Accepting early customers

Prove risk reduction.

Your portfolio's exposure moved $0.6M this quarter. Your companies retired $2.6M of it. Testify's Board shows the difference (verified control closes on one side, model changes on the other) across every portfolio company, inside your own deployment.

Earned ≠ re-estimated
Verified closes and model changes never share a number
Portfolio-native
Parent-child hierarchy from the ground up
Your deployment
Docker container, your cloud, local AI
FIG.01 Exposure bridge Modeled

What moved projected annual loss this quarter, and how much of it was earned rather than re-estimated.

PROJECTED ANNUAL LOSS $12.0M Opening −$2.6M Earned +$0.6M Re-estimated +$1.4M Portfolio changed $11.4M Closing
Live position 2 incidents in window

Risk trajectory · Three readings, deliberately not merged into one.

Proven Counted+17controls verifiedEvidence landed, procedure passed
Modeled Modeled−$0.6Mprojected annual lossMonthly snapshots, your loss model
Observed Counted2incidentsYour incident register, the ground truth

Illustrative data. A fictional seven-company portfolio, not customer figures.

01 The problem

Dollar figures are easy. Defending them is not.

  1. 01

    Dollar figures nobody can defend

    A risk number that drops because the model changed looks exactly like a risk number that drops because a control got fixed. Boards and LPs can't tell the difference, and most platforms don't show it.

  2. 02

    Questionnaire snapshots

    An annual questionnaire captures what a company said once. Posture degrades between reviews, and nobody knows until an incident forces discovery.

  3. 03

    No accountability trail

    When a breach hits, there's no record of whether known gaps were communicated, tracked, or addressed. Liability is undefined.

▸ Read the ledger → Two companies sit below their calibrated expectation: a combined $5.3M in annualized loss expectancy the fund cannot currently see.

02 The Board

Six screens a board can interrogate.

The exposure bridge above is screen one. The other five answer the questions that follow it: where the weakness is, whether the tools work, what the model assumes, what a budget buys, and whether the work landed.

FIG.02

Portfolio Exposure Map

Modeled

Is this weakness everywhere, or one company's problem?

Every company against every control capability, shaded by dollars at risk. Flip from what companies claim to what campaigns verified, and see which gaps are portfolio problems, clusters, or one company's issue.

CompanyMFAEDRBackup recoveryVuln. mgmtLogging & detectionIncident response
Quill Media
Atlas Cloud
Vertex Payments
Meridian Health
Northwind Logistics
Cedar Retail
Keystone FreightBaseline in progress
Portfolio problem

Darker = more dollars at risk. Within this firm only.

Illustrative data. Board screens shown with a fictional seven-company portfolio.

03 The bake-off

The five demos to ask any vendor for

PE security leaders are running the same bake-off. Here is what each ask usually gets, and what Testify shows instead.

The askWhat you'll usually be shownWhat Testify shows
1Onboard a new acquisition in days, with imperfect data Questionnaires and a months-long baseline Local-AI import of the assessments, policies and audit findings a company already has. Keystone Freight is mid-baseline in the ledger. What feeds the Board →
2Score a $15M software company and a $400M industrial on one scale One score for everyone, or reports you can't compare Calibrated expectations per company, rolled onto one normalized scale. Why the number holds up →
3A one-page fund heat map and an LP appendix, without a week of analyst work Consultant-assembled decks The Executive Brief and the Portfolio Exposure Map, generated from the live register. The Board →
4Residual risk after the top remediations, in dollars A dollar figure that moves whenever the model moves Earned versus re-estimated in the exposure bridge, and a capital frontier showing what each dollar retires. The bridge → Capital Allocation →
5Who owns the evidence, what happens at exit, and whose cloud it lives in Vendor SaaS; the evidence lives with the vendor Your deployment, local AI and a portable exit record, from a vendor with no private-equity investors or owners. Data sovereignty → Why Cyber Flag →

Eight questions to ask any vendor →

FIG.02 Board inputs 8 / 8 Online
01

Live Control State

Active
Register · Continuous

Security posture that updates itself. Assessments, incidents, and remediations feed a continuously current register: no stale dashboards, no manual sync.

