Capability map

Every capability, grouped by the stage it serves.

Not an alphabetical feature list. Sentinel’s stages are a dependency chain — requirements, controls, evidence, gaps, actions, readiness, reporting — so each capability is filed under the stage it belongs to, with what that stage takes in and what it hands on. Where something belongs to a particular plan, the plan is named. Where something is not in the product, that is on this page too.

Self-service signup opens shortly — we will set you up in the meantime

ReadinessSentinel interface, reproduced
76/ 100
Expected
  • Policies18%87
  • Evidence Ready18%79
  • Risk Mgmt14%73

Readiness in the example workspace. Every panel on this page is rendered from the same fictional tenant, so no two sections can disagree about the same number.

What Sentinel does

Seven stages, plus the two things that are not stages.

AI assistance runs across every stage rather than sitting between two of them, and administration, access and residency sit underneath all of them. Filing them as steps would misdescribe the product, so they are filed as what they are.

01

Bringing requirements in

Where most programmes stall: somebody starts a spreadsheet from a PDF of the standard, and six weeks later that spreadsheet is the only copy and one person understands it.

Takes in
A framework, an insurer’s question set, a customer’s security review
Hands on
Requirement records in scope, with applicability decided

Framework-by-framework coverage

Framework library
ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), Cyber Insurance Readiness, NIST CSF 2.0, CIS Controls v8.1 arrive as requirement sets you put in scope. Nobody re-types a standard, and nobody maintains their own copy of it.
Frameworks in scopeOne on Essentials
One framework on Essentials; multiple on Full Platform. In the example workspace four frameworks contribute 224 requirement items.
Requirements as records
Each clause, criterion or safeguard is a record with a status, an owner, notes and links to the controls that satisfy it — so it can be assigned, discussed and reported on individually.
Cross-framework mapping
One control can satisfy requirements in more than one framework. Adding the second framework starts from what is already covered rather than from zero.
Scoping and applicability
Record why something is out of scope at the point you decide it. “Not applicable” becomes an answer with a reason attached rather than a blank you reconstruct a year later.
Questionnaires and security reviews
An insurer’s question set or a customer’s review is held in the same structure as a framework and draws on the same controls and evidence, so answering one moves the others forward.
The structure the reviewer will cite
Requirement sets keep the shape the framework publishes — functions, clauses, criteria, safeguard groups — so what you hand over lines up with what was asked for, not with your internal naming.
02

Managing controls

A control register is not hard to build. It is hard to keep true, and what keeps it true is that somebody specific is accountable for each line and can see their own subset without wading through everybody else’s.

Takes in
Requirements in scope
Hands on
A register where every line has an owner, a status and a last-tested date

How the register feeds everything else

One control register
Not one register per framework. A control exists once, with one owner and one status, and is referenced by every requirement it answers.
Named owners
A control is owned by a person, not a department or a shared inbox. A missing owner is treated as a reportable gap rather than a blank cell.
Five views of the register
Control Library, Framework Readiness, Test Schedule, Test History, Findings — the product’s own tabs. One register, read five ways, instead of five exports that drift apart.
Implementation status
A short, fixed vocabulary — Operating, Needs evidence, Not implemented — used everywhere. In the example workspace that is 18, 6 and 2.
How it works here
A plain-language description of the control as it actually operates in your organisation — the sentence an auditor or an underwriter reads. Not the standard’s wording pasted back at them.
Linked evidence, both directions
A control shows every item that evidences it and how fresh each one is. An item shows every control it supports. Attach once, and the link holds.
Control testing and test historyFull Platform
Record that a control was tested — who, when, and what came out of it — so an audit engagement reads a history instead of an assertion.
Ownership and coverage views
Filter by owner, framework, status, or by what has no evidence at all. The view a control owner opens is the subset they are accountable for.
Bulk work inside the register
Assign, re-scope and update in place. The moment the working copy leaves the tool for a spreadsheet, the register stops being the source of truth.
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace
The register in the example workspace: 26 controls, 2 of them unowned and reported as such.
03

Evidence

Most organisations do have the evidence. What they do not have is a way of knowing which piece went stale, which control it was supporting, and who is meant to replace it.

