LAGAN CYBER
§ 02 — Control domains · CD-01 … CD-05

Five domains, each one accountable for a specific class of evidence.

A compliance product is only as good as the boundary it draws around itself. These are ours: what each domain reads, what it produces, and — for three of the five — the fact that it does not exist yet.

Two domains in build Three in design Nothing available to customers

Domain index

The register

Control domains — state as at 5 August 2026
Code Domain Produces State
CD-01Cloud postureConfiguration assertions and drift recordsBuild
CD-02EvidenceAppend-only evidence records with integrity hashesBuild
CD-03PoliciesVersioned policy register and acknowledgement logDesign
CD-04Supplier riskQuestionnaire responses and supplier review recordsDesign
CD-05PeopleTraining completion and phishing simulation recordsDesign

Build — code exists and runs in our internal environment against test tenants. Design — the domain is specified, its control mapping is written, and no production code exists. Neither state means available to buy.

CD-01 · Cloud posture · Build

Cloud posture

Scheduled, read-only inspection of how your cloud tenants are configured, compared against a baseline and against the last time we looked. Configuration drift is the thing that quietly invalidates last year’s audit.

Reads

Settings and metadata only

A posture scan requests configuration objects: conditional access policies, role assignments, sharing settings, transport rules, audit-log configuration, key vault and storage account properties. It reads the shape of your tenant, not its contents.

It does not read the body of emails, the contents of documents in SharePoint, OneDrive or Google Drive, chat messages, or any customer data your business holds. Where an API returns a document identifier or a mailbox name as part of a configuration object, that identifier is stored; the document is not fetched.

Connects to

Three platforms, one partially

Connector state
PlatformMethodChecksState
Microsoft 365 & Entra IDGraph API, read-only app registration31Build
Google WorkspaceAdmin SDK, read-only service account16Partial
Microsoft AzureARM reader rolePlanned

Checks

Forty-seven assertions across six families

Check families — CD-01
FamilyChecksExample assertionMaps to
Authentication12MFA enforced for all accounts holding a privileged role, with no policy exclusionsA.5.15 · A.8.5 · CE-UAC
Privilege7Global administrator count within a defined bound and no standing assignmentA.5.15 · A.5.18 · CE-UAC
Sharing & guests9Anonymous link sharing disabled or time-limited at tenant levelA.5.14 · A.8.12
Mail flow6No automatic external forwarding rule at mailbox or transport levelA.8.12 · CAF B3
Data & secrets8No storage container with public read access; key expiry setA.8.24 · NIS2 21(2)(h)
Logging5Unified audit log enabled with a retention period at or above policyA.8.15 · CAF C1

Example assertions are shortened for readability. Check counts are as at 5 August 2026 and move as the library is written.

Does not do

No write access, ever

The connectors request read-only scopes. The platform cannot change a setting in your tenant, cannot disable an account, cannot quarantine a message and cannot remediate a finding. If a check fails, you get the finding, the control reference and the evidence record; the change is made by you or by whoever runs your IT.

This is a deliberate constraint, not a gap. A compliance tool with tenant write access is a very attractive target, and we would rather not be one.

CD-02 · Evidence · Build

Evidence

The domain that makes the others worth anything. Every check, questionnaire response, policy acknowledgement and training completion resolves to an evidence record in a single append-only store.

Record model

Nine mandatory fields

A record that cannot answer “when”, “from where” and “by what method” is not evidence, it is a screenshot. Every record carries a control reference, a source system, a scope, a UTC collection timestamp, the collection method and API scope used, a result, a retention date and a content hash.

The full record model and a specimen record →

Append-only

Corrections are new records

Records are never edited in place. If a scan was wrong, or a scope changed, a superseding record is written that references the original, and both remain visible with their timestamps. An assessor can see the history rather than a tidied version of it.

