops counting toward readiness on the day it expires, not at the next review meeting.
- Reuse across frameworks and questionnaires
- The same backup report can evidence an ISO control, a SOC 2 criterion and an underwriter’s question. Collect once, cite everywhere it applies.
- Evidence packagesFull Platform
- Assemble the set a broker, an underwriter or an auditor asked for, rather than forwarding twelve attachments.
- What it does not do
- Evidence gets into the library because a person puts it there. There is no live connection pulling it in from your other systems, and somebody still has to decide whether a given export demonstrates the control.
- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
Gaps, assessments and risk
A gap is not a percentage. It is a control with no owner, no evidence, or evidence that has expired — and it is the same list the readiness report reads from, so there is no second version to reconcile.
- Takes in
- Controls without current evidence, and a question set worth repeating
- Hands on
- Findings and rated risks, each with an owner
- Gaps, defined mechanically
- No owner, no evidence, or expired evidence. Nothing is inferred from a neighbouring control, and blank is never treated as a passing state.
- Structured assessmentsFull Platform
- A defined set of questions with recorded answers and owners, so the next round is comparable with this one instead of being a fresh opinion.
- Findings that become actions
- A finding carries an owner and a date and lands in the shared backlog. An assessment that ends in a PDF has not changed anything.
- Maturity trackingFull Platform
- Where the programme sits over successive assessments, so “are we better than last year” is answered from records rather than from feeling.
- Risk register
- Descriptions, owners, ratings, treatment decisions and target dates that show as overdue once they pass — rather than a register opened once a year.
- Rating and status
- Inherent rating as likelihood × severity, shown on the row as L×S. Status is Open, Mitigated, Formally Accepted — accepting a risk is a recorded decision with a name against it.
- Risks linked to controls
- A risk points at the controls meant to reduce it. When one of those controls loses its evidence, the exposure becomes visible instead of theoretical.
- Audit engagement workspaceFull Platform
- Requests, control testing and the evidence somebody asked for, held in one place instead of an email thread and a naming convention.
Actions
Three sources of security work, one place to see whether any of it moved. A gap nobody owns and nothing is scheduled against is a note, not a finding.
- Takes in
- Gaps, assessment findings and risk treatments
- Hands on
- Owned, dated work in one backlog
- One backlog, three sources
- Actions raised from evidence gaps, from assessment findings and from risk treatments sit together with owners and dates. The register and the to-do list are the same list.
- Horizon buckets
- Critical Now, Next 30 Days, Next Quarter, Quick Wins, Strategic Projects — the product’s own horizons, because “what is critical now” and “what is a quick win” are different questions answered by different people.
- Priority, owner, due date, status
- On every row, with the module the action came from. Overdue work is visible on the dashboard rather than discovered at the next review.
- Raised from a gap in one step
- A missing or expired item becomes a tracked action without re-typing it somewhere else, which is the only version of this that survives a busy month.
Insurance readiness
Cyber-insurance questions are specific, evidence-backed and dated. Answering them well is mostly a matter of having done the organising in the weeks before, when there was still time to fix what was missing.
- Takes in
- The register, and a renewal date
- Hands on
- An answer per underwriter question, with the evidence behind it
- Readiness workspace
- A working area for the renewal itself: the questions that get asked, where you stand on each, and what evidence sits behind each answer.
- The 9 controls underwriters ask about
- Multi-factor authentication, EDR, immutable and restore-tested backups, email filtering, a patch cadence with a critical-vulnerability SLA, a tested incident response plan, awareness training and phishing simulation, critical vendor reviews, encryption in transit and at rest.
- Three answers, not two
- Yes, Partial or No. Partial is the answer that reprices a renewal, so it is a first-class state rather than something a spreadsheet rounds up.
- Gap list before the submission
- What is missing or expired ahead of the renewal date, with time to do something about it. The point of doing this early is that it is still changeable.
- Broker and underwriter evidence packagesFull Platform
- The evidence assembled as a package for the people who asked for it.
- Answer consistency
- Because the answers come from the register, what you tell an insurer, an auditor and a customer about the same control is the same thing. You remain responsible for what you submit.
- Cyber Insurance Submission PackOne-time service
- A reviewed, broker-ready evidence and questionnaire package assembled from your workspace. A one-time service at $499, arranged with us rather than bought from a checkout.