Takes in
Controls that claim to operate
Hands on
Dated proof attached to them, and a list of what has gone stale

More on the evidence library

One evidence library
Policies, tickets, configuration exports, training records, reports, screenshots — held with the controls they support, instead of a drive where the newest filename wins.
7 statuses, one vocabulary
Accepted · Approved · Under Review · Pending · Draft · Expired · Missing. The same words in the library, in the register and in the report, so two screens cannot describe one item differently.
Expiry on every item
Each item carries a date it stops being current. That is what turns “we have a penetration test” into “our penetration test expires in five weeks”.
Expiring soon
A view of what goes stale next, before somebody external finds it first. An expired item stops counting toward readiness on the day it expires, not at the next review meeting.
Reuse across frameworks and questionnaires
The same backup report can evidence an ISO control, a SOC 2 criterion and an underwriter’s question. Collect once, cite everywhere it applies.
Evidence packagesFull Platform
Assemble the set a broker, an underwriter or an auditor asked for, rather than forwarding twelve attachments.
What it does not do
Evidence gets into the library because a person puts it there. There is no live connection pulling it in from your other systems, and somebody still has to decide whether a given export demonstrates the control.
  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1
The status mix in the example workspace: 41 accepted, 1 expired and 1 missing out of 26. A fifth of it would fail an auditor today.
04

Gaps, assessments and risk

A gap is not a percentage. It is a control with no owner, no evidence, or evidence that has expired — and it is the same list the readiness report reads from, so there is no second version to reconcile.

Takes in
Controls without current evidence, and a question set worth repeating
Hands on
Findings and rated risks, each with an owner

Risk management in detail

Gaps, defined mechanically
No owner, no evidence, or expired evidence. Nothing is inferred from a neighbouring control, and blank is never treated as a passing state.
Structured assessmentsFull Platform
A defined set of questions with recorded answers and owners, so the next round is comparable with this one instead of being a fresh opinion.
Findings that become actions
A finding carries an owner and a date and lands in the shared backlog. An assessment that ends in a PDF has not changed anything.
Maturity trackingFull Platform
Where the programme sits over successive assessments, so “are we better than last year” is answered from records rather than from feeling.
Risk register
Descriptions, owners, ratings, treatment decisions and target dates that show as overdue once they pass — rather than a register opened once a year.
Rating and status
Inherent rating as likelihood × severity, shown on the row as L×S. Status is Open, Mitigated, Formally Accepted — accepting a risk is a recorded decision with a name against it.
Risks linked to controls
A risk points at the controls meant to reduce it. When one of those controls loses its evidence, the exposure becomes visible instead of theoretical.
Audit engagement workspaceFull Platform
Requests, control testing and the evidence somebody asked for, held in one place instead of an email thread and a naming convention.
05

Actions

Three sources of security work, one place to see whether any of it moved. A gap nobody owns and nothing is scheduled against is a note, not a finding.

Takes in
Gaps, assessment findings and risk treatments
Hands on
Owned, dated work in one backlog

See the pipeline end to end

One backlog, three sources
Actions raised from evidence gaps, from assessment findings and from risk treatments sit together with owners and dates. The register and the to-do list are the same list.
Horizon buckets
Critical Now, Next 30 Days, Next Quarter, Quick Wins, Strategic Projects — the product’s own horizons, because “what is critical now” and “what is a quick win” are different questions answered by different people.
Priority, owner, due date, status
On every row, with the module the action came from. Overdue work is visible on the dashboard rather than discovered at the next review.
Raised from a gap in one step
A missing or expired item becomes a tracked action without re-typing it somewhere else, which is the only version of this that survives a busy month.
06

Insurance readiness

Cyber-insurance questions are specific, evidence-backed and dated. Answering them well is mostly a matter of having done the organising in the weeks before, when there was still time to fix what was missing.

Takes in
The register, and a renewal date
Hands on
An answer per underwriter question, with the evidence behind it

The full insurance readiness workflow

Readiness workspace
A working area for the renewal itself: the questions that get asked, where you stand on each, and what evidence sits behind each answer.
The 9 controls underwriters ask about
Multi-factor authentication, EDR, immutable and restore-tested backups, email filtering, a patch cadence with a critical-vulnerability SLA, a tested incident response plan, awareness training and phishing simulation, critical vendor reviews, encryption in transit and at rest.
Three answers, not two
Yes, Partial or No. Partial is the answer that reprices a renewal, so it is a first-class state rather than something a spreadsheet rounds up.
Gap list before the submission
What is missing or expired ahead of the renewal date, with time to do something about it. The point of doing this early is that it is still changeable.
Broker and underwriter evidence packagesFull Platform
The evidence assembled as a package for the people who asked for it.
Answer consistency
Because the answers come from the register, what you tell an insurer, an auditor and a customer about the same control is the same thing. You remain responsible for what you submit.
Cyber Insurance Submission PackOne-time service
A reviewed, broker-ready evidence and questionnaire package assembled from your workspace. A one-time service at $499, arranged with us rather than bought from a checkout.
  • Yes
    Multi-factor authentication (email, remote/VPN, admin)
  • Yes
    EDR / next-gen AV deployed & monitored
  • Partial
    Backups immutable/offline AND restore-tested
    Backups are immutable and off-site. The Q3 restore test has not been run yet; the Q2 report is the last dated proof.
  • Yes
    Email filtering / advanced threat protection
The first four of the 9 questions, in the product’s own wording. Across all 9, the example position is 6 evidenced, 3 partial and 0 not in place — 96 days before a 15 December 2026 renewal.
07

Readiness and reporting

Nobody with a board seat wants a control export. They want to know where the organisation stands, what moved, what is late, and what needs them. That report should come off the register.

