MAX-PRO portfolio

Operational and digital risk

Defendry RiskOps

Connect risks and controls to incidents, owners, evidence, and corrective action.

Best forOperations, security, risk, and compliance teams
Workflow stageOperational and digital risk
DeliversPrioritized risk register · Incident and case timeline
Current maturityLive

The job to be done

Why this product exists.

Problem

Risk registers, incident notes, control evidence, and remediation work are often scattered. Leaders can see that a risk exists without seeing who owns the next action, what evidence supports it, or whether exposure is actually being reduced.

What it does

Defendry RiskOps connects risks and findings to owned cases, structured evidence metadata, verification, approvals, deadlines, and closure decisions. Evidence entries are sequenced and HMAC-chained to the tenant and case, while PostgreSQL transactions gate verification and closure so a passing verifier cannot also close the same case.

How it works

One controlled path through the handoff.

  1. 01

    Map

    Register critical operations, assets, vendors, risks, and the controls intended to protect them.

  2. 02

    Assess

    Capture incidents or control gaps, attach required evidence metadata, and prioritize the exposure that needs action.

  3. 03

    Act

    Assign remediation, verify evidence with an authorized reviewer, route approvals, and close only after the required gates pass.

Concrete example

What the workflow looks like in practice.

A key vendor reports a security incident. The team records the affected operation, links the relevant risk and control, assigns containment work, attaches structured evidence references, obtains verification from an authorized reviewer, and closes the case through a different accountable actor.

Inputs and outputs

What goes in. What comes out.

Inputs and context

  • Risks, assets, operations, and vendors
  • Controls and control owners
  • Incident records and evidence
  • Remediation tasks and decisions

Resulting record

  • Prioritized risk register
  • Incident and case timeline
  • Sequenced evidence-metadata chain
  • Ownership and remediation queue
  • Verification, approval, and closure record
  • Overdue and escalation view

Where it fits

Distinct role. Clear handoff.

Defendry manages organization-level cases, remediation, and evidence-gated closure. MAX-AI Guard answers the narrower pre-action question of whether an integrated AI agent should execute a proposed action now.

Current boundaries

What this product is not.

These limits are part of the product decision. They are shown before the launch link so the current scope is clear.

  • Defendry is not SIEM, EDR, antivirus, penetration testing, legal advice, or compliance certification.
  • The evidence chain covers structured metadata and references; it is not WORM storage, binary-artifact custody, or independent proof that submitted evidence is true.
  • Governed accepted-risk and false-positive workflows are not yet implemented, so direct disposition through the generic finding editor is intentionally blocked.
  • It organizes supplied risk and response information; live detection or ingestion requires a connected and verified integration.

Ready to evaluate it?

Try the live product or discuss your use case.

The product opens on a separate MAX-PRO deployment in a new tab.

Continue exploring

More in this product family