Ask standards in plain language.
Bring OSCAL catalogs into the conversation and get answers your team can use immediately.
For risk, compliance, and audit readiness.
Built for the AI era.


Bring OSCAL catalogs into the conversation and get answers your team can use immediately.
Keep compliance work moving while write, read-only, and admin responsibilities stay clear.
Connect documents, spreadsheets, and APIs to NIS2, Grundschutz++, ISO, and GDPR workflows.
Build questionnaires for any framework, track every response, and surface gaps before they become audit findings.
Securely onboard your organization with SAML SSO, role-based access controls, audit logs, and isolated workspaces.
See how Secani helps your team turn security work into clear, audit-ready progress.
OSCAL use cases across government and the public sector.
Explore OSCAL use casesThe audit is coming up. Where is the evidence for the IT baseline check?
We are extending the scope. Which modules do we need to model?
New cloud service. Which safeguards apply in the baseline check?
Analyze data and spot what is still missing before it shows up in the audit.
| A | B | C | D | E | F | G | H | |
|---|---|---|---|---|---|---|---|---|
| 1 | Asset | Module | Status | Owner | Due | Evidence | Priority | Revision |
| 2 | FW cluster PROD | OPS.1.1.4 Firewall | In progress | IT Operations | Apr 15 | Rule set v3 | High | Q2/26 |
| 3 | M365 tenant | APP.5.2 Microsoft 365 | Open | CISO | Apr 22 | MFA evidence missing | High | Q2/26 |
| 4 | Backup server | OPS.1.3 Backup | Done | Infra team | ongoing | Restore test 02/26 | Medium | Q2/26 |
| 5 | VPN access | OPS.1.1.5 Remote access | In progress | Network | Apr 19 | Bastion concept | High | Q2/26 |
| 6 | Client hardening | SYS.2.1.2 Endpoints | Open | Workplace IT | Apr 30 | Baseline missing | Medium | Q2/26 |
| 7 | SIEM | DER.2.2 Logging | Done | SOC | ongoing | Use cases v5 | Medium | Q2/26 |
| 8 | Emergency plan | ORP.4 Continuity | In progress | BCM | May 08 | Test date open | High | Q2/26 |
| 9 | Supplier risk | OPS.2.1 Third parties | Open | Procurement | May 12 | Assessment missing | Medium | Q2/26 |
| 10 | Patch management | OPS.1.1.2 Patch process | In progress | IT Operations | Apr 25 | SLA report | High | Q2/26 |
| 11 | IAM roles | ORP.2 Permissions | Done | Identity team | ongoing | Recert. March | Low | Q2/26 |
| 12 | Awareness | ORP.3 Training | In progress | HR + CISO | May 05 | Attendance 84% | Medium | Q2/26 |
| 13 | Audit package | CON.1 Evidence | Open | Compliance | May 17 | Docs incomplete | High | Q2/26 |
| 14 | KPIs | ISMS monitoring | Done | CISO Office | ongoing | Quarterly report | Low | Q2/26 |
| 15 | ||||||||
| 16 | ||||||||
| 17 | ||||||||
| 18 | ||||||||
| 19 | ||||||||
| 20 | ||||||||
| 21 | ||||||||
| 22 | ||||||||
| 23 | ||||||||
| 24 |
Review the imported security concept for missing or incomplete protection needs assessments.
Jonathan Bezdek
Co-Founder, CTO