Skip to content
Tenvara is coming soon. Get early access

Compliance and hardening

Compliance your customers can show an auditor

Run ISO 27001, ISO 9001, UK GDPR and Cyber Essentials programmes for your customers from the data Tenvara already has, harden their devices against baselines with rollback, and show them how ready they are to use AI safely. Evidence collects itself, so the audit is not a scramble.

A management system programme with readiness for Cyber Essentials, evidence and what to do next

One control library

ISO 27001, ISO 9001, UK GDPR and Cyber Essentials mapped onto common controls, so one piece of evidence counts everywhere it applies.

Evidence that keeps itself

Checks from devices, Microsoft 365 and backups feed hashed evidence and daily snapshots, ready for the auditor.

Hardening with a safety net

424 settings in plain words, audited first, enforced in rings with approvals and rolled back in one click.

Ready for AI

Oversharing, sensitive files, unapproved AI tools and Copilot licences, scored per customer with fixes you can undo.

Management systems without the spreadsheets

Start a programme for a customer and Tenvara shows readiness per framework: controls in place, evidence that is fresh, documents approved, risks treated and nonconformities on time. Policy documents live under document control with your master library, customer approvers and acknowledgement. The risk register and Statement of Applicability are versioned and export to PDF and Excel.

  • Template packs for ISO 27001, ISO 9001, Cyber Essentials and UK GDPR
  • Internal audits, management reviews, objectives and registers
  • Auditors get their own access and a signed evidence pack

Device hardening you can undo

Pick a baseline for Windows workstations, servers, domain controllers, macOS or Cyber Essentials, or build your own from the setting library. Tenvara audits first and tells you what enforcing would change, then enforces in a pilot ring and a broad ring inside the maintenance window, with approvals. It never fights Group Policy, can push a baseline to Intune, and tells you who changed a setting when it drifts.

  • Exceptions with a reason, an expiry and the customer's approval
  • Rollback per setting, device or run
  • Drift alerts, monthly report sections and the portal's Device security page
Hardening compliance for a customer by baseline, with settings managed elsewhere and enforcement mode

Is this customer ready for AI?

Switch on AI readiness for a Microsoft 365 tenant and Tenvara scores the customer across data exposure, sensitive content, Copilot licences, other AI tools and people and policy. It finds files shared with anyone, guests with too much reach and sensitive data in widely shared places, keeping only hashes of what it finds. Fixes go through the customer's approver and can be undone, and the branded report makes a good conversation starter.

  • ChatGPT, Claude and 160 other AI tools spotted on devices and in sign-ins
  • An AI acceptable use policy with acknowledgement
  • A remediation project and a catalogue item to sell the assessment
The AI readiness score for a customer with section scores and the fixes to do first

In the knowledge base

See exactly how it works

Management systems overview What a programme is, how the control library, documents, risks, evidence and audits fit together, and how readiness is worked out. Frameworks and the control library The shipped frameworks, the 321 common controls they map to, building your own framework with versions, and the template packs. Policy documents under control Keep policies and procedures under document control, from a master library you adopt for customers, with customer approval, versions and staff acknowledgement. Risk register and Statement of Applicability Score risks on the customer's matrix, treat them, get them accepted by their owner, and generate, approve and export the Statement of Applicability. Auditors and the portal What the customer's people see and do in the portal's Compliance section, read-only access for an external auditor with an emailed code, and evidence packs. Device hardening overview What device hardening does in Tenvara, how audit, enforcement, rollback and drift fit together, and where to find it. Enforcing in rings and rolling back Start an enforcement run, get it approved, let the pilot ring prove it inside maintenance windows, then roll back a run, a device or a single setting. Drift and reporting Drift alerts that name who changed a setting, keep enforced to put it back, fights between tools, and hardening in the overview, Home, the monthly report and the customer portal. AI readiness overview and the score What an AI readiness assessment looks at, how the score and its sections are worked out, the top fixes and the all-customers view. Data exposure Find what is shared too widely in SharePoint, OneDrive and Teams, read the findings, and fix links, grants and guests through the customer's approver. Other AI tools See which AI apps, browser extensions and consents a customer's staff already use, what each does with data, and sanction, block or revoke them.

Tenvara is coming soon.

We're inviting MSPs to the beta in small groups. Apply to join, or get launch updates by email and hear first when pricing is announced.