PurpleWASP platform

Connected governance, risk and assurance work.

PurpleWASP connects Policy & Document Management, Assets, Risks, Controls, Compliance, external provider evidence and Third-Party Risk so teams can follow ownership, decisions, assurance and change in context.

One connected operating model

Move from context to governance to assurance

Each workspace has its own lifecycle and authority. PurpleWASP connects them through explicit relationships rather than collapsing them into one generic register.

1. Establish context

Know what matters

Maintain the Assets, services, owners and external dependencies that governance decisions relate to.

2. Govern

Set expectations

Create controlled Policies and other governed documents with approval, publication, review and acknowledgement.

3. Assess

Understand exposure

Assess Risk, quantify selected scenarios with FAIR and govern treatment, exceptions and reassessment.

4. Control

Define and assure safeguards

Adopt Controls, establish applicability, track implementation and support assessments, tests, evidence, issues and exceptions.

5. Demonstrate

Manage compliance readiness

Operate the ISO 27001 ISMS, manage SOC 2 readiness, run Cyber Essentials/Plus preparation, use NIST CSF 2.0 Profiles and implement CIS Controls v8.1—all on top of shared organisation Controls.

6. Extend

Govern third-party dependency

Discover, tier, assess, assure, contract, review and monitor suppliers and services that support the organisation.

Operational workspaces

Purpose-built lifecycles, connected by shared context

Use each workspace for the decisions it owns, then follow links across the platform when a decision depends on another domain.

PurpAI

Understand, navigate and act from connected governance context.

PurpAI combines product guidance with authorised live context. Ask about posture and relationships, select exact records conversationally, open the relevant workflow, prepare an editable Risk draft from a verified Asset, or start supported Third-Party workflows with explicit confirmation.

  • Permission-aware live context and relationship reasoning.
  • Exact record and deep-workflow navigation.
  • Contextual drafts that still require normal review and save.
  • Confirmation-gated supported actions and on-demand Suggested Attention.
Operational confidence

Keep decisions traceable to owners, evidence and lifecycle state.

Role-based access, approval workflows, review records, version history, activity logs, due dates and explicit relationships help teams understand what changed, why it changed and what needs attention next.

  • Role-aware access and assigned work.
  • Approval, exception and review decisions.
  • Linked owners, actions and due dates.
  • Evidence and activity retained with context.
Implementation

Adopt the platform in controlled stages

A phased rollout helps teams establish ownership, clean source data and working cadences before increasing scope.

Establish governance

Confirm scope, module owners, roles, access and the first business outcomes.

Prepare trustworthy data

Clean the initial Assets, Policies, Risks, Controls, Compliance records or third-party data before migration or bulk import.

Launch one repeatable workflow

Prove ownership, lifecycle, reporting and hand-offs with a manageable group before expanding.

Connect additional workspaces

Add explicit relationships once the underlying ownership and operating cadence are working.

Security and administration

Access designed around organisational responsibilities

Administrators manage users, role mappings, module access, groups, account security and organisation settings. AI capabilities can be governed at organisation level, and two-factor authentication can be required according to the configured security policy.

Need a fit assessment?

Discuss required workflows, user roles, rollout scope and support expectations.