PlatformCommand · Scout · Anvil Advisory & software · Led by a practicing CISO and CIO
Pylon SoftwareThree products · One record

Three products that already know each other.

Command runs the program, Scout watches the third parties, Anvil handles the transaction. They are not integrations of each other. The controls, vendors, findings and evidence are the same objects in all three, so work started in one arrives finished in the next.

See how work crosses

Fig. 01 · One record · which product reads which object

4,182 shared objectsOne record
CommandScoutAnvil
ObjectTypeRead by
Northwind CloudVendor
Logical access controlsCC6.1Control
No admin MFAFND-007Finding
Patient DatabaseAsset
OktaConnection
Access review, Q2EV-441Evidence
Unauthorized accessRSK-001Risk
Project FalconDeal
One object, stored once, read from wherever you sit
§ 01Every day Command

Not another GRC tool.

GRC tools document the program. Command runs it: AI-drafted assessments, a live roadmap, findings worked to closure, and board decks that stay current, all wired into the security tools you already run.

Walk-the-control assessments Live roadmap and budget Findings, open to closed Always-current board reporting
Explore Command For CISOs, vCISOs & PE security leads
Meridian Health Program roadmap Search controls, findings, projects MF
Program Command Center Strategy Roadmap54 Assessments3 Controls Findings27 Risk Reporting Board brief
FY26 Domain All Owner Any Timeline Updated 11:04 PM
FY26 · 54 initiatives · $2.4M committedProgram roadmap
On plan
Open12
Closing4
Closed38
Slipped3
Q1Q2Q3Q4Today
IAM hardeningMF
Vendor reviewsJD
IR tabletopPM
SOC 2 Type IIJD
EDR deploymentDC
Data classificationMF
Policy library refreshPM
Backup restore testsJD
Third-party reviewsMF
Log retention upliftDC
Privileged accessJD
Vendor offboardingPM
DR failover exerciseMF
Segmentation phase 2DC
§ 02Steady state Scout

A TPRM platform, not another vendor list.

Evidence-based scoring, continuous monitoring, and live vendor connection mapping. When an incident hits a vendor, you already know what is exposed and where, before the call comes in.

Evidence-based scoring Live connection mapping Continuous breach monitoring Reusable Trust Profiles
Explore Scout For GRC & security teams · free for vendors
Meridian Health Vendor register Search 142 vendors JD
Portfolio Dashboard Vendors142 Assessments9 Monitoring Supply chain Findings31 Reporting Board pack
Tier 1 Tier 2 Status Monitored Sort Score Synced 4m ago
142 monitored continuously · 38 tier oneVendor register
1 breach
Critical7
Elevated23
Breach1
Overdue6
VendorTierReviewedPostureScore
OktaT1Apr 0292
CloudflareT1Apr 1190
TwilioT2Apr 2288
SnowflakeT1Mar 1886
Beacon PaymentsT2Apr 0584
VantaT3Mar 0581
DatadogT2Feb 2774
Auth0T2Feb 0971
SegmentT3Nov 1467
FivetranT2Dec 0258
Relay LogisticsT3Oct 2852
Northwind CloudBreachT1Jan 0941
Halcyon IDT2Sep 3038
§ 03A transaction Anvil

Diligence becomes the integration plan.

From first look through post-close integration. One platform to assess targets, plan TSAs, execute integration, and report to the board through every phase, instead of a bespoke spreadsheet rebuilt for every deal.

Pre-LOI and deep-dive diligence Auto-discovered tech stacks SBOM and dependency analysis TSA and Day-1 readiness
Explore Anvil For deal, legal & integration teams
Deal pipeline Project Falcon Search findings, systems, docs PM
Deals Pipeline6 Project Falcon Nexus Health Cedar Ridge Falcon Findings18 Data room Day-1 plan
Phase Diligence Workstreams Findings Economics Close target Sep 30
Target · 240 seats · SaaS · $48M EVProject Falcon
62%diligence
ScreenDiligenceTSADay 1Integrate
Workstreams
Tech stack discoveredauto
SBOM & dependency analysisauto
Security posture reviewin review
Identity & access mappingin review
Contract & licence review2 of 9
TSA scope & exit plannot started
Day-1 cutover runbooknot started
Vendor & TPRM inventoryin review
Cloud cost baseline3 of 7
Application rationalisationnot started
Data migration plannot started
Integration test plannot started
Deal impact
Findings18
Critical4
Remediation$1.24M
TSA, 9 months$680K
Synergy, IT$2.1M
Price adjustment−$1.9M
Escrow holdback$900K
One-time capex−$420K
Run-rate savings$340K
Insurance delta−$85K
Net to model−$2.3M
§ 04The seam

Work crosses.
Nothing is re-entered.

This is what one record buys you. A finding raised in diligence is the finding your team closes after the deal. A vendor Scout downgrades is the vendor behind a control Command is holding you to. The object does not get copied, exported or retyped. It is already there.

AnvilCommand Finding 212, Nexus HealthFinding Rated Critical in diligence and priced into the deal model. On Day 1 it is Command's finding, with the owner already named and the clock already running.
ScoutCommand Northwind Cloud, posture 41Vendor The vendor sitting behind CC6.1. Scout's downgrade opens the control Command reports to your board on, before anyone files a ticket.
CommandScout Logical access controls, CC6.1Control Answered once, with evidence read live from Okta. Scout reuses that answer on every vendor assessment that asks for it.

Three products · one object graph · no exports

Hudson
§ 05The analyst

One analyst,
inside all three.

Because the objects are shared, an analyst can finally read all of them at once. Hudson walks controls in Command, scores evidence in Scout and drafts diligence in Anvil, and it is the same analyst with the same context each time. That is only possible on one record.

Walks controls in CommandAssess Scores evidence in ScoutMonitor Drafts diligence in AnvilDiligence
§ 06Next

Built by the same people
who would run your engagement.

Not a side project. The same standard we hold on every client engagement at Pylon.

See the advisory practice