ES
GRC platform · ISO/IEC 27001:2022 · CNO Agreement 1960

ISO 27001 & CNO 1960
with real evidence

Tridenty Auditor is a GRC platform to implement and audit ISO/IEC 27001:2022 and the CNO Cybersecurity Guide (Agreement 1960): 134 preloaded controls, a guided path that does not advance without approved evidence and documents sealed with a SHA-256 hash and two signatures.

SHA-256 · Two signatures · Guided path · Multi-tenant

134
Preloaded controls
7
Integrated modules
2
Standards, one per tenant
4
Roles with segregation of duties

WHY TRIDENTY AUDITOR

Compliance you can stand behind

Complying with an information security standard shouldn't mean chasing evidence across emails and shared folders. Tridenty Auditor centralizes the whole cycle in a single multi-tenant platform. It isn't a flat checklist: it's a path that blocks progress without approved evidence, and every approved document is sealed with a SHA-256 hash and two signatures, verifiable at any time.

Real evidence, not ticked boxes

The compliance indicator only goes up when there is an approved document behind every control or task. The number you see is the one you can defend in front of an external auditor.

Verifiable integrity for every document

Two signatures (reviewed and approved), a SHA-256 hash per version and a stamped PDF as a controlled copy, marked OBSOLETE or DRAFT when applicable. One click recalculates the hash and confirms nobody touched the file.

A clear, step-by-step path

ISMS Path (8 phases) or CNO Path (10 phases) with tasks, owners and mandatory evidence. A phase does not unlock until the previous one is closed.

Everything connected, in one place

Documents, processes, risks, SoA, legal requirements and audit share the same controls and the same evidence. No more spreadsheets that never add up.

Control by role and by tenant

Four roles with segregation of duties (the auditor can't approve their own evidence) on an architecture that isolates each customer's data in the database.

134 controls ready to use

The full Annex A of ISO/IEC 27001:2022 and the 41 controls of CNO Agreement 1960, with their evidence requirements, come preloaded. Nothing to enter by hand before you start.

Included modules

Seven modules that share the same controls and the same evidence.

MOD·DOC

Document control

Versioning with a draft → review → two-signature approval flow, SHA-256 seal, stamped PDF, "read and understood" acknowledgment, retention with disposition and legal hold, templates and full-text search in Spanish.

MOD·WZD

Step-by-step wizard

ISMS Path or CNO Path according to the tenant's standard: tasks with owner, date and mandatory evidence; unlock by phase. Turns the standard into a work plan.

MOD·RSK

Risk management

Assets, probability × impact matrix, treatment plan and residual risk, linked to the controls that mitigate it.

MOD·SOA

Statement of Applicability

The standard's controls with applicability, exclusion justification and an owner per control. A living SoA, not a PDF that goes out of date.

MOD·AUD

Internal audit

Audit program, classified findings and CAPA with root cause, owner, % progress and estimated cost; auditor's assessment on closing and evidence-verifiable closure.

MOD·PRC

Process map and dashboard

Process tree with linked documents and an embedded viewer; landing dashboard with ISMS status and document hygiene.

MOD·LEG

Legal requirements

Matrix of legal, regulatory and contractual requirements with owner, evidence and compliance level (ISO 27001 cl. 4 and A.5.31).

Cross-cutting

Audit log, roles and experience

Record of who did what, when and from where; four roles; Spanish-language interface, light and dark mode, and use on desktop, tablet and mobile.

ON SCREEN

What compliance looks like

Compliance indicator: a single percentage visible across the whole platform that only goes up with approved evidence on the SoA, the Path and the legal matrix. It measures real implementation maturity, not just document validity.

Tridenty Auditor dashboard with compliance indicator and document hygiene

Dashboard

Live compliance indicator, ISMS status and document hygiene: overdue, due soon and implementation days.

Tridenty Auditor document control with signatures and integrity verification

Documents

Signatures, seal and SHA-256 integrity verification in one click.

Tridenty Auditor ISMS Path with phases and required evidence

ISMS Path

Phases that only unlock with approved evidence.

Tridenty Auditor internal audit with findings and CAPA

Internal audit

Program with auditor assessment, classified findings and CAPA with % progress and estimated cost.