Integrity

Content hashing

Each record is hashed at write time over its canonical serialisation. The hash is displayed alongside the record and included in exports, so a record extracted today can be checked against the record in the store later. This is a tamper-evidence measure, not a tamper-proof one, and we describe it that way.

Not built

Export and auditor access

  • Evidence bundle export as PDF and structured JSON
  • Time-boxed read-only access for an external assessor
  • Cross-framework evidence reuse view
  • Retention-clock automation and expiry warnings
CD-03 · Policies · Design

Policies

Specified in full. No production code exists. Included here because a coverage claim that omits the unbuilt half of the product is a marketing claim, not a coverage claim.

Intent

A register, not a document generator

Assessors ask for policy documents, and then ask who approved them, when they were last reviewed, and who has read them. The three follow-up questions are where SMEs fail, because the document lives in a shared drive with no owner and a review date that passed in 2023.

CD-03 holds the register: document, version, owner, approver, approval date, next review date, and an acknowledgement log per version. Each policy links to the controls it is offered as evidence for, so a gap in the register shows up as a gap in the matrix.

Baseline set

Fourteen drafted policies

A starting set drafted against Annex A themes, intended to be edited rather than adopted verbatim: information security policy, acceptable use, access control, cryptography, supplier security, secure development, change management, asset management, remote and mobile working, incident response, business continuity, data protection, logging and monitoring, and physical security.

These are templates. Adopting a template you have not read is a compliance risk in itself, and the platform will say so at the point of adoption.

Honest note

Templates are not advice

We are not a law firm and the drafted policy set is not legal advice. It is a structured starting point for a business that currently has nothing written down.

CD-04 · Supplier risk · Design

Supplier risk

Specified. Unbuilt. The domain that turns your own supply chain from a spreadsheet into dated records — and the prerequisite for any credible DORA or NIS2 supply-chain answer.

Intent

Questionnaires that produce records

Issue a security questionnaire to a supplier, tiered by how much damage that supplier could do to you. Track what came back, what did not, and when it is due to be asked again. Attach the certificates and reports they send. Hold the whole thing against the same control references as everything else.

Tiering

Three questionnaire templates

Planned questionnaire tiers
TierApplies toQuestionsReview cadence
T1Suppliers processing personal data or holding privileged access~60Annual
T2Suppliers material to service delivery, no personal data~25Every 2 years
T3Low-criticality suppliers~10On change

Question counts are design targets and will change once the domain is written.

Boundary

We do not score or rate suppliers

There is no risk score, no letter grade, no external scanning of your suppliers’ infrastructure and no threat-intelligence feed. We collect and hold what your supplier told you, with a date on it. Judging whether the answer is acceptable is your decision to make and to record.

CD-05 · People · Design

People

Specified. Unbuilt. Security awareness treated as an evidence source rather than as a separate subscription with its own login.

Intent

Completion records, not engagement metrics

The compliance question is never “did your staff enjoy the training”. It is “show me, for this named person, that they completed the assigned module on this date, and show me the record”. CD-05 stores that, plus phishing simulation results by cohort, plus the starter, mover and leaver checks that keep access aligned to employment.

Fairness

Phishing simulation, handled carefully

Simulated phishing produces personal data about employee behaviour, and it is easy to build something disciplinary out of it. The design position is that results are reported at cohort level by default, that individual results exist to trigger further training rather than sanction, and that an employer using them otherwise is making a decision we will document in the record.

Where your business runs simulations through us, you are the controller of that data and we are your processor. See the processor sections of the privacy notice.

Boundary

Not an HR system

No performance data, no absence records, no payroll, no disciplinary workflow. The People domain holds security training and simulation records and the minimum identity fields needed to attach them to a person.

§ 06 — Early access

Two of five domains work. That is the honest position.

If your organisation would find CD-01 and CD-02 useful on their own — cloud posture scanning that writes referenced, dated evidence — private early access is open to a small number of UK and Ireland businesses. Everything else on this page is a plan.

Early access — hello@lagancyber.co.uk · we reply within two working days