Live buyer readout
Select an organization and engagement to build the live meeting brief.
This turns evaluation, trust-chain artifacts, and deployment profile into an executive summary.
Talk Track
Trust Signals
Meeting Notes
Quick Start
New environment? Use this to get to a first evaluation and an auditor-shareable snapshot fast.
Operations & Onboarding
This is the operator view for launch readiness: onboarding progress, connector health, workflow pressure, and pilot-proof artifacts.
Onboarding Checklist
Operational Alerts
Pilot Outcome Readout
Workspace access required
Engagement details appear after an authorized workspace credential is accepted.
Included handoff
Next step
Organization
Engagement
Engagement Setup
One-click setup for demos: seed control libraries and PBC requests (idempotent).
Imports (Connector-lite)
Upload a CSV/JSON export to create Evidence + Evidence Signals mapped to existing controls (by framework + control_code).
Source App Evidence
Import sanitized Kairnex evidence packages from KeyControl, AgentBoundary, ExposureOps, ShieldDesk, TechStack, or custom systems. Raw secrets, credential values, session material, and sensitive prompts are rejected.
Connectors (Evidence Sources)
Pull auditor-friendly evidence directly from common systems. Most connector pulls attach to the currently selected control and automatically record provenance + replay instructions. (Baseline pack imports attach to multiple controls.)
Managed connectors
Save recurring connector definitions with encrypted secrets, run them on a schedule, and monitor whether automation is healthy enough for customer-facing use.
Inventory
Selected connector
{} to clear.
GitHub — Audit log
Google Workspace — Admin audit log
Jira — Audit log
Microsoft Entra — Security posture (Graph)
AWS — IAM credential report (import)
Upload a credential report CSV and Kairnex Evidence will attach it to the selected control, compute a posture summary (MFA, active keys), and store replay instructions for auditors.
HTTP JSON — Fetch (bridge connector)
Cloud export — Ingest JSON (AWS/GCP/etc.)
For providers that require external tooling (AWS CLI / gcloud), export JSON locally and ingest it here. This attaches evidence to the selected control while recording provenance + optional replay instructions.
Baseline packs — Import ZIP (AWS / Entra / GCP)
Upload a ZIP created from a baseline export pack folder (must include manifest.json). The pack attaches evidence to
multiple controls based on the manifest targets.
Controls
Import controls catalog (CSV/JSON)
List
Selected
Raw control JSON
(none)
ISO 27001 ISMS (Clauses 4–10)
These artifacts drive the computed ISO clause controls in /evaluate. Use “Approve + Save” to attach an approval decision id (auditor-friendly).
Clause 4 — Scope
Clause 5 — Policy
Clause 6 — Risk Method + Risk Treatment Plan
Clause 7/8 — Competence + Operations
Clause 9 — Internal Audits + Management Reviews
Internal audits (9.2)
(none)
Management reviews (9.3)
(none)
Clause 10 — Corrective Actions
List
Selected
(none)
Evidence Library
Select evidence to attach to exceptions and control tests.
List
Selected
Raw evidence / provenance JSON
(none)
Evidence Signals (integrity / relevance)
These scores are used by /evaluate (objective requirements gating and evidence confidence). Create multiple signals; the latest extracted_at wins.
List
Selected
(none)
Evidence + Attestation
Attach evidence to a control, then create an engagement attestation (drives /evaluate).
Evidence Requests (PBC)
Track PBC items, statuses, and attach evidence (auditor workflow).
List
Selected
(none)
Exceptions (Findings)
Create findings/exceptions and attach evidence (SOC 2 Type II realism).
List
Selected
(none)
Control Tests (Workpapers)
Create test results with Type II metadata (period, population, sampling) and evidence links.
List
Selected
(none)
SoA (Statement of Applicability)
Risk
Objective Requirements
Define objective-level evidence quality gates. When a requirement is present and not satisfied, an objective that would otherwise be PASS becomes INCONCLUSIVE.
List
Selected
(none)
Objective Graph (Prerequisites)
Define objective prerequisites (A → B). Evaluation gates objective PASS to INCONCLUSIVE when prerequisites aren’t satisfied.
List
Selected
(none)
Evaluation
Suggested workflow
Objective blockers
Objectives
Controls
Auditor Visuals (Graphs)
Visualize objective prerequisites and the merged engagement explanation graph. Click nodes to inspect details and “why” chains.
Crosswalk (SOC 2 + ISO → Canonical 10 frameworks)
This is a derived view computed from objective results (by default sources SOC2,ISO27001). It helps you reuse evidence across frameworks.
Summary
Selected
(none)
Objective prerequisite graph (DAG)
Selected node
(none)
Engagement explanation graph (merged)
Matches
Neighborhood
Selected node
(none)
Audit Pack Snapshots
Create immutable audit pack snapshots, verify hash integrity, and diff changes over time.
List
Output
Jobs (Background work)
Queue long-running exports and track status (useful for enterprise-scale audits).
List
Selected
(none)
Deployment (Scaling)
Scaling is controlled by your orchestrator (Docker Compose, Kubernetes, etc). These buttons copy reference Docker Compose commands for local scale testing.
Runtime readiness
Hardening checks
Enterprise posture
Key Vault, sealed export storage, SIEM export, request limits, security events, and sealed export verification.
Security events
Sealed exports
Verification
(none)
KAIRNEX_ADMIN_API_KEY.
Security & Exports
Admin tools for auditor-grade exports: signing keys, recipient registry, export policy, and encrypted export approvals.
Identity & Access (Users)
List
Selected
(none)
Org API Tokens (scoped)
Admin-only. Org-scoped tokens can be limited by scopes (e.g. connectors:write, evaluation:read, reports:read, exports:write) and used in the
UI header as an X-API-Key.
List
Selected
(none)
Org Signing Keys (seal + bundle signatures)
List
Selected
(none)
Export Recipients (RSA public keys)
List
Selected
(none)
Export Policy (per engagement)
(none)
Encrypted Export (approval flow)
Requires a sealed snapshot + recipient RSA public key.
Requests
Selected
(none)
After downloading, run: backend/.venv/bin/python tools/verify_encrypted_bundle.py --bundle ... --recipient-private-key ... --keys-bundle ...
Reports (PDF)
Generate and download a PDF report for the selected engagement.
List
Selected
(none)
Audit Logs
Read-only log of audit-relevant actions (seeds, requests, exceptions, snapshots, etc.).
List
Selected
(none)