- YesMulti-factor authentication (email, remote/VPN, admin)
- YesEDR / next-gen AV deployed & monitored
- PartialBackups immutable/offline AND restore-testedBackups are immutable and off-site. The Q3 restore test has not been run yet; the Q2 report is the last dated proof.
- YesEmail filtering / advanced threat protection
Readiness and reporting
Nobody with a board seat wants a control export. They want to know where the organisation stands, what moved, what is late, and what needs them. That report should come off the register.
- Takes in
- Everything above
- Hands on
- A score, a position per framework, and a summary somebody outside the programme can read
- Sentinel Score
- 9 weighted categories, and the weights are published in the product. Every category scores from the records in your workspace — a category with nothing in it scores from a documented floor rather than being left blank — and the figure decomposes to the item that is missing.
- Benchmark bands
- 5 bands, from Below Expected to Leading, so a number is read against a scale rather than treated as a grade. The example workspace scores 76.
- Readiness by framework
- Where you stand against each framework in scope and which requirements are still unanswered — useful for deciding what to do next, not only for reporting what happened.
- Executive summary
- The short version for somebody with ten minutes: position, movement, overdue work, and what needs a decision from them specifically.
- Board reportingFull Platform
- Shaped for a board pack rather than an operational review, and reproducible next quarter.
- What changed
- Movement since the last period, so a quarter is reported as a delta instead of restated as a position.
- Figures that come from the register
- Every number is generated from the workspace, so the summary and the detail underneath it cannot drift apart.
Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.
Needs a decision
- Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
- Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
- Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
AI assistance
The useful application of AI here is narrow and unglamorous: read what is already in the register, draft the thing somebody has to write, and point out what does not hold together. Not decide anything.
- Takes in
- Your own tenant’s records
- Hands on
- A draft, or a review comment, for a person to approve
- Scoped to your own tenant
- It works on your workspace’s data. It is not answering from another customer’s controls, and its chat answers start from your own records.
- Drafting
- First drafts of policy text, questionnaire answers and assessment write-ups, built from your company profile and what is already in your register.
- Review
- Reads a policy back and points at the sections and requirements that are thin or missing outright — before somebody external does the same thing less kindly.
- You approve, always
- Output arrives as something to review. It does not change a control status, approve evidence, produce the score, or submit anything on your behalf.
- Where the calls go
- AI requests are sent to Anthropic in the United States. What is sent, and what that means in practice, is set out in the AI Features Notice.
- Optional
- Every workflow on this page works if you never open the AI features. Nothing is scored or approved by them.
Administration, access and residency
Who gets in, what they see, and where the data sits. Answered the same way here as it is answered in the security questionnaire we send back.
- Takes in
- The questions a procurement review asks in writing
- Hands on
- Answers that match the ones in our own questionnaire responses
- Included users, then packs
- Essentials includes 2 users, Full Platform includes 5. Additional users are priced per seat or in packs. Control owners need their own login — a shared account destroys the ownership everything else depends on.
- Separate tenants
- Each customer workspace is isolated at the database level. Your controls, evidence and reporting are not co-mingled with another organisation’s.
- Access scoped by role
- What a person sees follows what they are responsible for: a control owner opens their controls, an executive opens the report.
- Data residency
- Workspace data is stored in Supabase in Canada, region ca-central-1. Application compute runs on Vercel in the United States. AI requests go to Anthropic in the United States.
- Multiple entities
- Group structures, several legal entities or an unusual framework go through the Custom route rather than bending a published plan into a shape it does not fit.
- A real support address
- support@cyberwave.ca, answered by the people who build it. There is no tier of support you have to buy to get a reply.
A capability list that never says no is not a capability list.
Everything on the previous list is something Sentinel does. This is the shorter list, and for a buyer comparing three tools it is the more useful one.
Straight answers
What is not in here.
These are deliberate. Some of them are the most commonly implied capabilities in this category, and finding out on the call — or after signing — is worse for both of us.
- Certification, audit opinions, or any statement that you are compliant. Those come from bodies qualified to issue them.
- Security monitoring, log collection or alerting. Sentinel does not watch your network, and CyberWave does not operate a security operations centre.
- Managed detection and response, or any managed security service.
- Vulnerability scanning and penetration testing. Sentinel records the results and their expiry; it does not produce them.
- 24/7 operations, emergency incident response or digital forensics. Sentinel holds your incident response plan and the evidence that you exercise it.
- Dark-web monitoring, as a standalone service or otherwise.
- Insurance broking and coverage decisions. Sentinel prepares what a broker and an underwriter ask you for.
