PlatformCommand · Scout · Anvil One record · Three products · One analyst
CommandProduct 01 of 03

Give your security
program a memory.

Your tools connect once. From there the strategy, controls, findings, projects and risk all live on one record that carries forward. Nothing is re-derived. Nothing is lost between quarters.

Walk the loop

Fig. 01 · Command Center · live program health

Command Center: program health score, findings past due, maturity by domain and the risk heatmap

Your program already exists. It is just scattered across a controls spreadsheet, a findings tracker, a roadmap deck and four people's inboxes. Command does not ask you to build a program. It gives the one you have a single place to live, and a memory that survives the quarter.

§ 01The loop

Walk the loop.
Every screen connects.

Connections feed the record. Strategy sets what the record is for. Assessment produces findings, findings become projects, projects move maturity, and maturity moves the risk position, which sets the next quarter's plan. In most stacks those are separate tools joined by exports. Here they are one record, and each step already knows what the last one found.

Command Connections
Attack surfaceOperationsConnectionsTechnology
AWSAmazon Web ServicesActiveFeeds 22 controls2 findingsLast synced Jul 24, 11:00 PM
EntraMicrosoft Entra IDActiveFeeds 18 controls1 findingsLast synced Jul 24, 11:00 PM
WorkspaceGoogle WorkspaceActiveFeeds 9 controls0 findingsLast synced Jul 24, 11:00 PM
CrowdStrikeCrowdStrike FalconActiveFeeds 14 controls3 findingsLast synced Jul 24, 11:00 PM
GitHubGitHubActiveFeeds 11 controls1 findingsLast synced Jul 24, 11:00 PM
CloudflareCloudflareActiveFeeds 7 controls0 findingsLast synced Jul 24, 11:00 PM
OktaOktaActiveFeeds 26 controls2 findingsLast synced Jul 24, 11:00 PM
WizWizActiveFeeds 19 controls4 findingsLast synced Jul 24, 11:00 PM
JiraAtlassian JiraActiveFeeds 8 controls0 findingsLast synced Jul 24, 11:00 PM
Active 24 connectionsLast sync 11:00 PMEvidence refreshed continuously
Command Strategy
Active · Dec 31, 2025 to Dec 30, 20262026 Strategic Plan
Goals3
Initiatives4
On track82%
Detect and respond to threats In progressHigh Due Q4 202634% OKRs · 2Mean time to detect62%Endpoint coverage88%Linked risk · 1Ransomware via unmanaged endpointInitiatives · 2 Deploy EDR to all endpointsEnterprise DLP
Protect The Pylon Group In progressHigh Due Q4 202661% OKRs · 2Critical findings closed71%Control coverage83%Linked risk · 1Unauthorized access to systemsLinked project · 1 EDR deployment2 initiatives
Comply with laws and regulations Not startedHigh Due Q1 20278% OKRs · 2Obligations mapped33%Policies reviewed12%Linked risk · 1Regulatory finding at next auditInitiatives · 2 HIPAA gap assessmentUpdate policy library
Command NIST CSF 2.0
Framework assessmentNIST CSF 2.0
68%complete
Govern14/14
Identify18/22
Protect21/31
Detect6/14
Respond4/16
Recover2/9
SubcategoryStatusMaturity
GV.OC-01Organizational mission understoodMet4.0
ID.AM-01Hardware inventories maintainedMet4.0
PR.AA-01Identities and credentials managedPartial3.0
DE.CM-01Networks and environments monitoredPartial2.0
RS.MA-01Incident response plan executedGap1.0
Command Access control
Control library142 mapped
CIS v8 · Access control
6.5Multi-factor authenticationMet
6.3Unique account credentialsMet
8.2Audit log collectionPartial
5.1Asset inventory maintainedMet
11.1Data recovery testedGap
3.3Data access control listsPartial
CIS v8 · 6.5Multi-factor authentication

Require MFA for all administrative and remote access to in-scope systems.