7 / 7 entities in the register
02

Risk-Adjusted Expectations

Active
Calibration · CME tiers 1–4

A 20-person SaaS startup and a 20,000-person logistics company aren't the same. Maturity expectations automatically calibrate to each company's size, complexity, and data sensitivity.

Expectations auto-calibrated
03

AI-Powered Onboarding

Active
Ingest · Local model

Import existing assessments, policies, and audit findings. AI extracts structured maturity data in hours, not the weeks of interviews traditional onboarding requires. Runs locally. Your data never leaves.

< 1 day per company
04

Verification Campaigns

Active
Evidence · Score-gated

Don't take their word for it. Evidence-based, score-gated campaigns verify that controls operate as designed, targeted to each company's actual technology stack and reviewed against the evidence. When a tool fails, an Effectiveness Case records the hypothesis and derives the outcome at review, backed by a versioned failure-pattern library your firm can extend.

Controls verified, not asserted
05

Attack Surface Intelligence

Active
OSINT · External

See what adversaries see. Monitoring of each company's attested domain footprint (credential leaks, certificate issues, exposed services), correlated across the portfolio and turned into attack paths through open control gaps.

Monitored only with that company's consent
06

AI Risk Governance

Active
SAFE² · EU AI Act / NIST / ISO 42001

Structured AI hygiene assessments across every portfolio company, anchored to SAFE² with crosswalks to the EU AI Act, NIST AI RMF, and ISO 42001. Measure AI risk the same way you measure everything else.

Crosswalked frameworks
07

Built to Extend

Active
Overlay SDK · MCP

Overlay SDK and MCP server. Define custom frameworks, gates, verdicts and failure patterns with no forking and no code changes, and build a scored top-level framework in the authoring wizard. Jira, ServiceNow, Slack, and Teams included.

Jira · ServiceNow · Slack · Teams
08

Board & LP Reporting

Active
Reporting · Anonymizable

Six Board screens, from the exposure bridge to the campaign rollup, plus configurable, anonymizable board briefings and LP portfolio reports. The same numbers, framed for whoever is asking.

Hours, not weeks

04 What feeds the Board

Eight inputs, one continuously current register

Everything on the Board is computed from the same register. These are the modules that keep it current, architected from day one for the parent-child relationships and calibrated expectations PE oversight requires.

Eight inputs · one continuously current register

05 How evidence is gathered

Your framework. Questions that get evidence.

Most portfolio platforms score every company against one framework, usually NIST CSF. Testify scores against CIS Controls v8, NIST CSF 2.0, or a framework you write. Its local AI helps every assessor give an answer that holds up.

Your framework

Score against the framework you run

  1. Basics
  2. Controls
  3. Questions
  4. Review & Publish

CIS Controls v8, NIST CSF 2.0, or your own framework, built and published in the authoring wizard.

Questions that get evidence

Ask for proof, not a flattering yes

Before

Do you require MFA for externally exposed applications?

After

When did you last review MFA exceptions for your external apps, and where is that list kept?

Illustrative of what the local model drafts.

AI coach

A coach, not a certifier

Answer

We use MFA everywhere.

Coach

Names no system or exception list. Which apps are covered, and what is excluded?

Illustrative example. The coach suggests; the assessor decides.

06 Why the earned number holds up

One portfolio. One scale. Every company on it.

Dollars only mean something if the controls behind them are measured the same way everywhere. A 20-person SaaS startup and a 20,000-person logistics company are not the same, so Testify holds each to a calibrated expectation, then rolls every company onto one normalized maturity scale. Select a company to see what's underneath the number.

