tormine://nodes/eu-1 · session secure · build 0.4.7-dev
$ ./tormine --statusstage: active development · early access open
>>>------------------------------------------------------------------------>
// CYBER COMPLIANCE OPERATIONS

TORMINEStorm-grade compliance.
Audit-ready output.

Tormine is an AI-assisted cyber compliance, risk and testing workspace being built for teams that need evidence, policies and security posture clarity — without the spreadsheet chaos.

ISO 27001NIS2SOC 2DORAGDPRAPRANYDFSPCI DSS
09
MODULES
08
FRAMEWORKS
DEV
STATUS
// LIVE FEED — /var/log/tormine.audit
tormine.audit · tail -futc 03:14:07
root@tormine:~$ init --workspace acme-corp
ok · workspace mounted
tormine:~$
GAP SCAN
OK
POLICIES
DRAFT
FINDINGS
7 CRIT
$ dmesg | grep torminekernel · userland · ok
[ OK ] POST · cryptographic self-test ............ OK
[ OK ] MOUNT /controls (iso27001, nis2, soc2) .... OK
[ OK ] INIT ai-gap-engine v0.4 ................... OK
[ OK ] LOAD policy-generator (9 templates) ....... OK
[ OK ] ATTACH risk-register, supplier-register ... OK
[ OK ] OPEN connectors: aws · azure · google · m365 · slackOK
$ cat /var/log/compliance.errors5 recurring incidents
// THE PROBLEM

Compliance posture degrades silently.

0001spreadsheet rotControls tracked in 14 different .xlsx files. Nobody knows which is current.
0002evidence chaosScreenshots in Slack DMs. Policies in Google Docs. Logs in S3. Audit in 2 weeks.
0003framework overlapISO, NIS2 and SOC 2 ask the same things in different words. You answer them three times.
0004pentest in PDFFindings live in a static report. Remediation lives in nobody's backlog.
0005risk in someone's headThe CISO knows the top risks. The risk register doesn't.
$ tormine modules --list9 modules · roadmap visible
// WHAT TORMINE DOES

A living compliance workspace — not a static spreadsheet.

MODULE · M01
AI GAP ANALYSIS

Self-assess against major frameworks. AI maps answers and evidence to missing or weak controls.

MODULE · M02
POLICY GENERATOR

Generate policies, procedures and control documents tailored to your framework target and business context.

MODULE · M03
RISK REGISTER

Identify, score, assign and treat risks. Keep a versioned trail of decisions.

MODULE · M04
SUPPLIER REGISTER

Vendors, services, criticality, data access, contracts and recurring reassessments.

MODULE · M05
EVIDENCE VAULT

Collect and map evidence to controls — uploads, questionnaires, integrations, scan output.

MODULE · M06
PENTEST REPORTING

Live pentest workflow: findings, severity, assets, screenshots, remediation, executive summary.

MODULE · M07
SCAN ORCHESTRATION

Planned technical testing and scan importers — map results to risks and controls automatically.

MODULE · M08
CONNECTORS

AWS, Azure, Google, M365, Slack and more — designed to pull evidence in continuously.

MODULE · M09
POSTURE DASHBOARD

What's missing, what's improving, what's overdue, what needs management attention. Live.

$ tormine frameworks lsreadiness · gap analysis · evidence mapping
// FRAMEWORK READINESS

One workspace, many control sets.

Tormine maps overlapping requirements once — answer a control in ISO 27001 and we'll surface where it lands in NIS2, SOC 2 and DORA. Built for readiness and continuous gap analysis, not for issuing certifications.

Framework
Region
Controls
Module
ISO 27001
GLOBAL
114
[ READY ]
NIS2
EU
[ READY ]
SOC 2
US
TSC
[ READY ]
DORA
EU · FIN
[ READY ]
GDPR (security)
EU
Art. 32
[ READY ]
APRA CPS 234
AU · FIN
[ BETA ]
NYDFS 500
US · FIN
[ BETA ]
PCI DSS
GLOBAL
v4.0
[ PLAN ]
* Tormine supports readiness, gap analysis, evidence collection and documentation. It does not issue formal certifications.
$ tormine gap-analysis --ai-assistscan complete · 03:14:08
// AI-ASSISTED GAP ANALYSIS

Answer once. Map everywhere.

Answer structured questions, upload existing evidence, or connect a system — Tormine's AI maps the input against your target frameworks, flags missing or weak controls, and proposes the next concrete action.

  • structured questionnaires per framework
  • evidence upload + automatic control tagging
  • AI-suggested remediation per gap
  • overlap detection across frameworks
$ tail control-matrix114 controls · iso 27001
COVERED
PARTIAL
GAP
N/A
$ tormine policies generate --missing9 drafts queued · review required
// AI POLICIES & DOCUMENTS

Generate the documents auditors keep asking for.

