Live Control State
ActiveSecurity posture that updates itself. Assessments, incidents, and remediations feed a continuously current register: no stale dashboards, no manual sync.
Your portfolio's exposure moved $0.6M this quarter. Your companies retired $2.6M of it. Testify's Board shows the difference (verified control closes on one side, model changes on the other) across every portfolio company, inside your own deployment.
What moved projected annual loss this quarter, and how much of it was earned rather than re-estimated.
Risk trajectory · Three readings, deliberately not merged into one.
Illustrative data. A fictional seven-company portfolio, not customer figures.
01 The problem
A risk number that drops because the model changed looks exactly like a risk number that drops because a control got fixed. Boards and LPs can't tell the difference, and most platforms don't show it.
An annual questionnaire captures what a company said once. Posture degrades between reviews, and nobody knows until an incident forces discovery.
When a breach hits, there's no record of whether known gaps were communicated, tracked, or addressed. Liability is undefined.
▸ Read the ledger → Two companies sit below their calibrated expectation: a combined $5.3M in annualized loss expectancy the fund cannot currently see.
02 The Board
The exposure bridge above is screen one. The other five answer the questions that follow it: where the weakness is, whether the tools work, what the model assumes, what a budget buys, and whether the work landed.
Is this weakness everywhere, or one company's problem?
Every company against every control capability, shaded by dollars at risk. Flip from what companies claim to what campaigns verified, and see which gaps are portfolio problems, clusters, or one company's issue.
Darker = more dollars at risk. Within this firm only.
Your companies bought the tools. Are they working?
Spend against verified coverage, product by product or grouped by capability. Price comparisons stay inside your firm.
| Product class | Deployed (claimed) | Verified working |
|---|---|---|
| EDR | 7 companies | 5 |
| MFA | 7 companies | 6 |
| Backup | 7 companies | restore verified at 3 |
| Email security | 6 companies | 4 |
| Capability | Products deployed | Companies failing |
|---|---|---|
| Endpoint visibility & response | 2 EDR products | 2 |
| Backup & recoverability | 3 backup products | 4 |
| Phishing-resistant authentication | 2 MFA products | 1 |
When a tool fails: open an Effectiveness Case
Cases live on the Technology tab. Sibling companies appear as counts, and Testify never names them to each other. Testify contacts no vendor; the CISO takes an escalation pack into their own conversation.
The method is the product.
Every input is visible and every assumption is yours to change. This quarter the firm raised its ransomware frequency assumption, and that one change is the +$0.6M re-estimate in the bridge, kept apart from anything earned.
What moves the number most
Shown in general terms. The full method is transparent to customers inside the platform.
Every gap priced, ranked by what each dollar retires.
Drag the budget. The frontier shows how much projected annual loss the best-ranked gaps retire for that spend. $1.9M closes every priced gap and retires $5.9M, a 3.1× return. The remaining $5.5M is residual risk.
Did it work? Answered in dollars.
Campaigns go out to companies, evidence comes back, procedures pass, and the exposure those verified closes retire is counted. Regressions are counted too.
Modeled: $2.9M retired by verified closes, less $0.3M from verified regressions = the $2.6M earned in the bridge.
Illustrative data. Board screens shown with a fictional seven-company portfolio.
03 The bake-off
PE security leaders are running the same bake-off. Here is what each ask usually gets, and what Testify shows instead.
| The ask | What you'll usually be shown | What Testify shows |
|---|---|---|
| 1Onboard a new acquisition in days, with imperfect data | Questionnaires and a months-long baseline | Local-AI import of the assessments, policies and audit findings a company already has. Keystone Freight is mid-baseline in the ledger. What feeds the Board → |
| 2Score a $15M software company and a $400M industrial on one scale | One score for everyone, or reports you can't compare | Calibrated expectations per company, rolled onto one normalized scale. Why the number holds up → |
| 3A one-page fund heat map and an LP appendix, without a week of analyst work | Consultant-assembled decks | The Executive Brief and the Portfolio Exposure Map, generated from the live register. The Board → |
| 4Residual risk after the top remediations, in dollars | A dollar figure that moves whenever the model moves | Earned versus re-estimated in the exposure bridge, and a capital frontier showing what each dollar retires. The bridge → Capital Allocation → |
| 5Who owns the evidence, what happens at exit, and whose cloud it lives in | Vendor SaaS; the evidence lives with the vendor | Your deployment, local AI and a portable exit record, from a vendor with no private-equity investors or owners. Data sovereignty → Why Cyber Flag → |
Security posture that updates itself. Assessments, incidents, and remediations feed a continuously current register: no stale dashboards, no manual sync.
