Skip to content
Sovereign GRC Execution Mesh

The Deterministic Methodology of
Vivid Risk

Replacing qualitative guesswork in enterprise risk governance with deterministic scoring and AI-assisted regulatory cross-mapping — live today — plus a public roadmap of additional calculus engines and specialized agents we have not built yet.

Modern organisations do not suffer from a lack of frameworks, standards, or policies. In fact, most organisations are overwhelmed by governance expectations, compliance obligations, and external regulatory scrutiny. The fundamental flaw lies in how risk is measured.

"The problem is not governance, risk, or compliance individually — it is the absence of a deterministic mathematical bridge connecting them to live technical reality."

Governance defines policy expectations. Compliance checks external alignment at static points in time. Vivid Risk replaces subjective 1-5 questionnaires with a deterministic maturity score computed from your real answers, plus AI-assisted mapping of your evidence against multiple regulatory frameworks at once. Evidence-decay tracking, tenant-scoped report chaining, an exact remediation-spend optimizer, and a real Monte Carlo financial-loss simulation over your own estimates are live too. The GDPR (Art. 83) and NIS2 (Art. 34) statutory ceilings are now cited live alongside that simulation — see the Verified Regulatory Source Library below. The EU AI Act ceiling remains on our roadmap until its primary text is supplied and verified the same way.

The Structural Paradigm Shift

  • Legacy GRC

    Static annual spreadsheets, subjective 1-5 ratings & unverified self-attestations

  • Vivid Mesh (Live)

    Deterministic VMI calculus, AI-assisted cross-mapping, evidence decay tracking & tenant-scoped report chaining, computed from your real evidence and answers

  • Vivid Mesh (Roadmap)

    Continuous telemetry ingest is on our roadmap — not yet built

Engine Status10 / 12 Live · 2 Roadmap

The Sovereign Truth Library

To eliminate technical interpretation drift, every safeguard is anchored in the Vivid Truth Library—a canonical, bi-directionally mapped knowledge graph of statutory requirements:

  • EU AI Act (Regulation (EU) 2024/1689)Roadmap — not yet mapped by the cross-mapper; no verified citation set exists yet
  • EU NIS2 Directive (EU 2022/2555) & DORA (EU 2022/2554)Articles 21/23, 24h/72h early warning & ICT resilience
  • EU Digital Services Act (DSA - EU 2022/2065)Roadmap — Notice & Action, Article 17 Statements, EU Transparency DB are not yet built
  • ISO/IEC 27001:2022 & NIST CSF 2.0Annex A controls & 6 CSF Core Functions. The Cyber Resilience Act is not mapped as a control set here — what is live is a separate CRA Article 14 reporting register (the 24h/72h/final-report clock), which files nothing with ENISA.

Severe Gaps Aren't Averaged Away

Traditional GRC algorithms linearly average all questions, allowing high scores on trivial controls (like password policy documents) to mask catastrophic single points of failure.

Mathematical Formulation Proportional penalty: up to −60 pts

VMI = ((∑ w_i · s_i) / ∑ w_i) × 100 − 60×(severe gaps / severe controls) − 20×(moderate gaps / moderate controls), floor 0

Failing a critical baseline safeguard — missing MFA on external access, unencrypted cloud backups, unpatched remote code execution — costs you a share of a 60-point severe-gap budget, on top of whatever the weighted average already reflects. Moderate gaps draw on a separate 20-point budget. A severe miss therefore costs roughly three times what a moderate one does and cannot be diluted by unrelated compliant answers, which is the point of having a penalty at all rather than a plain average.

Changed 13 September 2026. This penalty was previously a flat −15 points per severe gap with no ceiling. On the control set of the time, six severe gaps produced a score of exactly 0 — and so did twenty-six, so the number stopped telling you anything below that point. Expressing the penalty as a share of the controls assessed keeps the full 0–100 range meaningful and means the score does not shift when the control set grows. Scores calculated before that date are not comparable with scores after it; a report you generated earlier will re-render under the current formula.

What the sum runs over — 113 of 118 questions

i ranges over the 113 questions that have an entry in the Vivid Truth Matrix — the control library that carries the regulatory citations. The other 5 questions in the assessment are still asked, and still feed evidence collection and AI-generated findings, but they contribute nothing to the VMI in either direction: answering them all "No" does not lower your score, and answering them all "Yes" does not raise it.

Every question is labelled Scored Control or Evidence & Context Only as you answer it, and your report states the same split for your own answers.

The 5 unscored questions are excluded deliberately, not pending work. Two are free text and a headcount — there is no yes/no to score. The other three ask whether you expose systems publicly, whether you use an MSP, and whether you have had incidents in the last two years. Those record your situation, not a control you have implemented, and the engine awards full marks for "Yes": scoring them would credit an organisation for having a larger public attack surface, or for having had incidents.

