Digital Trust,
proven live at the AWS Summit.

Meet Cybervergent at AWS Summit Johannesburg. See how governance, compliance, risk, data security and privacy converge into one continuously assured posture on AWS, and register your interest to reserve time with our team on the day.

WhereSandton Convention Centre, JohannesburgFind usVisit the Cybervergent standOfficial event page ↗

Trusted by the teams behind the emerging markets’ digital economy

Paystack
Moniepoint
Sterling Bank
Wema Bank
Zenith
Absa
Fidelity Logo Gh.png
UMB
Interswitch
CBG
MoMo PSB
eTranzact
Payaza
Qore
Heirs Tech
AirArabia
21st Century Tech
Datatrix

See continuous assurance, live on AWS.

CybervergentCybervergentMC

Good morning, María

Ask Datavergent Assist
Get audit-ready across frameworksQuantify and treat top risksRun an internal auditClassify sensitive dataProve control effectivenessAutomate remediation workflows
Get started with Cybervergent
Connect once. We watch everything, always.StartDelegate ▾
Working…
Connecting your stackCloud and on-premise agentReading evidence sources···
Working…
Scanning cloud and on-premise1,284 resources discovered···
Working…
Automated evidence snapshots gathered247 artefacts signed and timestamped···
Working…
Syncing policy documentation from StorageAccess Provisioning Policy found · needs review
Access Provisioning Policy.docxSynced from Storage · version 4 draftView documentRequest attestation
Working…
Classifying PII, PCI, PHI across sourcesCardholder data found outside approved stores
PII12,408 fieldsPCI247 recordsPHINone foundSECRETS3 in vault
customer_export.csv · analytics-archive247 records · emails, card PANs · Data Retention Policy 4.2Policy violationQuarantine nowMask fields
Quarantined · access revoked · fields masked
Working…
Processing change · document sync from StorageDrafting DPIA from live evidence
DPIA · Storage document syncResidual risk · High
Screening answered from live control evidence · 4 of 4 points coveredRequest DPO sign-offExport DPIA
Signed by DPO · filed to the record of processing
Working…
Testing against your frameworksControls: 214 tested against live evidencePolicies: 41 checked for coverageProcedures: 18 walked through···
3 gaps identified. Needs attention
Gap 1 · Least-privilege in production · SOC 2 CC6.1Standing admin access found on production data storesRemediateRaise exceptionRisk treatment
Working…
Generating remediation
control "prod_least_privilege" { framework = "COBIT" requirement = "SOC 2 CC6.1" enforce = true}apply "remediation" { scope = ["flagged_resources"]}
$ cyv controls retest SOC 2 CC6.1 test: mfa-enforcement ......... PASS evidence: #E-4821 written$ cyv evidence verify #E-4821 ... ACCEPTED
Gap 1 closed · retest passed
Gap 2 · Customer-data retention · exception raised, expires Q4Gap 3 · Key & secret rotation · risk treatment planned
Working…
Compliance posture 92%Frameworks readiness 93%Risk in appetite 86%Governance posture 97%Publishing to your Trust Center···
Governance, trust and assurance, running continuously.

Every control tested, every gap owned, and evidence always fresh, not a point-in-time scramble.

Get reportStatement of ApplicabilityInvite auditor
Ask Datavergent Assist
ISO 27001COBITInternal
Connecting your stack
Amazon Web ServicesCloud
Connecting…
OktaIdentity
Connecting…
GitHubSource control
Connecting…
CrowdStrikeEndpoint security
Connecting…
On-premise agentData center
Connecting…
Scanning services
Production cloud (AWS)214 resources
Queued
Customer data store96 resources
Queued
CI/CD pipeline34 resources
Queued
Identity & access126 resources
Queued
Endpoints92 resources
Queued
Evidence snapshots
IAM access-review exportIdentity
Pending
Encryption-at-rest configCloud
Pending
Backup & restore attestationInfrastructure
Pending
Change-approval logCI/CD
Pending
Policies from Storage
Access Provisioning PolicyDOCX
Syncing
Data Retention PolicyDOCX
Syncing
Incident Response PlanPDF
Syncing
Vendor Management PolicyDOCX
Syncing
Sensitive data map
Employee PIIPII · HR systems, 2 stores
Locating…
Cardholder dataPCI · analytics-archive bucket
Locating…
Health recordsPHI · no stores in scope
Locating…
Secrets & keysSecrets · vault, rotated
Locating…
DPIA assessment
Purpose and necessityDocumented from the processing purpose
Queued
Data minimisationOnly policy files sync
Queued
Cross-border transferProcessor outside region
Queued
MitigationsQuarantine control from discovery
Queued
Record of processing
PurposePolicy document sync from Storage
Drafting…
Lawful basisLegitimate interest, assessed
Drafting…
Data subjectsEmployees and vendors
Drafting…
Retention90 days, then automatic deletion
Drafting…
Testing controls & policies
Controls214 tested against evidence
Testing
Policies41 checked for coverage
Checking
Procedures18 walked through
Checking
Cross-mapped frameworks
Map a control once, satisfy many. Your ISO 27001 and COBIT tests automatically cover:
PCI DSS168 controls satisfied
Auto-satisfied
SOC 2142 controls satisfied
Auto-satisfied
POPIA96 controls satisfied
Auto-satisfied
Risk matrix
Likelihood
23421
Impact
Remediating gaps
Production access reviewsIn progress
RPlatform EngACTOCSecurityIBoard
Customer-data retentionIn progress
RDPOACISOCLegalIBoard
Key & secret rotationIn progress
RPlatform EngACISOCRiskIBoard
Continuously assured
Connect your stack
Test controls & policies
Close the gaps
Publish your Trust Center
Access Provisioning Policy Saved just nowGenerate with AIExport Draft Publish Version
TH1H2H3BIUS