A 20-person SaaS startup and a 20,000-person logistics company aren't the same. Maturity expectations automatically calibrate to each company's size, complexity, and data sensitivity.
Import existing assessments, policies, and audit findings. AI extracts structured maturity data in hours, not the weeks of interviews traditional onboarding requires. Runs locally. Your data never leaves.
Don't take their word for it. Evidence-based, score-gated campaigns verify that controls operate as designed, targeted to each company's actual technology stack and reviewed against the evidence. When a tool fails, an Effectiveness Case records the hypothesis and derives the outcome at review, backed by a versioned failure-pattern library your firm can extend.
See what adversaries see. Monitoring of each company's attested domain footprint (credential leaks, certificate issues, exposed services), correlated across the portfolio and turned into attack paths through open control gaps.
Structured AI hygiene assessments across every portfolio company, anchored to SAFE² with crosswalks to the EU AI Act, NIST AI RMF, and ISO 42001. Measure AI risk the same way you measure everything else.
Overlay SDK and MCP server. Define custom frameworks, gates, verdicts and failure patterns with no forking and no code changes, and build a scored top-level framework in the authoring wizard. Jira, ServiceNow, Slack, and Teams included.
Six Board screens, from the exposure bridge to the campaign rollup, plus configurable, anonymizable board briefings and LP portfolio reports. The same numbers, framed for whoever is asking.
04 What feeds the Board
Everything on the Board is computed from the same register. These are the modules that keep it current, architected from day one for the parent-child relationships and calibrated expectations PE oversight requires.
05 How evidence is gathered
Most portfolio platforms score every company against one framework, usually NIST CSF. Testify scores against CIS Controls v8, NIST CSF 2.0, or a framework you write. Its local AI helps every assessor give an answer that holds up.
CIS Controls v8, NIST CSF 2.0, or your own framework, built and published in the authoring wizard.
Do you require MFA for externally exposed applications?
When did you last review MFA exceptions for your external apps, and where is that list kept?
Illustrative of what the local model drafts.
We use MFA everywhere.
Names no system or exception list. Which apps are covered, and what is excluded?
Illustrative example. The coach suggests; the assessor decides.
06 Why the earned number holds up
Dollars only mean something if the controls behind them are measured the same way everywhere. A 20-person SaaS startup and a 20,000-person logistics company are not the same, so Testify holds each to a calibrated expectation, then rolls every company onto one normalized maturity scale. Select a company to see what's underneath the number.
Illustrative data. Figures shown are sample portfolio companies, not customers. CME tier reflects organizational complexity; the method is transparent to customers inside the platform.
07 External exposure
Ask about any company and the assistant answers from the evidence already in your register, on a local model inside your own deployment. No API calls, no third-party provider.
An internet-facing service found by your attack-surface connectors (Shodan, GreyNoise, HIBP and crt.sh, stored in a self-hosted OpenCTI) becomes the technique an attacker would use: T1190, T1133 or T1078. Connector lookups send only a company's attested domains or IPs to those services, and only with that company's consent; findings, correlation and all AI stay inside your deployment.
Open control gaps, mapped from MITRE ATT&CK to CIS Controls, carry that entry through to Impact or Exfiltration.
The path's loss range comes from your own loss model.
Only domains each company has attested, monitored only with that company's consent. A company that has never been scanned is shown as never scanned.
Observed or inferred, stated on every link. Confidence is never rounded into one number. An empty scan is not a clean company.
Illustrative: local model output on a sample portfolio company.
08 Data sovereignty
Testify deploys as a Docker container into your own cloud or on-prem environment. No SaaS multi-tenancy. No vendor with access to your portfolio company data. No third-party AI providers.
AWS, Azure, GCP, or on-prem: same container, same platform. Deploy where your data governance policy requires.