FIG.05Live portfolio ledgerOverview
Company Normalized maturity Status

Illustrative data. Figures shown are sample portfolio companies, not customers. CME tier reflects organizational complexity; the method is transparent to customers inside the platform.

07 External exposure

Local AI · No AI egress

See the way in before an attacker does.

Ask about any company and the assistant answers from the evidence already in your register, on a local model inside your own deployment. No API calls, no third-party provider.

  1. 01

    Observed entry

    An internet-facing service found by your attack-surface connectors (Shodan, GreyNoise, HIBP and crt.sh, stored in a self-hosted OpenCTI) becomes the technique an attacker would use: T1190, T1133 or T1078. Connector lookups send only a company's attested domains or IPs to those services, and only with that company's consent; findings, correlation and all AI stay inside your deployment.

  2. 02

    Inferred chain

    Open control gaps, mapped from MITRE ATT&CK to CIS Controls, carry that entry through to Impact or Exfiltration.

  3. 03

    Priced blast radius

    The path's loss range comes from your own loss model.

  4. 04

    Monitored footprint

    Only domains each company has attested, monitored only with that company's consent. A company that has never been scanned is shown as never scanned.

Observed or inferred, stated on every link. Confidence is never rounded into one number. An empty scan is not a clean company.

How attack paths are built →

Testify · Assistant Local model

Illustrative: local model output on a sample portfolio company.

08 Data sovereignty

Your portfolio data never leaves your infrastructure

Testify deploys as a Docker container into your own cloud or on-prem environment. No SaaS multi-tenancy. No vendor with access to your portfolio company data. No third-party AI providers.

Deployment targets AWSAzureGCPOn-prem
Deployment

Your cloud, your rules

AWS, Azure, GCP, or on-prem: same container, same platform. Deploy where your data governance policy requires.

Local inference

Local AI inference

All AI features (document import, assessment coaching, natural language queries) run on a local model inside your deployment. Zero data transmitted to external providers.

Evidence

Auditable by design

Every control state change logged with source, timestamp, and actor. Board-ready reports and M&A due diligence packages generated in hours, not weeks.

09 How it works

The continuous improvement cycle

Closed loop · running today

  1. 1Assess
  2. 2Monitor
  3. 3Detect & Correlate
  4. 4Remediate & Verify
  5. 5Validate

Every incident drives a remediation. Every remediation improves a control. Every improvement is verified against evidence and recorded. That closed loop is how the platform operates today, not a roadmap. Validation is the longer arc it builds toward: fewer incidents, lower premiums, and defensible valuations that prove the program is working over time.

10 Who it's for

Built for the people who own the risk

Portfolio Directors & Operating Partners

Portfolio-level oversight

  • Compare security maturity across all portfolio companies with calibrated expectations
  • Identify systemic gaps before they become fund-level risks
  • Generate board-ready reports that demonstrate diligence
  • Track remediation commitments with built-in accountability
Portfolio Company CISOs

Operational security command

  • Run assessments against CIS Controls v8, NIST CSF 2.0, or your own framework
  • Manage incidents with MITRE ATT&CK mapping and automated control degradation
  • Verify control effectiveness with evidence-based campaigns
  • Communicate risk posture to the parent firm through shared dashboards

11 Who's behind it

Advisory-grade methodology, distilled into software

Testify isn't a feature list someone assembled. It's a cybersecurity methodology refined across years of enterprise advisory work (the kind of portfolio assessment large consultancies build over years), systematized so it runs continuously, at portfolio scale, for a fraction of the cost. Founder-led, built by practitioners.

ProvenanceFounder-ledPractitioner-builtNo PE investors
The methodology

Backed by results

The scoring model, the four maturity dimensions, the calibrated CME tiers: built on how the world's best-resourced security programs actually operate. These are the practices proven where budgets are largest and the stakes are highest, now running across every company in your portfolio.