Generate individual documents or whole document sets based on your framework target, business context and identified gaps. Edit, version and approve — then map them to controls as evidence.

[+]Information Security Policy
[+]Access Control Policy
[+]Incident Response Plan
[+]Business Continuity Plan
[+]Vendor Security Policy
[+]Risk Management Procedure
[+]Asset Management Policy
[+]Acceptable Use Policy
[+]Backup and Recovery Policy
// EVIDENCE VAULT

One place every auditor's request lands.

Evidence
Source
Control
State
AWS IAM password policy.json
aws-connector
A.9.4
FRESH
Backup restore test 2026-04
upload
A.12.3
FRESH
MFA enforcement screenshot
m365
A.9.4
AGED
Incident drill minutes Q1
upload
A.16.1
FRESH
Vendor SOC 2 report — Acme
supplier
A.15.1
MISSING
$ tormine risks ls --owner allregister · v3.2
// RISK REGISTER

Risks with owners, scores and history.

ID
Risk
Sev
Status
R-014
Ransomware via phishing
HIGH
MITIGATING · j.tamm
R-021
Cloud key leakage
CRIT
OPEN · m.kask
R-009
Single supplier outage
MED
ACCEPTED · ciso
R-031
Insider data exfil
MED
MITIGATING · j.tamm
R-005
Backup not tested
LOW
TREATED · ops
$ tormine suppliers --criticalvendor oversight
// SUPPLIER REGISTER

Who you depend on — and what they hold.

Vendor
Service
Crit
Evidence
Review
AWS
infra
CRIT
DPA · SOC 2
OK
Stripe
payments
HIGH
PCI DSS
OK
Acme Helpdesk
support
MED
REVIEW
MailGorilla
email
MED
DPA
OK
Tiny LLC
consulting
LOW
NDA
EXPIRED
$ tormine pentest --engagement Q2-2026-EXTlive monitoring · findings sync
// PENTEST WORKFLOW

Pentests stop being a PDF on a shared drive.

Manage the engagement end-to-end: test process, findings, severity, affected assets, screenshots and evidence, remediation status, executive summaries — and the final report.

  1. [01] scope · assets · stakeholders
  2. [02] live finding intake
  3. [03] evidence + screenshots attached
  4. [04] remediation tracking
  5. [05] executive summary + signed report
  6. [06] findings → risk register + controls
// LIVE FINDINGS
ID
Finding
Sev
Status
F-101
SQLi · /api/v1/users
CRIT
OPEN
F-098
Stored XSS · admin panel
HIGH
IN PROGRESS
F-094
Outdated TLS on edge LB
MED
FIXED
F-088
Verbose error messages
LOW
ACCEPTED
Findings auto-link to assets, risks and the relevant ISO/NIS2/SOC 2 controls.
$ tormine scans queueorchestration · planned module
// AI-ASSISTED SCANNING

Run checks. Import scans. Close the loop.

Planned technical testing and scan orchestration: run lightweight checks, import results from external scanners, map findings to risks and controls, and track remediation alongside the rest of your posture.

SCAN QUEUE — tail
tls-checkedge.tormine.com[DONE]
dns-hygienetormine.com/*[DONE]
cloud-misconfigaws/eu-west-1[RUNNING]
secrets-scangithub/tormine/*[QUEUED]
ext-pentest-importQ2-2026.pdf[PARSING]
$ tormine connectors --listdesigned to integrate
// INTEGRATIONS

Pull evidence in — automatically.

Tormine is designed to integrate with cloud and collaboration platforms so security posture and evidence can be gathered continuously instead of chased every audit cycle.

AWS[ READY ]
iam · cloudtrail · config
Microsoft Azure[ READY ]
tenant · defender
Google Workspace[ READY ]
admin · drive · login audit
Microsoft 365[ BETA ]
entra · purview
Slack[ BETA ]
audit log · alerts
GitHub[ PLAN ]
secrets · branch policy
Jira / Linear[ PLAN ]
remediation tickets
SIEM / EDR[ PLAN ]
incident bridge
$ tormine posture --livecontinuous · not a snapshot
POSTURE
72%
iso 27001 readiness
OPEN GAPS
23
7 critical · 11 medium
POLICIES
34/41
approved & in force
EVIDENCE
218
fresh artifacts < 90d
REQUEST EARLY ACCESS
tormine.com · build list
// JOIN THE BUILD LIST

Tormine is being built. Get in early.

We're onboarding design partners — CISOs, IT managers, MSPs, security consultants and founders preparing for ISO 27001, NIS2, SOC 2 or DORA. Tell us where you are, and we'll show you what Tormine can take off your plate.

  • early access to modules as they ship
  • direct line to the build team
  • influence the roadmap
  • founder pricing
secure channel · no spam