Answers these frameworks
NIST PR.AA-03ISO A.5.17SOC 2 CC6.1
Evidence · 3
Okta-MFA-policy.pdfApr 26
Admin-MFA-export.csvlive
Access-review-Q2.pdfJun 26
MFMia FloresTested quarterly
Command Findings
27 open · 2 critical · 4 overdueFindings
SeverityFindingFrameworkOwnerStatusAge
CriticalAWS access keys unrotated 90+ daysFND-2026-002NIST CSFJDOpen12d
CriticalPublic S3 bucket exposed to internetFND-2026-024CIS v8PMTriage3h
HighNo MFA on administrative accountsFND-2026-007CIS v8MFIn progress4d
HighDisaster recovery plan review overdueFND-2026-014ISO 27001MFIn review6d
MediumBackup restore not tested this quarterFND-2026-011SOC 2PMOpen1d
MediumVendor SOC 2 report expiring in 30 daysFND-2026-021NIST CSFJDOpen9d
LowLogging gaps in staging environmentFND-2026-018SOC 2MFResolved2d
Command EDR deployment
From FND-2026-007 · 8 of 14 doneEDR deployment
60%on plan
To do3
Pilot ring expansionEDR-31PM
Tune detection rulesEDR-34MF
Decommission legacy AVEDR-38
In progress2
Phased rollout to all corporate endpoints60%DC
Endpoint coverage report30%MF
Blocked2
Server fleet agentsAwaiting change approvalEDR-22PM
Legacy VDI image rebuildOwner unassignedEDR-27
Done8
Phase 1 rollout
Vendor onboarding
Tooling procurement
Linked finding FND-2026-007Owner R. AlvarezTarget Aug 24, 2026Budget $180KReduces RISK-2026-001
Command Risk register
Risk register
RISK-2026-001Unauthorized access to company systemsHigh
Before controls
Almost certain × Severe Critical
After controls
Possible × Severe High

Linked controls reduce this risk by one level.

Properties
StatusIdentified
OwnerR. Alvarez
CategoryIdentity & auth
AppetiteLow
TreatmentMitigate
Target dateAug 24, 2026
Linked finding · 1
No MFA on administrative accountsFND-2026-007 · open
Linked control · 1
Access control managementCIS v8 · 6 · coverage partial
07 returns to 01The loop is the product
§ 02Connections

Fifty-nine connections.
One evidence layer.

A control backed by a connection is evidenced continuously rather than screenshotted once a year. Coverage runs across identity, cloud, code, endpoint and ticketing, and every connection reports which controls it feeds and which findings it has raised.

Okta
Entra ID
Duo
JumpCloud
AWS
Azure
Google Cloud
Wiz
GitHub
GitLab
CrowdStrike
SentinelOne
Defender
Huntress
Intune
Jamf
Qualys
Rapid7
Cloudflare
Proofpoint
KnowBe4
1Password
Axonius
Jira
59 connections across identity, cloud, code, endpoint and ticketingAll integrations
Hudson
§ 03The analyst

It runs the loop
with you.

Hudson has the whole record open: every control, every finding, every assessment you have ever run. It drafts, investigates and plans inside the loop rather than beside it, shows the evidence behind each answer, and stops for your approval before anything changes. One keystroke from any screen.

AssessWalked SOC 2 CC6.1 out loud.Drafted the narrative, proposed Met at maturity 4.0, attached the Q2 access review, and held for approval.
InvestigateFinding 118 has been open 71 days.Traced it to two controls and one overdue project, then wrote the escalation note with the owner named.
PlanNext quarter's roadmap.Sequenced nine projects by maturity lift per dollar and flagged the two with no owner.
BriefBoard deck for Thursday.Built eleven slides from live findings, every figure linked back to the record it came from.

It asks before it acts · Every answer shows its evidence

§ 04Three seats

One program model.
Three seats.

The same record, read from wherever you sit. One company, a book of clients, or a portfolio of them. Nothing is rebuilt for the next seat up.

§ 05Next

See it on
your own program.

Bring a framework you are held to and a finding you have been carrying. We will walk the loop with your material, not a demo tenant.

All three products