The engineering

Built to a higher bar

Portfolio-native architecture, a private locally-hosted AI model, and an Overlay SDK for custom frameworks. No SaaS multi-tenancy, no third-party AI, no data leaving your environment. Engineered for the rooms that ask hard questions.

The ownership

Independent by design

Cyber Flag has no private-equity investors or owners. The platform that governs your portfolio doesn't answer to a sponsor you compete with for deals. And because Testify is self-hosted, your portfolio data never sits with us either.

The posture

Early by design

Cyber Flag is taking a deliberately small number of founding customers. You work directly with the team who built the methodology and the platform, not a support queue. First movers shape the roadmap.

12 Questions, answered

Common questions about Testify

Q.01

What is Testify?

Testify, by Cyber Flag, is a cyber GRC platform purpose-built for private equity firms to govern cybersecurity across every portfolio company. It maintains a continuously updated, evidence-backed security posture for each company, prices that posture in dollars, and runs all AI locally so portfolio data never leaves your environment.

Q.02

How is Testify different from compliance tools like Vanta or Drata?

Vanta and Drata help a single company earn a certification such as SOC 2; Testify governs cybersecurity maturity across an entire portfolio for the investor. A portfolio company can be SOC 2 compliant and still have controls that are not automated or enforced. Firms often run a compliance tool inside individual companies and use Testify on top to measure, compare, and prove control efficacy across the whole portfolio.

Q.03

Does my portfolio data ever leave my environment?

No. Testify deploys as a Docker container into your own cloud or on-prem environment, and all AI inference runs locally on open-weight models. There is no SaaS multi-tenancy and no third-party AI provider. Portfolio data never leaves your infrastructure.

Q.04

How does Testify compare security across companies of very different sizes?

Testify calibrates maturity expectations to each company's size, complexity, and data sensitivity, then rolls every company onto one normalized 0–100 maturity scale. A 20-person SaaS startup and a 20,000-person logistics company are held to appropriate expectations and still compared on a common baseline.

Q.05

What frameworks does Testify support?

Testify assesses against CIS Controls v8 at the safeguard level and NIST CSF 2.0, with a NIST-to-CIS crosswalk, and you can build and score your own framework in the authoring wizard. AI risk is covered through an AI hygiene assessment based on SAFE² with crosswalks to the EU AI Act, NIST AI RMF, ISO 42001, and OWASP-LLM. Testify recommends assessment questions from your incident history, its local AI drafts them to ask for evidence, and an AI coach checks answers against the control's requirements when the assessor asks.

Q.06

What does Testify show a PE board?

Six Board screens computed from the live register: an Executive Brief whose exposure bridge separates risk reduction earned by verified control closes from model re-estimates and portfolio changes; a Portfolio Exposure Map of claimed versus verified coverage; Spend Efficacy; a Loss Model with every assumption visible; Capital Allocation ranked by what each dollar retires; and a Campaign Rollup that counts the exposure verified work retired.

Q.07

How is Testify different from CRQ tools that show dollar exposure?

Most cyber risk quantification tools produce a dollar figure. Testify ties that figure to verified control state and shows why it moved: earned by verified closes, re-estimated because an assumption changed, or changed because the portfolio changed. The loss model is visible to customers and theirs to adjust.

Q.08

Is Cyber Flag owned or funded by private equity?

No. Cyber Flag has no private-equity investors or owners, so the vendor behind your portfolio governance platform is not backed by a sponsor you compete with. Testify is also self-hosted: portfolio data stays in your deployment.

More in the full FAQ, or start with What is Testify and how it compares.

13 Get started

See it live

Testify is accepting early customers. Portfolio Directors and Fund Operating Partners get priority access to a guided walkthrough.

Request a Demo Or reach us directly at [email protected]

What you'll see

  • Exposure bridge · earned vs re-estimated
  • Six Board screens · one register
  • Attack paths · observed vs inferred
  • Live portfolio ledger · 7 entities
  • Local AI · zero data egress