Black Bay Security
Get your no-cost assessment deepcurrent login
deepcurrent GRC™ · Platform

Your security program,
with a home.

deepcurrent GRC™ is the co-managed governance, risk and compliance platform included with every Black Bay engagement, at no additional cost. Assessments, risk register, remediation tasks and board reporting, resolving to one dataset.

deepcurrent GRC
deepcurrent dashboard: security score 2.9 and efficiency score 2.1, twelve open findings, domain maturity scored against target across seven domains, and the Black Bay Compass business risk ranking.
Task distribution: 32 pending, 6 in process, 4 completed.
Deepwater pillar scores: AI Landscape 3.4 at weight 15 percent, Readiness 2.8 at weight 25 percent.

deepcurrent GRC™: assessment scoring, Deepwater readiness and tracked remediation, in one place.

0COMPASS™ business risk domains scored end to end
0Compliance frameworks mapped from one control set
0Roles with scoped, least-privilege access
No-CostIncluded with every program engagement
How it works

Business risk in. Executable program out.

A continuous loop. COMPASS establishes what the business cares about; assessment measures current state against it; findings become owned, dated tasks; reporting shows movement, and the loop restarts with real evidence behind it.

01

COMPASS

Executive alignment workshop maps the seven business risk areas and sets the priority weighting.

02

Assess

Custom assessment scored against COMPASS™ and your target frameworks.

03

Findings

Gaps become discrete findings with severity, business-risk linkage and evidence.

04

Tasks

Findings generate assignable remediation tasks with owners, due dates and status.

05

Report

Board-ready and audit-ready output generated from live data.

Re-assessed on your program cadence, with prior cycles retained for trending

Modules

Seven working areas.

Each is a first-class object in the data model, and each references the others, which is why a change to an assessment answer propagates to the risk register, the task list and the report without a rebuild.

Module 01

COMPASS

Executive alignment and business-risk mapping across the seven COMPASS™ areas: Brand and Reputation, Legal Liability, Business Enablement, Data and IP Protection, Cost of Remediation, Business Disruption, Compliance and Governance. Establishes the weighting every downstream score inherits.

  • Seven-area business risk model
  • Executive workshop capture
  • Priority weighting applied program-wide
Module 02

Assessments

Custom, repeatable assessments scored against your chosen frameworks: maturity and efficiency scores, not a pass/fail checklist.

  • Framework-aligned question sets
  • Maturity + efficiency scoring
  • Cycle history retained for trending
Module 03

Findings

Every identified gap becomes a discrete, tracked record with severity, owner, evidence and a link back to the business risk it threatens.

  • Severity and business-risk linkage
  • Evidence attachment
  • Open → verified-closed lifecycle
Module 04

Risk register

The single authoritative view of organizational cyber risk mapped to business risk: inherent and residual, with treatment decisions recorded.

  • Business-risk to cyber-risk mapping
  • Inherent vs. residual tracking
  • Accept / mitigate / transfer logged
Module 05

Tasks

Remediation work with real owners and dates, run in the weekly co-management cadence between your team and your vCISO.

  • Assignment across both organizations
  • Due dates, status and burndown
  • Traceable to the originating finding
Module 06

Reports

Board-ready and audit-ready output generated from live platform data, so the executive narrative and the evidence pack never disagree.

  • Executive and board summaries
  • Audit-ready evidence output
  • Maturity trend over time
Module 07

AI Security

Controls, insights, gaps and recommended solutions for the AI your business actually runs, built from real-time platform data rather than a point-in-time questionnaire. AI-enhanced analysis correlates findings across assessments, the risk register and live evidence, so what you get is an accurate security result instead of an estimate.

  • Real-time data, not an annual snapshot
  • AI-assisted gap detection and control recommendations
  • Findings correlated across the whole program
Role-based access

Five roles. Least privilege by default.

Co-management only works if everyone sees exactly what their job requires and nothing more. Access is scoped per role at the module level.

deepcurrent role and capability matrix
Role COMPASSAssessmentsFindingsRisk registerTasksReportsdeepwater
Black Bay vCISO Advisor
Your Executives
Your Security Leaders
Your Security Teams
Internal/External Auditors
Full access Visibility No access
Security & compliance posture

We hold the platform to the standard we hold you to.

A GRC platform holds the most sensitive material an organization has: its unremediated gaps. Below is how deepcurrent is secured, and what your own security review will want on file before onboarding.

Encryption

Data encrypted in transit with TLS 1.2+ and at rest with AES-256, with managed key rotation.

Identity & access

Role-based access control across all five roles, enforced server-side. MFA on every account; SSO / SAML for enterprise tenants.

Tenant isolation

Each client operates in a logically isolated tenant. Advisors are scoped to the engagements they are assigned to.

Audit logging

User actions, access events and record changes logged with actor, timestamp and prior value.

Availability & recovery

Major cloud infrastructure, automated backups, defined RPO/RTO targets and tested restore procedures.

Data residency

Client data stored in a defined region and not moved without explicit agreement.

Secure development

Change control with peer review, dependency and vulnerability scanning, and periodic third-party penetration testing.

Retention & exit

Full export available throughout the engagement, with defined retention and secure deletion on termination.

Framework coverage

Answer once. Map everywhere.

deepcurrent scores against one control set and maps the result across the frameworks you actually have to satisfy, so preparing for a SOC 2 audit does not mean starting your ISO evidence from zero.

ISO 27001NIST CSFNIST 800-53PCI DSSSOC 2HIPAACMMCAI securityLegacy systems

Framework list per the current site. Confirm CMMC and 800-53 are live in-platform.

  • DeliveryCloud-hosted SaaS, no client-side infrastructure
  • AccessBrowser-based; no install or plug-in
  • AuthPassword + MFA; SSO / SAML for enterprise tenants
  • AuthorizationRole-based, five roles, enforced server-side
  • ProvisioningPer tenant, scoped by role
  • LicensingIncluded at no additional cost with any program
  • CadenceWeekly check-ins · monthly reviews · quarterly board reviews
FAQ

Platform questions.

Is deepcurrent an extra line item?

No. Full access to your own configured tenant is included with any Black Bay program at no additional cost.

Can our auditors get access?

Yes. Auditors receive scoped, read-only visibility: reports and control status with attached evidence, without touching program operations.

Do we lose our data if we leave?

No. Your data is yours; full export is available throughout the engagement, with defined retention and secure deletion on termination.

Does it replace our SIEM or vulnerability scanner?

No. deepcurrent is the governance, risk and compliance layer, the place the program is designed, tracked and reported. It sits above your operational tooling, not instead of it.

Next step

Bring your own risk register.

We will show you what it looks like in deepcurrent. Included at no additional cost with every Black Bay program.

No cost. No obligation. No vendor pitch. We don't resell anything.