Evidence Gradation
Level 1 (Low)Policy Document
Level 2 (High)CLI/API Export
Level 3 (Roadmap)Live Stream + HMAC

Evidence as the Foundation of Trust

In statutory regulatory defense (NIS2, DORA, EU AI Act), trust does not derive from self-attestations or slide decks. It comes from real, organized technical evidence — with continuous decay tracking and cryptographic tamper-evidence now live for report versions, evidence-artifact uploads, and reviewer accept/reject decisions alike, all chained in one continuous per-tenant sequence. Continuous live-stream evidence ingest (rather than discrete upload/review events) remains on our roadmap.

  • Structured Evidence (Live)
  • Cross-Reg Reusable (Live)
  • Continuous Decay (Live)
  • Report Chain — HMAC-SHA256 (Live)
  • Evidence-Artifact Hash Chain (Live)

The 10 Deterministic Computation & Scale Engines

10 engines are live and computing on your real data today. The other 2 are public roadmap — not yet built.

10 Live · 2 Roadmap
  • ENG-01Live Today

    Vivid Maturity Index (VMI) & Severe Gap Penalty Engine

    VMI = ((∑ w_i · s_i) / ∑ w_i) × 100 − 60×(severe gaps / severe controls) − 20×(moderate gaps / moderate controls), floor 0

    Calculates the core Vivid Maturity Index (0–100) from weighted questionnaire answers, minus a proportional penalty for the share of severe and moderate controls that came back as gaps — a cost that can’t be averaged away by unrelated compliant answers.

  • ENG-02Live Today

    Continuous Evidence Freshness Decay Engine

    Confidence(t) = C_0 · e^{-λ(t - t_0)}, where t_1/2 = ln(2)/λ ≈ 693 hours (28.8 days)

    Continuously decays evidence freshness over time from each artifact's real upload timestamp, so unrefreshed audit proof loses 50% validity every ~28.8 days — computed live, not stored, so it never goes stale itself. A real, authenticated cloud webhook event (Compliance Workspace+) that references the evidence's control ID resets this clock too, without a fresh re-upload.

  • ENG-03Live Today

    FAIR Monte Carlo Financial Loss Simulator

    ALE = Σ LogNormal(magnitude) over Poisson(Beta-PERT(frequency)) events, 10,000 real simulated years

    Live for a real loss distribution over your own estimates: a genuine 10,000-iteration Monte Carlo simulation (Beta-PERT-sampled event frequency, LogNormal-sampled loss magnitude, both calibrated from a Min/Most-Likely/Max range you enter) produces a full annualized-loss distribution — mean, median, P10/P90 — not one fabricated number. Every input is your own estimate; there is no real per-tenant financial dataset behind it. Real GDPR (Art. 83) and NIS2 (Art. 34) statutory ceilings, cited from their primary texts — see the Verified Regulatory Source Library below — are now shown as references alongside the distribution. The EU AI Act ceiling is not built in yet, pending its primary text.

  • ENG-04Live Today

    Multi-Framework Cross-Mapping Engine

    Gemini-assisted clause mapping over a hand-curated control-to-framework citation reference (NIS2, ISO 27001, DORA, NIST CSF)

    Maps evidence artifacts against NIS2, DORA, NIST CSF 2.0, and ISO 27001 citations using a real Gemini-assisted call. AI-generated draft output — review before relying on it for an actual audit. Fails honestly if the AI service is unavailable.

  • ENG-06Live Today

    NIS2 & DORA Incident Register

    User-submitted incident records, timestamped and tracked per NIS2 Article 23 24h/72h notification guidance

    Log real incidents and track them against NIS2 Article 23 24h/72h notification guidance. Empty until you create an incident.

  • ENG-07Live Today

    Third-Party Vendor Registry

    Flat vendor registry: criticality, category, and compliance status per vendor you add

    A flat registry of the vendors you add, with criticality and compliance status. Not a recursive sub-processor or 4th-party dependency graph — that mapping is roadmap.

  • ENG-08Live Today

    HMAC-SHA256 Report & Evidence Chain

    H_k = HMAC-SHA256(H_k-1 ∥ LinkType ∥ RefID ∥ TenantID ∥ ContentHash ∥ Timestamp)

    Live for assessment/report version history, evidence-artifact uploads, reviewer accept/reject decisions, and authenticated cloud telemetry events (Compliance Workspace+): each new event is chained to the tenant's prior link server-side (the signing key never reaches a client), inside a tenant-scoped Firestore transaction so concurrent writes never race. One continuous sequence per tenant covers all four event types.