- Legal advice. Sentinel organises what your counsel and your auditor request, in a form they can read.
Which plan
Line by line, in dollars.
Stated in full so a comparison does not require a call. The advisory tiers are the same software with a named CyberWave advisor on top.
| Essentials | Full Platform | Managed vCISO Lite | |
|---|---|---|---|
| Price, per month | $99 | $249 | $999 |
| Price, per year | $1,069.20 | $2,689.20 | $11,388.60 |
| Included users | 2 | 5 | 5 — the advisor does not consume a seat |
| Frameworks in scope | One | Multiple | Multiple |
| Control register, evidence library, risk register | Included | Included | Included |
| Cyber-insurance readiness workspace | Included | Included | Included |
| Sentinel Score and executive summary | Included | Included | Included |
| AI assistance for drafting and review | Included, monthly allowance | Included, larger allowance | Included, larger allowance |
| Audit engagement workspace and control testing | — | Included | Included |
| Executive and board reporting | — | Included | Included |
| Broker and underwriter evidence packages | — | Included | Included |
| Assessment programme and maturity tracking | — | Included | Included |
| Named advisor and scheduled advisory sessions | — | — | Included |
| Free trial | 14 days, no card | 14 days, no card | Not applicable |
- Price, per month
- $249
- Price, per year
- $2,689.20
- Included users
- 5
- Frameworks in scope
- Multiple
- Control register, evidence library, risk register
- Included
- Cyber-insurance readiness workspace
- Included
- Sentinel Score and executive summary
- Included
- AI assistance for drafting and review
- Included, larger allowance
- Audit engagement workspace and control testing
- Included
- Executive and board reporting
- Included
- Broker and underwriter evidence packages
- Included
- Assessment programme and maturity tracking
- Included
- Named advisor and scheduled advisory sessions
- —
- Free trial
- 14 days, no card
- Price, per month
- $99
- Price, per year
- $1,069.20
- Included users
- 2
- Frameworks in scope
- One
- Control register, evidence library, risk register
- Included
- Cyber-insurance readiness workspace
- Included
- Sentinel Score and executive summary
- Included
- AI assistance for drafting and review
- Included, monthly allowance
- Audit engagement workspace and control testing
- —
- Executive and board reporting
- —
- Broker and underwriter evidence packages
- —
- Assessment programme and maturity tracking
- —
- Named advisor and scheduled advisory sessions
- —
- Free trial
- 14 days, no card
- Price, per month
- $999
- Price, per year
- $11,388.60
- Included users
- 5 — the advisor does not consume a seat
- Frameworks in scope
- Multiple
- Control register, evidence library, risk register
- Included
- Cyber-insurance readiness workspace
- Included
- Sentinel Score and executive summary
- Included
- AI assistance for drafting and review
- Included, larger allowance
- Audit engagement workspace and control testing
- Included
- Executive and board reporting
- Included
- Broker and underwriter evidence packages
- Included
- Assessment programme and maturity tracking
- Included
- Named advisor and scheduled advisory sessions
- Included
- Free trial
- Not applicable
Managed vCISO from $2,499/month is scoped in a statement of work, and Custom covers group structures and requirements the published plans do not fit. Neither is a quote-on-request version of the plans above — the published prices are the prices. Managed vCISO is an advisory service. It does not include 24/7 security operations monitoring, emergency incident response, legal representation, insurance brokerage, or audit or certification services unless a signed statement of work expressly provides them. Your management retains decision authority.
Seats and services
What it costs to add a person, and the one service we sell.
Control owners need their own login, so seats are the number that moves as a programme spreads. They are priced per user and in packs.
Per additional user beyond the plan's included seats. $205.20/year.
5 users together, or 10 users at $149/month.
A reviewed, broker-ready evidence and questionnaire package assembled from your workspace. Arranged with us, not bought from a checkout.
Questions
What a comparison usually leaves unanswered.
Six that decide whether this page is worth acting on, answered here rather than on a call.
Can we start with one framework and add another later?
Does Sentinel collect evidence automatically from our systems?
How many users do we need to buy?
What is the difference between the platform and the advisory plans?
Is the AI optional?
What happens at the end of a trial?
Something on this page that a procurement review needs in writing? support@cyberwave.ca. We answer procurement questionnaires with the same words that are on this page.
Find the capability you came for?
If the thing you need is not on this page, it is worth twenty minutes to hear whether Sentinel is the wrong tool for it. We would rather tell you that early than sell you a workspace you resent.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required