SAK Get your exposure reportFree report
SAK · Technologies · Services · Exposure

Know your exposure.
Prove your compliance.

Two questions decide your security posture, and they are the same question twice: what can an attacker reach from outside, and what can you evidence to a regulator. SAK Exposure finds what you are exposing; every finding is filed automatically as control evidence in GRCorb; SAK Services fixes what the evidence says is broken. One loop, not three tools.

No agent to install · no access required · 6-page report in 5 business days

That is what turns a scan into compliance: an exposure we find is not just a ticket, it is evidence — mapped to the obligations that actually bind you, in whichever regime you answer to.

Mapped natively in GRCorbNCA ECCSAMA CSFPDPLAramco CCC (SACS-002)NDMOISO 27001:2022PCI DSS v4.0.1GDPREssential EightSOCI Act 2018Privacy Act & NDBAPRA CPS 234APRA CPS 230ISM / IRAPSOC 2
One umbrella, three offerings

Everything under SAK works from the same picture of your organisation

Most firms resell someone else's tooling. SAK builds its own — and every offering reads and writes the same asset graph and evidence store, so what one finds, the others act on.

The assurance loop

From static compliance to continuous assurance

A point-in-time audit tells you what was true on one Tuesday in March. This runs every day — and each step hands evidence to the next.

  1. 01

    Discover

    Every internet-facing asset, certificate, subdomain and exposed service — found, not declared.

    SAK Exposure
  2. 02

    Assess

    Exposures scored against live threat intelligence and what's actually being exploited.

    SAK Exposure
  3. 03

    Evidence

    Findings and configuration state collected as control evidence, mapped to obligations.

    SAK Technologies
  4. 04

    Remediate

    Owners, due dates and build instructions — how to fix the control, not just that it failed.

    SAK Technologies
  5. 05

    Assure

    Controls re-verified continuously. Drift raises an exception the day it happens.

    SAK Technologies
  6. 06

    Report

    Board packs and auditor workspaces generated from the same evidence, not rewritten.

    SAK Technologies
Regulatory coverage

Built for your regulator, not translated for it

Your obligations are mapped natively in GRCorb — NCA ECC, SAMA CSF and PDPL in the Gulf, Essential Eight, the ISM, SOCI and the Privacy Act in Australia, plus ISO 27001, SOC 2 and PCI DSS globally — with the evidence each assessor actually asks for.

FrameworkWho it bindsObligations mappedPlatform coverage
NCA ECCAll Saudi government entities and critical national infrastructureECC-2:2024 · 4 domains · 108 controlsFull
SAMA Cyber Security FrameworkBanks, insurers and financial institutions regulated by SAMA4 domains · maturity levels 0–5Full
PDPLAny entity processing personal data of individuals in KSAConsent · transfer · DPOFull
Aramco CCC (SACS-002)Third parties connecting to or serving Saudi AramcoSupplier certificationIn build
NDMO data standardsEntities handling national data under SDAIA governance15 domainsIn build
ISO/IEC 27001:2022Voluntary — commonly contractually required93 controlsFull
Essential Eight (ML1–ML3)Federal agencies mandatory; strongly recommended for all8 strategies · 3 levelsFull
ISM / IRAPSuppliers handling Australian Government data1,100+ controlsFull
SOCI Act 2018Designated critical infrastructure operatorsRMP + reportingFull
Privacy Act 1988 & NDBTurnover above AU$3m, all health providers13 APPsFull
APRA CPS 234 / CPS 230Banks, insurers, superannuation fundsInfo security + op riskIn build
ISO/IEC 27001:2022Voluntary — commonly contractually required93 controlsFull

Framework coverage is delivered through SAK Technologies. See what each framework asks for →

Delivery network

Accredited delivery partners

We work with accredited specialist firms — ISO certification bodies, offensive security teams and training providers — who deliver alongside our platforms. That is how a product company ships enterprise engagements without pretending to be a body shop, and it means each engagement is staffed by the firm best suited to it, not the only one we have.

Certification

ISO & compliance audit

ISO 27001, 22301, 9001, 27017/27018, PCI DSS, SOC 1/2/3 and SAMA CSF certification and audit practice.

Feeds GRCorb audit workspace
Offensive

Red team & testing

Black, white and grey box penetration testing, malware analysis, compromise assessment, secure code review.

Feeds SAK Surface
Education

Accredited training

Internationally accredited IT security training and certification courses for client teams, run by partner training faculties.

Records filed as evidence
Start here

Get your free external exposure report

Give us a domain. SAK Surface maps every internet-facing asset, expiring certificate, exposed service and lookalike domain we can see from the outside. You get a six-page report in five business days. No agent, no access, no obligation.

Request the report

English & Arabic reporting · partner-delivered execution