Automate GRC.
Quantify risk.
Stay compliant.
One platform to automate compliance, quantify cyber risk in financial terms, and run security operations — across 71 frameworks, built for CISOs and the teams behind them.
- Critical CVE · remote code executionCritical
- IOC match · C2 beacon activityHigh
- Lookalike domain · brand impersonationMedium
Illustrative product preview.
// Inside the platform
See it work — not just hear about it.
Click through the surfaces your team lives in every day. One platform, one evidence trail, every workflow connected.
// How it works
From connected to audit-ready.
A single workflow takes you from raw infrastructure to board-ready reporting — no spreadsheets in sight.
Connect
Link your cloud, identity, and ticketing stack in minutes — no agents, no rip-and-replace.
Automate
Evidence is collected continuously and mapped across all 71 frameworks at once.
Quantify
Cyber risk is translated into financial impact your board actually understands.
Report
Generate audit packs and live executive dashboards with a single click.
// One platform, eight modules
Everything your GRC team needs, unified.
From threat intel to audit-ready compliance — every module works from one shared evidence trail.
Threat Intelligence
Live CVE and IOC feeds mapped to your actual stack, CISA KEV tracking, and MITRE ATT&CK context on 25 tracked threat actors — so you patch what attackers are exploiting, not just what scanners list.
Incident Response
Case management with kanban boards, AI enrichment, playbook automation, containment actions, root-cause analysis and lessons-learned — integrated with your GRC evidence trail.
Compliance Centre
Multi-framework compliance across ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, Cyber Essentials & more. Track controls, map evidence, and generate audit packs instantly.
Questionnaire AI
Auto-respond to security questionnaires using your existing controls and policies. Save hours on customer due diligence with AI-powered answer suggestions.
Vendor Risk Management
End-to-end vendor assessments, automated questionnaires, contract tracking, risk scoring, supply-chain breach intelligence, and domain impersonation alerts per vendor.
AI Risk Advisor
AI-powered gap analysis, control effectiveness scoring, and compliance reporting. CISO Copilot for instant GRC advice, and financial risk quantification.
Tabletop Exercises
Run realistic cyber incident simulations with AI-generated scenarios, track participant responses, measure team readiness, and generate post-exercise reports.
Compliance Automation
Automate evidence collection, continuous control monitoring, policy attestation, and audit workflows — dramatically reducing manual effort across every framework.
// Built differently
Faster, clearer, smarter than legacy tools.
AI-First Architecture
- Automated evidence collection cuts audit-prep effort
- Continuous control monitoring reduces compliance risk
- Threat intelligence mapped to MITRE ATT&CK surfaces risk early
Enterprise Grade, Startup Speed
- Weeks to value, not months
- Cloud-native, zero legacy baggage
- 99.5% SLA with zero-downtime deployment
Business Language, Not Jargon
- Executive reports translate risk to financial impact
- Board-ready metrics without extra work
- Risk quantification ties security to outcomes
Compliance as Code
- Multi-framework automation (ISO, SOC 2, NIST, PCI)
- Version control for policies and controls
- Audit-ready documentation, always current
Built to integrate with your stack
23 integrations across cloud, identity, endpoint, vulnerability, code and HR — each running automated checks against your live environment.
// Trust & security
Trust what you can verify.
We hold ourselves to the standards we help you achieve — and publish our posture so you can check it, not take our word for it.
UK ICO registered (no. ZC237332), with a public DPA and subprocessor list.
Controls aligned, certification targeted Q3 2027 — run on the same Compliance Centre we sell.
A public policy with safe harbour for good-faith security researchers.
Data encrypted at rest and in transit; MFA available to every user on every plan, and enforced on our own platform-administrator accounts.
Your data is stored in the EU (AWS eu-west-1, Ireland) on every plan. Some processing — hosting, identity, AI features, email and backups — happens in the US under the transfer safeguards in our DPA. Tenant isolation throughout.
A published SLA with service credits — not a marketing number.
We name every sub-processor and the region it processes your data in, rather than summarising it as one badge — see the full sub-processor list.
See exactly where your SOC 2 / ISO 27001 gaps are.
Answer 20 quick questions and get an instant, scored read-out across ten control areas — the strengths to lean on and the gaps worth fixing first, each mapped to the SOC 2 and ISO 27001 controls an assessor would check. A directional starting point, not a formal audit. Free, ~3 minutes, no signup to see your score.
- Instant readiness score across every key control area
- A prioritised gap list your team can act on this week
- Benchmark your posture before you ever talk to an auditor
The check is built around SOC 2 and ISO 27001:2022. Free — no signup to see your score.
// Get started
Built for security practitioners.
Everything you need to run governance, risk, and compliance — included from day one, with hands-on onboarding to get your team live fast.
Straightforward Pricing
Core platform included from day one — clear tiers, no per-module upsells, no surprise add-ons.
