Zero-custody · Provenance-sealed

Your scanner knows the truth. Your auditor won’t take JSON.

Viwago turns the security scan you already run into sealed, multi-framework audit evidence — ISO 27001, SOC 2, NIST 800-53, HIPAA, PCI DSS — in minutes. Every number carries the SHA-256 of your exact file, verifiable by anyone. No agents, no IAM roles, no credentials: we never touch your cloud.

Free to sign up. No card. No cloud access — your credentials never leave your machine.

The problem: the evidence gap

Your cloud already gets scanned — Powerpipe, Prowler, Security Hub. The truth exists, sitting in a JSON file. But auditors, boards, and enterprise customers don’t accept JSON. They accept framework-shaped evidence they can defend.

Today there are two ways across, and both are broken. The spreadsheet: weeks of manual translation, stale on arrival, and unprovable — “trust me” isn’t evidence. The GRC suite: $15k–$100k a year, agents in your environment, admin credentials to your cloud, and months of security review before you can even start.

Viwago is the third way: the scan you already ran, translated into many frameworks at once, each number sealed to the exact file that produced it. The translation, without the custody.

How it works — the actual product

Real screens from the live application, running on sample data. Nothing staged, nothing mocked.

1

Drop the scan you already have

Run Powerpipe with your own credentials, on your own machine — then drop the JSON here. No agents, no IAM roles, no security review to schedule. The moment it lands, Viwago computes the SHA-256 of your exact file.

Viwago import screen: 'Bring the scan you already trust' — a drag-and-drop zone for scan JSON, with 'never touches your cloud credentials', 'zero agents deployed' and 'your data stays yours' badges, plus a try-with-sample-data option.
2

One scan lights up every framework

The translation engine maps your CIS results across ISO 27001, SOC 2, NIST 800-53, HIPAA and PCI DSS — stamped with the provenance seal and the pinned mapping-profile version it was scored under. Where a framework has no data, you see an honest dash — never a fake 0%.

Viwago compliance posture dashboard: overall score, the record-of-provenance panel showing the scan's SHA-256, ingestion time, source and mapping profile, and a cross-framework posture list with per-framework passing bars for CIS, ISO 27001, SOC 2, NIST 800-53, HIPAA and PCI DSS.
3

Export evidence your auditor accepts

Board-ready PDF, CSV for your workflow, NIST-standard OSCAL for their tooling, JSON for your pipeline. Every artifact embeds a recomputable provenance seal — generated from your scan and your attestations, nothing else.

Viwago reports screen: choose CSV, PDF, OSCAL or JSON format and a report type, with a banner stating every export carries a provenance seal that anyone can verify at viwago.com/verify.
4

Anyone can verify it. Nobody has to trust us.

Your auditor drops the export on our public verify page and the seal recomputes in their own browser — no account, no upload, no meeting about how the tool works. The report proves itself.

Viwago public seal-verification page: 'Verify a Viwago seal' — drop a Viwago JSON export and the provenance seal is recomputed locally in the browser; the file never leaves the device.
Create your free account

Sixty seconds to sign up — then drop your scan, or try the sample data first.

What Viwago does today

Everything below is in the product now. We don’t list what we haven’t built.

Zero-custody ingestion

You run your own scan with your own tools and credentials. Viwago only ever reads the output file. No agents, no IAM roles, no API keys — we never touch your cloud.

Cross-framework translation

One CIS scan, mapped across ISO 27001, SOC 2, NIST 800-53, HIPAA and PCI DSS — every mapping version-pinned and source-labeled. Stop re-doing the same control mapping by hand for every standard.

Provenance & chain-of-custody

Every score states where it came from (“based on your uploaded Powerpipe scan”). Export to OSCAL, the NIST machine-readable format auditors expect.

Manual attestation

Cover the controls a scanner can’t check — physical access, offboarding, policies — with evidence, and watch coverage climb toward complete.

Auditor-ready exports

Hand your auditor a real artifact: PDF for the board, CSV for your workflow, OSCAL for their tooling, JSON for your pipeline.

The evidence-to-audit layer, end to end

From a scan you run yourself to sealed, auditor-ready evidence — in five phases.

Viwago: The Evidence-to-Audit Layer — Phase 1: the sovereign scan run locally with zero-custody architecture; Phase 2: zero-liability ingestion with fail-closed tenant isolation; Phase 3: the translation engine mapping one CIS scan to NIST, ISO 27001, SOC 2, HIPAA and PCI DSS with honest-asymmetry reporting; Phase 4: cryptographic provenance via SHA-256 seals and versioned mapping profiles; Phase 5: auditor-ready multi-format exports with tier comparison.

Built zero-custody, secure by construction

We never deploy an agent, assume an IAM role, or hold an API key — so there’s no cloud access for a vendor review to scrutinize. The scan results you upload are encrypted in transit and at rest, and strictly tenant-isolated: access is derived only from a verified identity token, fail-closed by design.

SOC 2 in progress. We publish what is true and nothing that isn’t.

Pricing

Starter
$99/mo
  • CIS + ISO 27001 mapping
  • 5 scan uploads / month
  • PDF / CSV / OSCAL / JSON exports
Professional
$299/mo
  • All frameworks (SOC 2, NIST, HIPAA, PCI, CCPA)
  • 100 scan uploads / month
  • Manual attestation + full control detail

Framework coverage expands as our control mapping grows.

We don’t scan your systems. We make your scans audit-proof.

Create a free account, drop the scan you already have, and walk away with sealed, multi-framework evidence your auditor can verify without a meeting.

Create your free account

No card. No credentials. Your first sealed posture in minutes.