Takes in
Everything above
Hands on
A score, a position per framework, and a summary somebody outside the programme can read

Executive and board reporting

Sentinel Score
9 weighted categories, and the weights are published in the product. Every category scores from the records in your workspace — a category with nothing in it scores from a documented floor rather than being left blank — and the figure decomposes to the item that is missing.
Benchmark bands
5 bands, from Below Expected to Leading, so a number is read against a scale rather than treated as a grade. The example workspace scores 76.
Readiness by framework
Where you stand against each framework in scope and which requirements are still unanswered — useful for deciding what to do next, not only for reporting what happened.
Executive summary
The short version for somebody with ten minutes: position, movement, overdue work, and what needs a decision from them specifically.
Board reportingFull Platform
Shaped for a board pack rather than an operational review, and reproducible next quarter.
What changed
Movement since the last period, so a quarter is reported as a delta instead of restated as a position.
Figures that come from the register
Every number is generated from the workspace, so the summary and the detail underneath it cannot drift apart.
Board summarySentinel interface, reproduced
Northstar Manufacturing Ltd. · September 2026

Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.

Needs a decision

  • Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
  • Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
  • Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
The board summary: position, what changed, and what needs a decision — generated from the register, then edited.
Across

AI assistance

The useful application of AI here is narrow and unglamorous: read what is already in the register, draft the thing somebody has to write, and point out what does not hold together. Not decide anything.

Takes in
Your own tenant’s records
Hands on
A draft, or a review comment, for a person to approve

How the AI features are scoped

Scoped to your own tenant
It works on your workspace’s data. It is not answering from another customer’s controls, and its chat answers start from your own records.
Drafting
First drafts of policy text, questionnaire answers and assessment write-ups, built from your company profile and what is already in your register.
Review
Reads a policy back and points at the sections and requirements that are thin or missing outright — before somebody external does the same thing less kindly.
You approve, always
Output arrives as something to review. It does not change a control status, approve evidence, produce the score, or submit anything on your behalf.
Where the calls go
AI requests are sent to Anthropic in the United States. What is sent, and what that means in practice, is set out in the AI Features Notice.
Optional
Every workflow on this page works if you never open the AI features. Nothing is scored or approved by them.
Underneath

Administration, access and residency

Who gets in, what they see, and where the data sits. Answered the same way here as it is answered in the security questionnaire we send back.

Takes in
The questions a procurement review asks in writing
Hands on
Answers that match the ones in our own questionnaire responses

How CyberWave protects your data

Included users, then packs
Essentials includes 2 users, Full Platform includes 5. Additional users are priced per seat or in packs. Control owners need their own login — a shared account destroys the ownership everything else depends on.
Separate tenants
Each customer workspace is isolated at the database level. Your controls, evidence and reporting are not co-mingled with another organisation’s.
Access scoped by role
What a person sees follows what they are responsible for: a control owner opens their controls, an executive opens the report.
Data residency
Workspace data is stored in Supabase in Canada, region ca-central-1. Application compute runs on Vercel in the United States. AI requests go to Anthropic in the United States.
Multiple entities
Group structures, several legal entities or an unusual framework go through the Custom route rather than bending a published plan into a shape it does not fit.
A real support address
support@cyberwave.ca, answered by the people who build it. There is no tier of support you have to buy to get a reply.

A capability list that never says no is not a capability list.

Everything on the previous list is something Sentinel does. This is the shorter list, and for a buyer comparing three tools it is the more useful one.

Straight answers

What is not in here.

These are deliberate. Some of them are the most commonly implied capabilities in this category, and finding out on the call — or after signing — is worse for both of us.

  • Certification, audit opinions, or any statement that you are compliant. Those come from bodies qualified to issue them.
  • Security monitoring, log collection or alerting. Sentinel does not watch your network, and CyberWave does not operate a security operations centre.
  • Managed detection and response, or any managed security service.
  • Vulnerability scanning and penetration testing. Sentinel records the results and their expiry; it does not produce them.
  • 24/7 operations, emergency incident response or digital forensics. Sentinel holds your incident response plan and the evidence that you exercise it.
  • Dark-web monitoring, as a standalone service or otherwise.
  • Insurance broking and coverage decisions. Sentinel prepares what a broker and an underwriter ask you for.
  • Legal advice. Sentinel organises what your counsel and your auditor request, in a form they can read.

