Assess · Map · Remediate · Evidence · Report — referenced to NIST CSF 2.0, CIS v8, CISA CPGs

Know your posture.
Control your risk.

Praevyn connects the whole loop: assess your controls, map gaps to recognized frameworks, assign owners and due dates, attach evidence, and watch your posture score move — built for organizations that carry real cyber risk without a full internal GRC team.

Referenced to recognized frameworks Board-ready executive report Free plan: full platform, one assessment, no credit card

Illustrative example — not customer data.

Overall Score
82/ 100
Grade BManaged maturity · illustrative example
Framework Coverage
  • NIST CSF 2.0
  • CIS Controls v8
  • CISA CPGs
  • FTC Safeguards
  • Microsoft Baselines
Top Quick Win
Enable phishing-resistant MFA for admins

Removes the most common path to admin account takeover. Mapped to NIST CSF 2.0 PR.AA-05 and CISA CPG 2.H.

Critical priority

Assumed security is not measured security.

Praevyn turns assumptions into a measured, evidence-linked posture score — with a clear, owned path to improvement.

11

security domains assessed end to end

Praevyn scores every domain from access and identity through resilience, then maps each gap to NIST and CISA guidance and tracks remediation until the risk is closed.

432

question-to-control mappings across eight frameworks

Answers map automatically to NIST CSF 2.0, CIS Controls v8, CISA CPGs, ISO/IEC 27001, SOC 2, PCI DSS, HIPAA Security Rule and OMB M-22-09 — so one assessment produces framework-referenced output instead of separate spreadsheets.

10,000

Monte Carlo iterations behind every loss estimate

Financial exposure is modeled from your own three-point loss and frequency estimates, with P10–P90 ranges and a confidence rating — never a percentage of revenue or an industry average.

Figures describe the Praevyn platform itself, not customer outcomes or industry benchmarks. Assessment inputs are self-attested unless supporting evidence is uploaded and accepted. Financial exposure is modeled per organization from your own inputs — Praevyn never derives loss from a percentage of revenue or a published average breach cost.

Run a real security program without building a GRC team.

Measure, prioritize, assign, evidence and report — in one connected system instead of five disconnected spreadsheets.

Measure posture

Run a structured assessment across 11 control domains for a deterministic, repeatable maturity score.

Identify top risks

See which gaps carry the most risk for your organization, with the reasoning shown.

Assign remediation

Turn findings into tracked items with an owner, a due date and attached evidence.

Executive reporting

Generate board-ready reports with heatmaps, roadmaps and framework references.

A structured control assessment — with everything that has to happen after it.

Not another survey. A deterministic scoring engine, framework-referenced findings, owner-assigned remediation, evidence tracking and an AI narrative layer that explains the result in plain language.

11 control domains

Governance, Identity, Endpoint, Network, Email, Cloud, Data, Awareness, IR, VulnMgmt, Physical.

Deterministic scoring

Weighted category scoring with critical-finding penalties. Same answers → same grade, always.

AI recommendations

Ask 'why did I score a 72?' and get an answer generated from your own assessment data, with recommendations referenced to recognized guidance. AI writes the narrative; scoring stays deterministic.

Executive reports

Board-ready report with heatmaps, quick wins and a 90-day / 6-month / 12-month roadmap.

Remediation tracker

Assign owners, due dates and evidence. Closing a finding raises its credit immediately; accepted evidence raises it further.

Historical trend

Compare assessments over time to show leadership and insurers how your posture has changed.

Every recommendation, referenced.

Findings and recommendations reference recognized cybersecurity frameworks and guidance, so reviewers can trace each item back to its source.

NIST CSF 2.0
NIST SP 800-53
NIST SP 800-61 Rev. 3
NIST SP 800-171
CISA CPGs
CIS Controls v8
OWASP Top 10
FTC Safeguards
Microsoft Baselines
AWS Well-Architected
Azure Security Benchmark
Google Workspace Guidance
Included with every workspace

A ready-to-adopt security policy suite — not a blank template.

Auditors, insurers and enterprise buyers all ask the same question: show me your written policies. Most organizations either don't have them, or hold a consultant-built binder nobody maintains. Praevyn ships ten interconnected policies — governance, access control, data protection, vulnerability management, incident response, security awareness, business continuity, third-party risk, acceptable use, and monitoring — written in a defensible, audit-ready structure.

  • Framework-aligned by design
    Each policy cites NIST CSF 2.0, NIST SP 800-53 Rev. 5, CIS Controls v8.1, and CISA CPGs — the references commonly requested during audits and cyber-insurance reviews.
  • Editable in Word, Google Docs, or Pages
    Download both PDF and .docx. Replace [BRACKETED] placeholders with your organization's specifics and route through legal for approval.
  • Answers the questions that block deals
    Vendor security questionnaires, SOC 2 readiness, HIPAA/PCI due diligence and RFPs routinely require documented policies. Praevyn gives you a drafted starting point instead of a blank page.
  • Connected to your live posture
    Policies map back to the controls Praevyn scores and tracks — so what's written and what's operating stay in the same system.

Templates are provided for internal adaptation. Review with legal counsel and obtain executive approval before adoption.

Straightforward pricing.

Start free with the full platform and one assessment — no credit card. Professional adds unlimited assessments as your program matures.

Designed to reduce assessment overhead

Traditional cybersecurity assessments can require significant time, specialist involvement and financial investment depending on scope.

Structured, repeatable workflow

Deterministic scoring plus an AI narrative layer produces a consistent, board-ready output that can be re-run as your program evolves.

Cyber-insurance readiness summary

A directional view of commonly requested security controls. Coverage, pricing and evidence requirements are determined independently by each insurer and broker.

Free

$0Forever

Full access to Praevyn, including one security assessment.

  • Full access to Praevyn
  • 1 security assessment
  • Assessment results and reporting
  • Access to all platform tools

Professional

Most popular
$399per org / month

Everything in Free, plus unlimited assessments.

Everything in Free + unlimited assessments.

  • Everything in Free
  • Unlimited security assessments
  • 14-day free trial

Enterprise

CustomVolume & multi-site

For multi-entity organizations, MSPs, and regulated industries.

  • Everything in Professional
  • SSO / SAML & role-based access
  • Custom branding & white-label reports
  • API access & data export
  • Dedicated success manager
  • Custom framework mapping (HIPAA, PCI, ISO)

Free includes full access to Praevyn and 1 assessment · Professional adds unlimited assessments · No credit card for Free · Cancel anytime

Praevyn is a cybersecurity maturity decision-support platform. It does not provide certification, legal advice, a penetration test or a guarantee of compliance or insurance eligibility.

Ready to measure your posture?

Your first assessment is free — full platform access, no credit card.

Security & trust.

Built with security-first architecture and privacy by design.

TLS encryption in transit

All data is encrypted between your browser and our servers.

Encryption at rest

Data is stored on managed infrastructure that provides encryption at rest.

Organization-enforced MFA

Owners can require TOTP authenticator apps or emailed codes for accounts in their organization.

Row-level access controls

Users can only access the organizations and data they are authorized to see.

No payment card data stored

Payment details are handled by Stripe — we never store card numbers.

Praevyn is a decision-support platform — not a certification, audit or legal-advice service. For details on how we handle data, see our Privacy Policy and Methodology & limitations pages.