SUPPORTED STANDARDS

Two standards. One per tenant.

Each tenant chooses its standard on creation, so incompatible structures are never mixed.

93 controls · 4 domains · 8-phase Path

ISO/IEC 27001:2022

The international information security management standard, with its full Annex A.

41 controls · 10 sections · 58 requirements · 10-phase Path

CNO Cybersecurity Guide · Agreement 1960

The regulatory requirement of Colombia's National Operation Council (CNO) for power sector agents, with mandatory audits starting in 2026.

The compliance engine behind both is designed to add new standards (NIST CSF 2.0 is on the roadmap) without rebuilding the platform.

Specifications

Roles
Super Admin, Tenant Admin, Internal Auditor and Viewer, with segregation of duties.
Isolation
Multi-tenant with Row-Level Security in PostgreSQL and an application role without superuser privileges.
Authentication
bcrypt passwords, short-lived session token with revocable renewal, lockout after failed attempts.
Integrity
SHA-256 hash per version, two-signature approval seal and stamped PDF as a controlled copy.
Traceability
Event log: who did what, when and from which address, for audit and forensics.
Evidence
Every document is a real, versioned file with an approval flow; never a free-text field.
Deployment
Cloud SaaS as the main option; in special cases (regulation or network isolation), on-premise in containers in the customer's data center.
Interface
Spanish-language web app, light and dark mode, adapted to desktop, tablet and mobile.

Licensing

A single plan with every module included. Choose the billing cycle that best fits your operation.

Monthly
USD 150 / month

Billed month to month, no commitment.

Request a demo
Save 17% · 2 months free
Annual
USD 1,500 / year

Equivalent to USD 125/month: pay for 10 months, get 12.

Request a demo

Main option: cloud SaaS. On-premise deployment is evaluated case by case for customers with regulatory or isolation requirements, with the same licensing.

GETTING STARTED

From demo to go-live

01

Guided demo

A 45-minute walkthrough on the standard that applies to your organization: ISMS Path or CNO Path, document control with seal and integrity, internal audit.

02

Pilot

SaaS tenant ready the same day, with the 134 controls and paths preloaded. In special cases, on-premise container install in under 20 minutes.

03

Go-live

Support to load your existing documentation, define processes, owners and responsibilities, and start the path from your real state.

Roadmap

Subject to change

Upcoming releases

Password recovery and email invitations · second authentication factor (authenticator app) · information asset inventory with a power-sector catalog · internal audit with a standard-derived checklist and sealed report · incident log in the CNO Agreement 2088 format.

Phase 2

Management review with generated minutes · training and competence · security objectives and indicators · NIST CSF 2.0 on the same engine · federated enterprise SSO with the customer's directory · isolated tier for regulated customers.

FAQ

Tridenty Auditor FAQ

What is Tridenty Auditor?

Tridenty Auditor is a GRC platform to implement and audit ISO/IEC 27001:2022 and the CNO Cybersecurity Guide (Agreement 1960). It centralizes documents, risks, the Statement of Applicability, legal requirements and internal audit on the same controls and the same evidence.

Which standards does it cover?

ISO/IEC 27001:2022 (93 Annex A controls, 8-phase path) and the CNO Cybersecurity Guide, Agreement 1960 (41 controls, 10 sections, 58 requirements, 10-phase path). Each tenant picks one standard. NIST CSF 2.0 is on the roadmap.

Who does CNO Agreement 1960 apply to?

It is the regulatory requirement of Colombia's National Operation Council (CNO) for power sector agents, with mandatory audits from 2026.

How is evidence integrity guaranteed?

Every approved document carries two signatures (reviewed and approved), a SHA-256 hash per version and a stamped PDF as a controlled copy. One click recomputes the hash and confirms nobody altered the file.

Is it SaaS or on-premise?

The main deployment is cloud SaaS. In special cases, for regulatory or network isolation reasons, it is installed on-premise in containers in the customer's data center, with the same licensing.

How much does Tridenty Auditor cost?

A single plan with every module: USD 150 per month or USD 1,500 per year (USD 125/month).

Turn compliance into evidence

Book a 45-minute guided demo on the standard that applies to your organization and start a pilot the same day.

SaaS · On-premise in special cases · Spanish-language support