Your security program,
with a home.
deepcurrent GRC™ is the co-managed governance, risk and compliance platform included with every Black Bay engagement, at no additional cost. Assessments, risk register, remediation tasks and board reporting, resolving to one dataset.

deepcurrent GRC™: assessment scoring, Deepwater readiness and tracked remediation, in one place.
Business risk in. Executable program out.
A continuous loop. COMPASS establishes what the business cares about; assessment measures current state against it; findings become owned, dated tasks; reporting shows movement, and the loop restarts with real evidence behind it.
COMPASS
Executive alignment workshop maps the seven business risk areas and sets the priority weighting.
Assess
Custom assessment scored against COMPASS™ and your target frameworks.
Findings
Gaps become discrete findings with severity, business-risk linkage and evidence.
Tasks
Findings generate assignable remediation tasks with owners, due dates and status.
Report
Board-ready and audit-ready output generated from live data.
Re-assessed on your program cadence, with prior cycles retained for trending
Seven working areas.
Each is a first-class object in the data model, and each references the others, which is why a change to an assessment answer propagates to the risk register, the task list and the report without a rebuild.
COMPASS
Executive alignment and business-risk mapping across the seven COMPASS™ areas: Brand and Reputation, Legal Liability, Business Enablement, Data and IP Protection, Cost of Remediation, Business Disruption, Compliance and Governance. Establishes the weighting every downstream score inherits.
- Seven-area business risk model
- Executive workshop capture
- Priority weighting applied program-wide
Assessments
Custom, repeatable assessments scored against your chosen frameworks: maturity and efficiency scores, not a pass/fail checklist.
- Framework-aligned question sets
- Maturity + efficiency scoring
- Cycle history retained for trending
Findings
Every identified gap becomes a discrete, tracked record with severity, owner, evidence and a link back to the business risk it threatens.
- Severity and business-risk linkage
- Evidence attachment
- Open → verified-closed lifecycle
Risk register
The single authoritative view of organizational cyber risk mapped to business risk: inherent and residual, with treatment decisions recorded.
- Business-risk to cyber-risk mapping
- Inherent vs. residual tracking
- Accept / mitigate / transfer logged
Tasks
Remediation work with real owners and dates, run in the weekly co-management cadence between your team and your vCISO.
- Assignment across both organizations
- Due dates, status and burndown
- Traceable to the originating finding
Reports
Board-ready and audit-ready output generated from live platform data, so the executive narrative and the evidence pack never disagree.
- Executive and board summaries
- Audit-ready evidence output
- Maturity trend over time
AI Security
Controls, insights, gaps and recommended solutions for the AI your business actually runs, built from real-time platform data rather than a point-in-time questionnaire. AI-enhanced analysis correlates findings across assessments, the risk register and live evidence, so what you get is an accurate security result instead of an estimate.
- Real-time data, not an annual snapshot
- AI-assisted gap detection and control recommendations
- Findings correlated across the whole program
Five roles. Least privilege by default.
Co-management only works if everyone sees exactly what their job requires and nothing more. Access is scoped per role at the module level.
| Role | COMPASS | Assessments | Findings | Risk register | Tasks | Reports | deepwater |
|---|---|---|---|---|---|---|---|
| Black Bay vCISO Advisor | |||||||
| Your Executives | |||||||
| Your Security Leaders | |||||||
| Your Security Teams | |||||||
| Internal/External Auditors |
We hold the platform to the standard we hold you to.
A GRC platform holds the most sensitive material an organization has: its unremediated gaps. Below is how deepcurrent is secured, and what your own security review will want on file before onboarding.
Encryption
Data encrypted in transit with TLS 1.2+ and at rest with AES-256, with managed key rotation.
Identity & access
Role-based access control across all five roles, enforced server-side. MFA on every account; SSO / SAML for enterprise tenants.
Tenant isolation
Each client operates in a logically isolated tenant. Advisors are scoped to the engagements they are assigned to.
Audit logging
User actions, access events and record changes logged with actor, timestamp and prior value.
Availability & recovery
Major cloud infrastructure, automated backups, defined RPO/RTO targets and tested restore procedures.
Data residency
Client data stored in a defined region and not moved without explicit agreement.
Secure development
Change control with peer review, dependency and vulnerability scanning, and periodic third-party penetration testing.
Retention & exit
Full export available throughout the engagement, with defined retention and secure deletion on termination.
Answer once. Map everywhere.
deepcurrent scores against one control set and maps the result across the frameworks you actually have to satisfy, so preparing for a SOC 2 audit does not mean starting your ISO evidence from zero.
Framework list per the current site. Confirm CMMC and 800-53 are live in-platform.
- DeliveryCloud-hosted SaaS, no client-side infrastructure
- AccessBrowser-based; no install or plug-in
- AuthPassword + MFA; SSO / SAML for enterprise tenants
- AuthorizationRole-based, five roles, enforced server-side
- ProvisioningPer tenant, scoped by role
- LicensingIncluded at no additional cost with any program
- CadenceWeekly check-ins · monthly reviews · quarterly board reviews
Platform questions.
Is deepcurrent an extra line item?
No. Full access to your own configured tenant is included with any Black Bay program at no additional cost.
Can our auditors get access?
Yes. Auditors receive scoped, read-only visibility: reports and control status with attached evidence, without touching program operations.
Do we lose our data if we leave?
No. Your data is yours; full export is available throughout the engagement, with defined retention and secure deletion on termination.
Does it replace our SIEM or vulnerability scanner?
No. deepcurrent is the governance, risk and compliance layer, the place the program is designed, tracked and reported. It sits above your operational tooling, not instead of it.
Bring your own risk register.
We will show you what it looks like in deepcurrent. Included at no additional cost with every Black Bay program.
No cost. No obligation. No vendor pitch. We don't resell anything.