Built With Practitioners
Shaped by working security teams, with a roadmap driven by real-world needs.
Dedicated Onboarding
We set up your first framework, import your controls, and train your team.
Questions we get asked
Including the ones with awkward answers. If something here is not clear, ask us directly.
What is Cyber Horizon Intelligence?
Cyber Horizon Intelligence is a UK governance, risk and compliance (GRC) platform for security and compliance teams. It automates evidence collection across 71 compliance frameworks, quantifies cyber risk in financial terms, and runs vendor risk, incident response and threat intelligence from one shared evidence trail. It is built and operated by Cyber Horizon Intelligence Ltd, registered in England and Wales, company number 17327222, and registered with the UK Information Commissioner's Office under number ZC237332.
Who is Cyber Horizon built for?
Companies of roughly 30 to 250 people that have a compliance obligation but no dedicated compliance department — typically B2B SaaS, fintech, healthtech and managed service providers in the UK and EU. The common trigger is a customer asking for ISO 27001 or SOC 2, or a regulation such as DORA or NIS2 coming into scope, before anyone has been hired to own it.
Which compliance frameworks does Cyber Horizon support?
71 frameworks, including ISO 27001, SOC 2, GDPR, UK GDPR, NIS2, DORA, Cyber Essentials, NIST CSF, HIPAA, PCI DSS, CMMC and the EU AI Act. They are not all at the same depth and we would rather say so: 10 are verified control-by-control against the published standard, and the remaining 61 are curated crosswalk catalogues — control sets mapped from those verified libraries, useful for gap analysis and evidence reuse but not independently reconciled clause by clause. Every framework is labelled with its status inside the product.
How much does Cyber Horizon cost?
Prices are published rather than quoted. Start is £600 a month or £6,000 a year for 5 users; Grow is £1,500 a month or £15,000 a year for 15 users; Scale is £3,000 a month or £30,000 a year for 50 users. Enterprise is custom-priced with the seat count agreed in the Order Form. Paying annually is twelve months for the price of ten, a saving of 17%.
Does Cyber Horizon charge extra for additional frameworks?
No. Every module, every framework and every integration is included on every plan, with no per-framework, per-integration or per-module fee. Adding a framework in month six does not change the invoice. Plans differ by the number of included seats, by service level, and by single sign-on: MFA on every plan; SSO/SAML on Scale and Enterprise. This matters because the usual industry model charges per framework, so a team that buys ISO 27001 and is later asked for SOC 2 and then DORA pays three times.
Is Cyber Horizon Intelligence ISO 27001 certified?
No, and it is worth being exact about this. Cyber Horizon's own controls are aligned to ISO 27001 and certification is targeted for Q3 2027, but the company does not hold the certificate today. It is not SOC 2 certified and not Cyber Essentials certified either. The platform helps customers achieve those standards; it does not currently hold them. The full position, including what has and has not been independently tested, is published in the Trust Centre.
Where is customer data stored?
Customer Data is stored in the European Union by default, on Supabase in eu-west-1 (Ireland), on every plan. Some processing takes place outside the EU — application hosting and serverless compute, identity management, AI features, transactional email, malware scanning of uploaded files, and encrypted off-site backups. Every sub-processor, the service it provides, the region it processes in and the transfer mechanism relied on are listed publicly. Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request, with no tier condition attached.
What does Cyber Horizon integrate with?
23 integrations, covering the systems that already hold the evidence: Amazon Web Services, Microsoft Azure and Google Cloud; Okta, Microsoft Entra ID and Google Workspace for identity; CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Jamf Pro and Microsoft Intune for endpoints; Tenable.io, Qualys VM and Snyk for vulnerabilities; GitHub, GitLab and Jira for code and tickets; BambooHR, HiBob and KnowBe4 for people; Cloudflare and Slack. Integrations are included on every plan rather than sold as an add-on.
What support and uptime commitments come with it?
The published Service Level Agreement targets 99.5% monthly uptime with service credits. Critical (S1) response targets are 8 business hours on Start, 4 on Grow and 2 on Scale, with custom targets on Enterprise. These are measured against UK business hours (09:00–17:00 UK time, Monday to Friday); there is no staffed round-the-clock desk, and the SLA says so — outside business hours, S1 incidents are monitored on a best-efforts basis via an alerting channel.
How do I find out where my compliance programme currently stands?
There is a free readiness check on the site: 20 questions, about three minutes, no signup wall and no call required. It scores your current position against SOC 2 and ISO 27001, shows which controls you would presently fail, and maps each gap to the clause it belongs to.
More detail in the pricing FAQ, the Trust Centre and our published legal documents.
Ready to transform your
GRC programme?
Replace manual spreadsheets with automated compliance, quantified risk, and live security intelligence.
Plans from £600/month, or £6,000/year — every framework, module and integration included on every plan.