Ask whether Sentinel is the wrong toolLegal centre

Which plan

Line by line, in dollars.

Stated in full so a comparison does not require a call. The advisory tiers are the same software with a named CyberWave advisor on top.

Full Platform
Price, per month
$249
Price, per year
$2,689.20
Included users
5
Frameworks in scope
Multiple
Control register, evidence library, risk register
Included
Cyber-insurance readiness workspace
Included
Sentinel Score and executive summary
Included
AI assistance for drafting and review
Included, larger allowance
Audit engagement workspace and control testing
Included
Executive and board reporting
Included
Broker and underwriter evidence packages
Included
Assessment programme and maturity tracking
Included
Named advisor and scheduled advisory sessions
Free trial
14 days, no card
Essentials
Price, per month
$99
Price, per year
$1,069.20
Included users
2
Frameworks in scope
One
Control register, evidence library, risk register
Included
Cyber-insurance readiness workspace
Included
Sentinel Score and executive summary
Included
AI assistance for drafting and review
Included, monthly allowance
Audit engagement workspace and control testing
Executive and board reporting
Broker and underwriter evidence packages
Assessment programme and maturity tracking
Named advisor and scheduled advisory sessions
Free trial
14 days, no card
Managed vCISO Lite
Price, per month
$999
Price, per year
$11,388.60
Included users
5 — the advisor does not consume a seat
Frameworks in scope
Multiple
Control register, evidence library, risk register
Included
Cyber-insurance readiness workspace
Included
Sentinel Score and executive summary
Included
AI assistance for drafting and review
Included, larger allowance
Audit engagement workspace and control testing
Included
Executive and board reporting
Included
Broker and underwriter evidence packages
Included
Assessment programme and maturity tracking
Included
Named advisor and scheduled advisory sessions
Included
Free trial
Not applicable

Managed vCISO from $2,499/month is scoped in a statement of work, and Custom covers group structures and requirements the published plans do not fit. Neither is a quote-on-request version of the plans above — the published prices are the prices. Managed vCISO is an advisory service. It does not include 24/7 security operations monitoring, emergency incident response, legal representation, insurance brokerage, or audit or certification services unless a signed statement of work expressly provides them. Your management retains decision authority.

Seats and services

What it costs to add a person, and the one service we sell.

Control owners need their own login, so seats are the number that moves as a programme spreads. They are priced per user and in packs.

$19/mo
Additional user

Per additional user beyond the plan's included seats. $205.20/year.

$79/mo
5-user pack

5 users together, or 10 users at $149/month.

$499
Cyber Insurance Submission Pack

A reviewed, broker-ready evidence and questionnaire package assembled from your workspace. Arranged with us, not bought from a checkout.

Questions

What a comparison usually leaves unanswered.

Six that decide whether this page is worth acting on, answered here rather than on a call.

Can we start with one framework and add another later?
Yes, and that is the usual path. Essentials covers one framework in scope; Full Platform covers multiple. Adding the second does not restart the work — the cross-framework mapping shows which of your existing controls and evidence already answer parts of it.
Does Sentinel collect evidence automatically from our systems?
No. Evidence gets into the library because a person puts it there — there is no live connection pulling it in from your other systems. Be sceptical of anything in this category that implies a connector removes the judgement step: somebody still has to decide whether a given export actually demonstrates the control.
How many users do we need to buy?
Essentials includes 2 users and Full Platform includes 5. After that an additional user is $19/month, with a 5 users pack at $79/month and a 10 users pack at $149/month. Count the people who will own a control, not everyone in the company.
What is the difference between the platform and the advisory plans?
Full Platform is the software. Managed vCISO Lite at $999/month is the same software with a named CyberWave advisor and a scheduled advisory cadence, for organisations with no internal security leadership. The advisor does not consume one of your included users.
Is the AI optional?
Yes. The AI features are assistance, not a dependency. Every stage on this page — requirements, controls, evidence, gaps, actions, readiness, reporting — works if you never open them, and nothing is scored or approved by AI.
What happens at the end of a trial?
When the trial ends, carrying on means choosing a paid subscription; nothing converts or is charged on its own. Your data is not deleted because a trial ended.

Something on this page that a procurement review needs in writing? support@cyberwave.ca. We answer procurement questionnaires with the same words that are on this page.

Find the capability you came for?

If the thing you need is not on this page, it is worth twenty minutes to hear whether Sentinel is the wrong tool for it. We would rather tell you that early than sell you a workspace you resent.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required