All AI features (document import, assessment coaching, natural language queries) run on a local model inside your deployment. Zero data transmitted to external providers.
Every control state change logged with source, timestamp, and actor. Board-ready reports and M&A due diligence packages generated in hours, not weeks.
09 How it works
Closed loop · running today
Every incident drives a remediation. Every remediation improves a control. Every improvement is verified against evidence and recorded. That closed loop is how the platform operates today, not a roadmap. Validation is the longer arc it builds toward: fewer incidents, lower premiums, and defensible valuations that prove the program is working over time.
10 Who it's for
11 Who's behind it
Testify isn't a feature list someone assembled. It's a cybersecurity methodology refined across years of enterprise advisory work (the kind of portfolio assessment large consultancies build over years), systematized so it runs continuously, at portfolio scale, for a fraction of the cost. Founder-led, built by practitioners.
The scoring model, the four maturity dimensions, the calibrated CME tiers: built on how the world's best-resourced security programs actually operate. These are the practices proven where budgets are largest and the stakes are highest, now running across every company in your portfolio.
Portfolio-native architecture, a private locally-hosted AI model, and an Overlay SDK for custom frameworks. No SaaS multi-tenancy, no third-party AI, no data leaving your environment. Engineered for the rooms that ask hard questions.
Cyber Flag has no private-equity investors or owners. The platform that governs your portfolio doesn't answer to a sponsor you compete with for deals. And because Testify is self-hosted, your portfolio data never sits with us either.
Cyber Flag is taking a deliberately small number of founding customers. You work directly with the team who built the methodology and the platform, not a support queue. First movers shape the roadmap.
12 Questions, answered
Testify, by Cyber Flag, is a cyber GRC platform purpose-built for private equity firms to govern cybersecurity across every portfolio company. It maintains a continuously updated, evidence-backed security posture for each company, prices that posture in dollars, and runs all AI locally so portfolio data never leaves your environment.
Vanta and Drata help a single company earn a certification such as SOC 2; Testify governs cybersecurity maturity across an entire portfolio for the investor. A portfolio company can be SOC 2 compliant and still have controls that are not automated or enforced. Firms often run a compliance tool inside individual companies and use Testify on top to measure, compare, and prove control efficacy across the whole portfolio.
No. Testify deploys as a Docker container into your own cloud or on-prem environment, and all AI inference runs locally on open-weight models. There is no SaaS multi-tenancy and no third-party AI provider. Portfolio data never leaves your infrastructure.
Testify calibrates maturity expectations to each company's size, complexity, and data sensitivity, then rolls every company onto one normalized 0–100 maturity scale. A 20-person SaaS startup and a 20,000-person logistics company are held to appropriate expectations and still compared on a common baseline.
Testify assesses against CIS Controls v8 at the safeguard level and NIST CSF 2.0, with a NIST-to-CIS crosswalk, and you can build and score your own framework in the authoring wizard. AI risk is covered through an AI hygiene assessment based on SAFE² with crosswalks to the EU AI Act, NIST AI RMF, ISO 42001, and OWASP-LLM. Testify recommends assessment questions from your incident history, its local AI drafts them to ask for evidence, and an AI coach checks answers against the control's requirements when the assessor asks.
Six Board screens computed from the live register: an Executive Brief whose exposure bridge separates risk reduction earned by verified control closes from model re-estimates and portfolio changes; a Portfolio Exposure Map of claimed versus verified coverage; Spend Efficacy; a Loss Model with every assumption visible; Capital Allocation ranked by what each dollar retires; and a Campaign Rollup that counts the exposure verified work retired.
Most cyber risk quantification tools produce a dollar figure. Testify ties that figure to verified control state and shows why it moved: earned by verified closes, re-estimated because an assumption changed, or changed because the portfolio changed. The loss model is visible to customers and theirs to adjust.
No. Cyber Flag has no private-equity investors or owners, so the vendor behind your portfolio governance platform is not backed by a sponsor you compete with. Testify is also self-hosted: portfolio data stays in your deployment.
More in the full FAQ, or start with What is Testify and how it compares.
13 Get started
Testify is accepting early customers. Portfolio Directors and Fund Operating Partners get priority access to a guided walkthrough.
What you'll see