Access Provisioning Policy

Version 4 · draft · Owner: CISO · COBIT · SOC 2 CC6.1

1. Purpose

This policy governs how access to production systems and regulated data is requested, approved, reviewed and revoked, so that every grant is justified, least-privilege and fully evidenced.

2. Scope

Applies to all employees, contractors and service accounts across cloud and on-premise systems in scope for ISO 27001 and COBIT.

3. Policy statements

  • Access is granted on a documented, role-based, least-privilege basis.
  • Privileged actions require segregation of duties with independent approval.
  • Access is reviewed at least quarterly and revoked within 24 hours of role change.
  • All grants, approvals and revocations are logged as tamper-evident evidence.

4. Review

Reviewed quarterly by the control owner and attested by the accountable owner.

CommentExplainCopy
“Privileged actions require segregation of duties with independent approval.”
Add a comment or @mention…@Ada Okafor
CancelComment
ActivityAIOutline
Access Provisioning Policy1. Purpose2. Scope3. Policy statements4. Review
412 words · 2,631 charactersComments 0
Access Provisioning Policy · Monitoring LiveRefresh
Collected evidence41 passing · 1 failingOperating with exceptions
95%
MFA on privileged roles
Okta · 61/64Passing
100%
Encryption at rest enforced
AWS · 38/38Passing
100%
Quarterly access reviews
Okta · 12/12Passing
50%
Contractor accounts need MFA
Okta · 3/6Failing
100%
Key rotation within 90 days
AWS · 44/44Passing
100%
Audit logging enabled
AWS · 96/96Passing
97%
Session timeout enforced
Okta · 58/60Passing
100%
No public storage buckets
AWS · 214/214Passing
94%
Least-privilege IAM roles
AWS · 118/126Passing
Tests ContinuousEdit SLAsRefresh
OK19893% of 214 passing
Overdue2Past remediation SLA
Due soon5Approaching SLA window
Needs remediation9Failing, no SLA yet
TestDomainSeverityStatusOwner
MFA enforced on privileged roles
AccessHighOKT. Nkosi
Encryption at rest on data stores
Data securityCriticalOKIT Ops
Quarterly access reviews complete
AccessModerateOKT. Nkosi
Contractor accounts require MFA
AccessHighNeeds remediationT. Nkosi
Sanctions screening coverage
Fin crimeCriticalOverdueCompliance
Backup and restore drill
ResilienceLowOKIT Ops
Policy attestationRequest attestation
Recipients
Kwame Mensah
Wanjiru Kamau
Layla Haddad
Requirements
Require training
Require knowledge check
Minimum score to pass85%
Max attempts to attest3
3 peopleCancelSend request
Request sent to 3 people

One live posture

Governance, compliance, risk, data security and privacy unified across your AWS environment and on-premise systems, continuously updated and ready the moment anyone asks.

Always audit-ready

Evidence is gathered automatically as your team works, from SOC 2 and ISO 27001 to POPIA, so assurance becomes continuous rather than a once-a-year scramble.

AI-native, on AWS

Datavergent Assist connects to your stack, tests controls against live evidence and drafts remediation, purpose-built for how cloud-first teams operate.

Adopt any framework in days, not months

Every framework, pre-built or custom, maps into one control graph that runs compliance, risk, data security, audit and governance.

ISO 27001
SOC 2
PCI DSS
NIST CSF
GDPR
HIPAA
COBIT
NDPA (Nigeria)
Kenya DPA
Ghana DPC
South Africa
Morocco DPL
CSA
HITRUST
85%Less audit prep time
6+Check hours saved daily
97%Within risk appetite
96%Remediation automated

Meet us at the Summit.

Register your interest and we’ll reserve time with our team, a live walkthrough of the platform, and priority notice for our Summit session.

  • A live walkthrough tailored to your environment
  • Dedicated time with the Cybervergent team
  • Priority notice for our Summit session
  • Early access to your own Trust Center

I’m interested

Preferred time for a follow-up
By submitting this form, you accept the terms in our privacy policy.

Cybervergent was named a Technology Pioneer by the World Economic Forum. SOC 2 Type II examination completed by an independent AICPA-accredited auditor; ISO/IEC 27001 and ISO/IEC 42001 certified via MSECB. AWS, Amazon Web Services and the AWS logo are trademarks of Amazon.com, Inc. or its affiliates. All third-party names and marks referenced on this page, including AWS, the World Economic Forum, AICPA, MSECB, PCI DSS and ISO, are trademarks of their respective owners, are used for identification only, and do not imply endorsement of Cybervergent or its products.