  • ENG-09Live Today

    Remediation Spend Optimizer

    Maximize ∑(ΔVMI_j · x_j) subject to ∑(Cost_j · x_j) ≤ Budget, x_j ∈ {0, 1}

    Live for real VMI-point allocation: an exact 0/1 knapsack, solved via bounded dynamic programming (not a greedy approximation), finds the highest-VMI-point-gain subset of your assessment's real open gaps within a budget you set. ΔVMI per gap is computed by literally re-running the same VMI formula that produces your live score, not re-derived by hand. Cost is your own estimate per gap — ENG-03 (the FAIR/Monte Carlo financial-loss engine) is live now too, but the two aren't wired together yet: this optimizer still targets VMI-point gain, not ENG-03's simulated €ALE.

  • ENG-11Live Today

    CRA Article 14 Reporting Register

    Per-stage elapsed time against Regulation (EU) 2024/2847 Art. 14: 24h early warning, 72h notification, then 14 days (vulnerability, from corrective-measure availability) or one calendar month (severe incident, from the submission of the 72h notification)

    Live as a private register and clock for actively exploited vulnerabilities and severe incidents in products you place on the EU market. It files nothing: no connection to ENISA, the EU Single Reporting Platform, any national CSIRT, or any market surveillance authority, and no automated submission. Every notification recorded is your own note of what you filed and when. All six stage timings are verified against Regulation (EU) 2024/2847 as published in the Official Journal of 20.11.2024 — the read corrected the severe-incident final report, which had been anchored 30 days from discovery rather than one calendar month from the submission of the 72h notification.

  • ENG-12Live Today

    DORA Register of Information Export

    Vendor registry rows projected onto 4 of the 15 templates in Commission Implementing Regulation (EU) 2024/2956: B_05.01, B_02.01, B_02.02 (one row per contract per Annex III service type) and B_06.01

    Live as a data-preparation aid: exports your vendor registry into four of the register's fifteen templates as plain CSV. It is not xBRL-CSV, is not validated against the EBA taxonomy, and cannot be filed with the Central Bank of Ireland or any other competent authority — every file says so in row 1 and carries DATA-PREP in its filename. All 45 column codes across the four templates, and all 19 Annex III service types, are verified against Annex I as corrected by the corrigendum of 19.9.2025, and independently against the EBA XBRL 4.0 taxonomy an automated submission is checked by.

  • ENG-05Roadmap

    EU AI Act 66-Node Governance & FRIA Engine

    Risk_AI = Classify(Annex III) ⊕ FRIA(Human Rights) ⊕ GPAI_eval

    Planned: automate Article 6 risk classification, Article 27 Fundamental Rights Impact Assessments, and GPAI systemic risk testing. We now hold the verified primary text of Regulation (EU) 2024/1689, so this is no longer blocked on sourcing — we are deliberately holding until the EU AI Office publishes the official FRIA questionnaire template Article 27(5) requires it to produce, rather than build our own version that could diverge from it. Not yet built.

  • ENG-10Roadmap

    WASM High-Scale SIMD Density & Offload Engine

    Barnes-Hut O(N log N) SIMD Quadtree + 2,000 Node Browser Guard

    Planned: offload large relational topology rendering into a compiled WebAssembly SIMD Web Worker for high-density graphs. Not yet built.

The 8 Domain Agents

5 agents are live today. The other 3 are a public roadmap of specialized agents we have not built yet.

5 Live · 3 Roadmap
  • AGT-01Live

    Vigilance-1

    Continuous Audit Readiness Agent

    AI-assisted summary of your real assessment findings, on request. Shows nothing before a real assessment exists.

  • AGT-02Live

    Sentinel-2

    Risk Prioritization & ROI Agent

    AI-assisted executive narrative over a real, already-solved ENG-09 remediation allocation. Never computes a euro figure or score of its own — it only narrates numbers you already computed. Shows nothing until you solve a real allocation.

  • AGT-03Live

    Guardian-3

    Incident Reporting Agent

    AI-assisted briefing over your real open incidents (ENG-06), referenced against the notification windows of the regime your own jurisdiction is under — NIS2 Article 23 in Ireland and the EU, the NIS Regulations 2018 in the UK — timing information only, never a compliance verdict. Shows nothing when there are no open incidents.

  • AGT-04Roadmap

    Prometheus-4

    EU AI Act Compliance & Model Governance Agent (Roadmap)

    Planned: audit AI model pipelines for bias controls, human oversight, and data lineage. Not yet built — depends on the roadmap ENG-05 governance engine, which is deliberately holding for the EU AI Office's official Article 27 FRIA questionnaire template.

  • AGT-05Live

    Ecosystem-5

    Supply Chain Concentration Agent

    AI-assisted narrative over your real Third-Party Vendor Registry (ENG-07): category concentration and data-access exposure computed from fields you entered. Never an automated sub-processor discovery — there is no real data source for that. Shows nothing until you have a vendor on file.

