Get through customer security requirementswithout becoming the compliance department.
Sable supports lean internal teams that need to meet SOC 2, ISO 27001, HIPAA, or other customer-driven requirements without a dedicated security leader. One workspace for your frameworks, evidence, vendors, risks, and findings, with SubRosa's specialists available when the work needs people.
14-day trial · No credit card required. No demo gate.
ISO 27001:2022 certification readiness
In progressISO 27001:2022 · Annex A · target audit Q1 2027
| ID | Control | Owner | Status | Progress |
|---|---|---|---|---|
| 5.1 | Policies for information securityInformation security policy and topic-specific policies shall be defined, approved by management, published and communicated to… | R. Gupta | Complete | 100% |
| 5.2 | Information security roles and responsibilitiesInformation security roles and responsibilities shall be defined and allocated according to the organization's needs. | R. Gupta | Complete | 100% |
| 5.3 | Segregation of dutiesConflicting duties and areas of responsibility shall be segregated. | M. Ellery | Complete | 100% |
| 5.7 | Threat intelligenceInformation relating to information security threats shall be collected and analysed to produce threat intelligence. | SubRosa SOC | In progress | 60% |
| 5.9 | Inventory of information and other associated assetsAn inventory of information and other associated assets, including owners, shall be developed and maintained. | M. Ellery | In progress | 45% |
| 5.15 | Access controlRules to control physical and logical access to information and other associated assets shall be established. | D. Whitfield | In progress | 30% |
| 5.23 | Information security for use of cloud servicesProcesses for acquisition, use, management and exit from cloud services shall be established. | Unassigned | Not started | 0% |
| 5.30 | ICT readiness for business continuityICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives. | Unassigned | Not started | 0% |
The deal is waiting on a security questionnaire.Somebody has to own the answer.
Customer security reviews, SOC 2 and ISO 27001 requirements, and vendor questionnaires all land on whoever is closest, usually an engineering lead or an operations manager already doing another full-time job.
Evidence lives in ten places
Screenshots in a drive, policies in a doc, tickets in a tracker, and the proof an auditor wants scattered across all three.
Questionnaires arrive without warning
A prospect's security review stalls the deal, and answering it means chasing people for things you cannot easily verify.
Nobody owns security full time
The work is real but the role does not exist yet, so it competes with the job the person was actually hired for.
One workspace for the whole program,not another tool to maintain.
Sable holds the parts of a security program that usually sprawl, so the answer to any question about where you stand is in one place.
Frameworks and evidence
Map your controls once and reuse the evidence across every framework you work toward, with the audit trail attached.
Vendor risk
Run real vendor reviews and keep the results, so the next customer question about your supply chain has an answer.
Risk register that stays current
A register where risks link to the controls and evidence behind them, rather than a spreadsheet that goes stale between reviews.
Findings with owners and due dates
Every finding gets an owner, a due date, and a retest, so remediation is tracked to done instead of closed on trust.
You do not have a security team.You can still have security people.
Some of this work needs humans: a penetration test a customer is asking for, an incident at 2am, a policy set someone senior has to stand behind. SubRosa's specialists do that work, and it lands back in the same workspace rather than in a PDF.
Penetration testing
The test your customer or auditor is asking for, with findings that arrive in your Sable queue with owners and retests.
Managed detection and response
24/7 monitoring across Microsoft 365, identity, and endpoints, triaged by analysts, for teams who cannot staff a night shift.
vCISO leadership
Senior security leadership on demand for the decisions, board questions, and program direction that need a named owner.
Sable is where I go to see where we actually stand. Before we had it I was mostly taking people's word for things, or digging through emails trying to work out whether something had been done. Now the frameworks, the evidence, the vendors, it's all in one place and I can just look.
not a sales call.
Create your account and bring your frameworks, evidence, vendors, and findings into one workspace. No credit card, and nobody has to sit through a demo before seeing the product.
14-day trial · No credit card required. No demo gate.
Common questions
- Can we use Sable without a dedicated security team?
- Yes. Sable is built so a lean internal team, often an engineering or operations lead who inherited the compliance work, can run the program: frameworks and evidence in one place, vendor reviews, a risk register, and findings with owners and due dates. When the work genuinely needs a specialist, SubRosa's team can be engaged from inside the same workspace rather than through a separate procurement.
- Which compliance frameworks does Sable support?
- Sable maps controls once and reuses the evidence across the frameworks you are working toward, including SOC 2, ISO 27001, HIPAA, and others. Because controls, evidence, and policies live in one graph, updating a control keeps everything connected to it current, including the audit trail.
- How is this different from a compliance automation tool?
- Most compliance platforms stop at the software. Sable covers the same ground, frameworks, evidence, policies, and audit readiness, and adds the part lean teams usually have to solve separately: access to SubRosa's security specialists for penetration testing, managed detection and response, and vCISO leadership, with the resulting findings and evidence landing back in the same workspace.
- What happens when a customer sends us a security questionnaire?
- The work that makes questionnaires painful is finding the evidence. With controls, policies, vendor reviews, and findings in one workspace, the answers and the proof behind them are already collected rather than reconstructed from drives, tickets, and inboxes each time a review lands.
- Can we start without talking to sales?
- Yes. The trial runs for 14 days, needs no credit card, and has no demo gate: you can create an account and bring your own frameworks, vendors, and findings into the workspace to see how it fits before any conversation.