>>>------------------------------------------------------------------------>
TORMINEStorm-grade compliance.
Audit-ready output.
Tormine is an AI-assisted cyber compliance, risk and testing workspace being built for teams that need evidence, policies and security posture clarity — without the spreadsheet chaos.
Compliance posture degrades silently.
A living compliance workspace — not a static spreadsheet.
Customer-facing order and intake flow for framework-specific compliance assessments.
Structured assessment answers, evidence and connector data analyzed by queued AI jobs with operator review.
Clause-by-clause answers, verdicts, scope filtering, cross-framework mappings and implementation tracking.
Per-clause uploads, secure downloads, signed links, evidence packs and file parsing for DOCX/PDF/MD/TXT.
Statement of Applicability exports, assessment reports, PDF packages and evidence bundle downloads.
126 imported policy templates with preview, clause mapping, customer requests and admin approval workflow.
Subscription plans, AI-assisted draft writing, markdown review, approval and monthly billing.
Implemented AWS, Google Drive and Microsoft 365/Graph connectors for evidence collection and AI gap fill.
Risk library import, scoring, owners, treatment status and editable register records.
Supplier/provider register for DORA Article 30 with catalog support and CSV export.
Operator-led engagement ordering, quote calculation, scope-based pricing and engagement placement.
Target inventory, ownership verification and per-target management for security testing.
Pentest scan records, start/show/export flows and report output ready for backend scan import later.
In-app notification bell, preferences, AI-complete and assessment-delivered notifications.
Customer helpdesk, FAQ, account/company settings, add-on subscriptions and onboarding wizard.
One workspace, many control sets.
Tormine maps overlapping requirements once across 28 supported frameworks and 713 seeded clauses. Built for readiness and continuous gap analysis, not for issuing certifications.
Answer once. Map everywhere.
Answer structured questions, upload existing evidence, or connect a system — Tormine's AI maps the input against your target frameworks, flags missing or weak controls, and proposes the next concrete action.
- ▸ structured questionnaires per framework
- ▸ evidence upload + automatic control tagging
- ▸ AI-suggested remediation per gap
- ▸ overlap detection across frameworks
Generate the documents auditors keep asking for.
Generate individual documents or whole document sets based on your framework target, business context and identified gaps. Edit, version and approve — then map them to controls as evidence.
One place every auditor's request lands.
Risks with owners, scores and history.
Who you depend on — and what they hold.
Pentests stop being a PDF on a shared drive.
Manage the engagement end-to-end: test process, findings, severity, affected assets, screenshots and evidence, remediation status, executive summaries — and the final report.
- [01] scope · assets · stakeholders
- [02] live finding intake
- [03] evidence + screenshots attached
- [04] remediation tracking
- [05] executive summary + signed report
- [06] findings → risk register + controls
Run checks. Import scans. Close the loop.
Planned technical testing and scan orchestration: run lightweight checks, import results from external scanners, map findings to risks and controls, and track remediation alongside the rest of your posture.
Pull evidence in — automatically.
Tormine is designed to integrate with cloud and collaboration platforms so security posture and evidence can be gathered continuously instead of chased every audit cycle.
Tormine is being built. Get in early.
We're onboarding design partners: CISOs, IT managers, MSPs, security consultants and founders preparing for ISO 27001, NIS2, SOC 2 or DORA. Tell us where you are, and we'll show you what Tormine can take off your plate.
Tormine is developed and owned by WiSec OÜ. Early-access requests are addressed to info@wisec.ee.
- > early access to modules as they ship
- > direct line to the build team
- > influence the roadmap
- > founder pricing