19 frameworks · controls decoded

Security frameworks, decoded.

Drill from framework → platform → control. Get plain-English explanations, CLI checks, remediation steps, and cross-framework mappings — powered by AI.

Explore frameworks
3 free AI lookups / day · or go unlimited from $4.99
Drill-down browse
AI control explainers
Cross-framework mappings
// Level 1

Pick a framework

7 platforms
CIS Benchmarks
CIS

Prescriptive, consensus-based hardening baselines for cloud, OS, and platforms. Curated highlights — full benchmark PDFs at cisecurity.org.

Explore
6 functions
NIST Cybersecurity Framework 2.0
NIST CSF 2.0

Outcome-based framework for managing cybersecurity risk across six core functions.

Explore
20 control families
NIST SP 800-53 Rev 5
NIST 800-53

Catalog of security and privacy controls for federal information systems.

Explore
1 requirements
PCI DSS v4.0
PCI DSS

Payment Card Industry Data Security Standard — 12 requirements protecting cardholder data.

Explore
13 tactics
MITRE ATT&CK
MITRE ATT&CK

Globally-accessible knowledge base of adversary tactics and techniques.

Explore
3 maturity levels
ASD Essential Eight
Essential Eight

Australian Cyber Security Centre baseline mitigation strategies — eight controls across three maturity levels.

Explore
4 themes
ISO/IEC 27001:2022
ISO 27001

International standard for information security management systems — 93 Annex A controls in 4 themes.

Explore
5 trust categories
SOC 2 (Trust Services Criteria)
SOC 2

AICPA Trust Services Criteria for service organizations — five trust categories.

Explore
14 families
NIST SP 800-171 Rev 3
NIST 800-171

Protecting Controlled Unclassified Information (CUI) in non-federal systems. 14 control families with 110+ requirements.

Explore
1 categories
OWASP Top 10 Web (2021)
OWASP Web

Top 10 web application security risks, with CWE mappings and mitigations for each category (A01–A10).

Explore
1 categories
OWASP Top 10 API Security (2023)
OWASP API

Top 10 API-specific security risks with attack vectors and mitigations (API1–API10).

Explore
1 categories
OWASP Top 10 for LLM Applications (2025)
OWASP LLM

Top 10 risks for large language model applications: prompt injection, data poisoning, model theft, and more.

Explore
1 sections
APRA CPS 234
APRA CPS 234

Australian Prudential Regulation Authority information security standard for regulated financial institutions.

Explore
3 safeguards
HIPAA Security Rule
HIPAA

US health data protection. Administrative, Physical, and Technical safeguards for protected health information (PHI).

Explore
2 domains
ISO/IEC 27017:2015
ISO 27017

Cloud-specific security controls extending ISO/IEC 27002, with guidance for cloud service providers and customers.

Explore
1 domains
ISO/IEC 27018:2019
ISO 27018

Protection of personally identifiable information (PII) in public clouds acting as PII processors.

Explore
4 functions
NIST AI Risk Management Framework 1.0
NIST AI RMF

AI risk management across four functions: Govern, Map, Measure, Manage — with categories and subcategories.

Explore
17 domains
CSA Cloud Controls Matrix v4
CSA CCM

Cloud Security Alliance control framework: 17 domains and 197 controls for cloud-specific security.

Explore
11 chapters
EU General Data Protection Regulation
GDPR

European regulation governing personal data protection and privacy — 99 articles across 11 chapters with significant global reach.

Explore
// Pricing

Simple, upfront pricing