Conundrum Intelligence is built with security-first principles and maps to the major cybersecurity and data-protection standards every regulated organisation faces, across any sector.
Our platform aligns with the NIST CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Conundrum supports Govern, Identify, and Detect through continuous threat monitoring and intelligence-driven risk assessment.
Conundrum operationalises the continuous-monitoring, risk-management, and incident-documentation duties NIS 2 introduces. Dated PIRs and tagged dissemination logs evidence risk-based prioritisation, supply-chain oversight, and timely incident reporting (Arts 21, 23–24).
We are committed to GDPR compliance for our European users. This includes data minimization in our collection practices, clear consent mechanisms, data portability support, and the right to erasure. Our privacy policy details how personal data is processed and protected.
Our information security management practices are aligned with ISO 27001:2022. This includes formal risk assessment processes, access control policies, incident response procedures, and continuous monitoring of our security posture.
Threat intelligence supports all five DORA pillars: evidence for ICT risk management, intel-enriched reports for major-incident reporting, real-world TTPs to shape operational-resilience testing, and threat monitoring to inform third-party risk.
One workflow is the proof for all five: dated PIRs show what you prioritised, consolidated reports show how you analysed it, and dissemination tagging shows who you told and when. That gives you the timestamped, traceable audit trail regulators ask for across every framework.
All data encrypted in transit (TLS 1.3) and at rest (AES-256). API keys and credentials are securely stored using environment-level encryption.
Role-based access control with tenant-level isolation, plus session management for all user accounts.
Continuous security monitoring, automated vulnerability scanning, and incident response procedures to detect and respond to threats promptly.