  • AGT-06Live

    Sherlock-6

    Vulnerability Triage Agent

    AI-assisted patching-priority briefing over your real, manually-logged vulnerabilities, sorted by real CVSS score and affected-asset count. No scan-feed ingestion, no asset-criticality correlation and no financial-exposure figure — none of those data sources exist yet. Shows nothing until you have a vulnerability on file.

  • AGT-07Roadmap

    Archon-7

    DSA Notice-and-Action & Transparency Agent (Roadmap)

    Planned: track illegal-content notice workflows and transparency reporting under the EU Digital Services Act. Not yet built.

  • AGT-08Roadmap

    Synthesizer-8

    Multi-Agent Coordinator (Roadmap)

    Planned: coordinate outputs across the other roadmap agents once they exist. Not yet built — there is no multi-agent orchestration or automated policy remediation today.

ENG-10 — Roadmap, Not Yet Built

Planned: High-Density Scale Guard & WebAssembly SIMD Offload

Roadmap

For very large entity/vendor graphs, we plan a tiered rendering strategy — standard client-side rendering at lower node counts, a density warning at a defined threshold, and offload to a compiled WebAssembly worker beyond that. None of this exists today; current graph views render client-side with no density guard or WASM offload.

The Sufficiency Standard

Governance Density (Sufficiency Metric)

Measuring the completeness of your defensive posture through the lens of total coverage and evidence freshness.

  • Coverage (Breadth)

    Every endpoint, server, identity directory, and cloud service must be mapped. 99% coverage is a 100% vulnerability.

    100% Asset Mapping
    Supply Chain Visibility
    Identity Perimeter
  • Depth (Evidence)

    Moving from narrative proof to technical machine verification. Metadata exports beat static PDF manuals every time.

    System Log Integrity
    Configuration State
    Upload Timestamps
  • Continuity (Time)

    Governance should be a continuous state, not an annual event. Evidence freshness now decays automatically between audit cycles; broader configuration drift detection is on our roadmap.

    Freshness Monitoring (Live)
    Persistence Check
    Drift Detection (Roadmap)
Measured, Not Assumed

Where Your Data Is Processed

Five services touch customer data. Each is named below with its region and how that was established. Two of them carry an EU commitment and three do not, soVivid Risk does not claim EU data residency — and will not until all five can. The full register, including what each service receives and the transfer safeguards, is at vividrisk.ai/subprocessors.

Firestore — europe-west1 (Belgium)

EU

Every customer record: assessments, evidence metadata, vendors, incidents, registers and logs. Moved on 2026-09-17 from europe-west2 — which is London, a third country for GDPR. 677 of 677 documents migrated with counts equal on both sides, and the London database has been deleted.

Gemini on Vertex AI — EU multi-region

EU

Cross-mapping and assistant calls. Cut over 2026-09-17 from the Developer API, which is globally routed and pinned to nothing. Google's Service Specific Terms §16 and its per-model processing table carry an EU commitment for every model used here. Prompts are not used to train Google's models, and we give no permission for them to be.

Firebase Authentication — no region available

Not EU

Email addresses and account identifiers. Identity Platform appears in none of the four lists in Google's Data Residency terms, and has never had a regionalization setting. This is not an option nobody selected — there is nothing to select.

Stripe — United States

Not EU

Receives an email address, an internal id and a plan tier. Card details go to Stripe from the checkout page and never reach our server. Its DPA §6.1 names Stripe, LLC in the United States; transfers rest on the Data Privacy Framework, EEA SCCs or the UK IDTA.

Resend — United States

Not EU

Sends the transactional email. Receives the recipient address and, where a template repeats a form back, the name and company typed into it. Its DPA §6.1 places primary processing in the United States; transfers rest on EU SCCs and Data Privacy Framework certification.

No file storage at all

EU

There is no storage bucket in this product. The Evidence Vault holds metadata about a document — its title, control mapping, dates and review decisions — and never the document itself. Keep your own copy; we could not return it.

Primary Sources, Not Paraphrase

Verified Regulatory Source Library

Every statutory figure this platform shows — like the GDPR and NIS2 fine ceilings in the Financial Loss Estimator (ENG-03) — is transcribed directly from the real, official regulation text below, not recalled from memory. This library grows as more primary sources are supplied and verified: the EU AI Act text is not yet included, so no figures from that regulation appear anywhere in the app yet.

A Deterministic Foundation for Global Enterprise

"The real advantage belongs to organizations that connect governance, risk, and compliance into a single, closed-loop, mathematically defensible execution mesh."
Sovereign Audit Readiness