Before you let an assessment tool near a regulated environment, you need to know what it can reach, who can see the results, and what happens to the data afterwards. This page answers those three questions — it is written for the security questionnaire, not the sales deck.
CloudTwyst's security model rests on four principles: engagement-scoped access, transparent audit, a data lifecycle that ends in deletion, and a connector that never gives us a way in.
CloudTwyst Security Assess evaluates your cloud environment against four frameworks, producing a per-control gap analysis, a posture score, and a prioritised remediation backlog for each.
| Framework | Control scope | Output | Status |
|---|---|---|---|
| NIS2 — EU Network & Information Security | Article 21 controls mapped and scored | Posture score, gap count, remediation backlog | Scored |
| ISO 27001 — Information Security Management | ISO 27001:2022 Annex A control evaluation | Posture score, gap count, remediation backlog | Scored |
| DORA — Digital Operational Resilience Act | ICT risk management and resilience controls | Posture score, gap count, remediation backlog | Scored |
| GDPR — General Data Protection Regulation | Technical safeguard assessment | Posture score, gap count, remediation backlog | Scored |