Features That Produce Reviewer-Ready Exports
If you have a buyer questionnaire, bring it. We’ll map capabilities to their asks.
Reviewer-Ready Export
Answers with linked evidence.
PDF/ZIP
Evidence Bundle
Timestamped artifacts for sampling.
ZIP
Trust Center Access Logs
Exportable access events.
CSV
How to Read This Page
- If your priority is “send a reviewer-ready packet,” start with Exports and Trust Center.
- If your priority is “keep evidence current,” start with Integrations and Freshness.
- If your priority is “prove readiness,” start with Practice Readiness and Governance.
Plan availability is marked below. If you need something not listed, ask in a walkthrough.
Showing All.
Plan Availability
- Included
- Not included
- Add-on / early access
- “Where enabled” (use in notes, not in checkmarks)
Buyers and auditors do not need paid seats. Operator seats are for your internal team.
Exports and Deliverables
Everything reviewers receive: PDFs, ZIPs, snapshots, and logs.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Included | Included | Included | Included | Included | |
| Included | Included | Included | Included | Included | |
Structured artifacts with source details and timestamps. | Included | Included | Included | Included | Included |
| Not included | Included | Included | Included | Included | |
| Not included | Included | Included | Included | Included | |
| Not included | Included | Included | Included | Included | |
Closure exports that cite evidence versions and include a tamper-evident file list. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Deterministic audit periods and signed diffs for offline review. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Verify source details, timestamps, and exports in a reviewer-friendly view. | Included | Included | Included | Included | Included |
Signed audit log bundles and optional sinks (webhook, Splunk HEC, Datadog). | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Evidence Management
Evidence capture, source details, pinned versions, freshness, and coverage.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Not included | Included | Included | Included | Included | |
| Not included | Included | Included | Included | Included | |
Capture dates and source details stay attached to exported evidence. | Included | Included | Included | Included | Included |
| Not included | Included | Included | Included | Included | |
Every replacement creates an immutable snapshot. | Not included | Included | Included | Included | Included |
Automation without sharing personal credentials. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Assessments and Answers
Questionnaires, cited drafting, approvals, and golden answers.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
Import questionnaires, set scope/deadlines, and keep an attributable review record. | Included | Included | Included | Included | Included |
Draft answers grounded in evidence, then review and approve before export. | Included | Included | Included | Included | Included |
Reuse approved language across reviews without starting from scratch. | Included | Included | Included | Included | Included |
AI-assisted drafting with citations and clear human review boundaries. | Not included | Included | Included | Included | Included |
Governance and Program Records
Policies, approvals, training records, and review cadence.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Included | Included | Included | Included | Included | |
| Included | Included | Included | Included | Included | |
| Included | Included | Included | Included | Included | |
Foundations supports 3 active frameworks. Higher plans support unlimited frameworks. | Included | Included | Included | Included | Included |
| Included | Included | Included | Included | Included | |
Centralized authentication and automated onboarding for larger teams. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Scope controls, evidence, and exports per entity. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Risk and Vendor Workflows
Risks, remediation tasks, vendor due diligence, and decision trails.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Not included | Included | Included | Included | Included | |
| Not included | Included | Included | Included | Included | |
Create breach events and escalation notifications with an audit trail. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
| Not included | Included | Included | Included | Included | |
| Not included | Not included | Included | Included | Included | |
| Not included | Not included | Included | Included | Included |
Trust Center Sharing
Tiered access, agreements, deal rooms (plan-based), watermarking, and logs.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
Buyers and auditors can access shared proof without taking operator seats. | Included | Included | Included | Included | Included |
Gate sensitive docs behind verification and agreements. Log access. | Included | Included | Included | Included | Included |
| Not included | Not included | Not included | Included | Included | |
Restrict portal access by network range with time-bound break-glass. | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access | Add-on / early access |
Readiness and Operations (Plan-Based)
Tabletop exercises, phishing, training, emergency communications, and incident proof.
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Not included | Not included | Included | Included | Included | |
| Not included | Not included | Included | Included | Included | |
| Not included | Not included | Not included | Included | Included | |
| Not included | Not included | Not included | Included | Included |
Command (Early Access)
Infrastructure evidence collection and drift/change reporting (scoped onboarding).
| Feature | Foundations | Continuous | Security Ops | Resilience | Command |
|---|---|---|---|---|---|
| Not included | Not included | Not included | Not included | Included |
Feature Questions
Do you have a free trial?
We start with a short walkthrough and a sample export.
Can you answer a buyer security questionnaire?
Aurora helps you draft cited answers and export a reviewer-ready packet. You still review and approve language before sending.
Can we see sample outputs?
Yes. Use the sample export page to preview the format.