The Deterministic Methodology of
Vivid Risk
Replacing qualitative guesswork in enterprise risk governance with deterministic scoring and AI-assisted regulatory cross-mapping — live today — plus a public roadmap of additional calculus engines and specialized agents we have not built yet.
Modern organisations do not suffer from a lack of frameworks, standards, or policies. In fact, most organisations are overwhelmed by governance expectations, compliance obligations, and external regulatory scrutiny. The fundamental flaw lies in how risk is measured.
"The problem is not governance, risk, or compliance individually — it is the absence of a deterministic mathematical bridge connecting them to live technical reality."
Governance defines policy expectations. Compliance checks external alignment at static points in time. Vivid Risk replaces subjective 1-5 questionnaires with a deterministic maturity score computed from your real answers, plus AI-assisted mapping of your evidence against multiple regulatory frameworks at once. Evidence-decay tracking, tenant-scoped report chaining, an exact remediation-spend optimizer, and a real Monte Carlo financial-loss simulation over your own estimates are live too. The GDPR (Art. 83) and NIS2 (Art. 34) statutory ceilings are now cited live alongside that simulation — see the Verified Regulatory Source Library below. The EU AI Act ceiling remains on our roadmap until its primary text is supplied and verified the same way.
The Structural Paradigm Shift
- Legacy GRC
Static annual spreadsheets, subjective 1-5 ratings & unverified self-attestations
- Vivid Mesh (Live)
Deterministic VMI calculus, AI-assisted cross-mapping, evidence decay tracking & tenant-scoped report chaining, computed from your real evidence and answers
- Vivid Mesh (Roadmap)
Continuous telemetry ingest is on our roadmap — not yet built
The Sovereign Truth Library
To eliminate technical interpretation drift, every safeguard is anchored in the Vivid Truth Library—a canonical, bi-directionally mapped knowledge graph of statutory requirements:
- EU AI Act (Regulation (EU) 2024/1689)Roadmap — not yet mapped by the cross-mapper; no verified citation set exists yet
- EU NIS2 Directive (EU 2022/2555) & DORA (EU 2022/2554)Articles 21/23, 24h/72h early warning & ICT resilience
- EU Digital Services Act (DSA - EU 2022/2065)Roadmap — Notice & Action, Article 17 Statements, EU Transparency DB are not yet built
- ISO/IEC 27001:2022 & NIST CSF 2.0Annex A controls & 6 CSF Core Functions. The Cyber Resilience Act is not mapped as a control set here — what is live is a separate CRA Article 14 reporting register (the 24h/72h/final-report clock), which files nothing with ENISA.
Severe Gaps Aren't Averaged Away
Traditional GRC algorithms linearly average all questions, allowing high scores on trivial controls (like password policy documents) to mask catastrophic single points of failure.
VMI = ((∑ w_i · s_i) / ∑ w_i) × 100 − 60×(severe gaps / severe controls) − 20×(moderate gaps / moderate controls), floor 0
Failing a critical baseline safeguard — missing MFA on external access, unencrypted cloud backups, unpatched remote code execution — costs you a share of a 60-point severe-gap budget, on top of whatever the weighted average already reflects. Moderate gaps draw on a separate 20-point budget. A severe miss therefore costs roughly three times what a moderate one does and cannot be diluted by unrelated compliant answers, which is the point of having a penalty at all rather than a plain average.
Changed 13 September 2026. This penalty was previously a flat −15 points per severe gap with no ceiling. On the control set of the time, six severe gaps produced a score of exactly 0 — and so did twenty-six, so the number stopped telling you anything below that point. Expressing the penalty as a share of the controls assessed keeps the full 0–100 range meaningful and means the score does not shift when the control set grows. Scores calculated before that date are not comparable with scores after it; a report you generated earlier will re-render under the current formula.
i ranges over the 113 questions that have an entry in the Vivid Truth Matrix — the control library that carries the regulatory citations. The other 5 questions in the assessment are still asked, and still feed evidence collection and AI-generated findings, but they contribute nothing to the VMI in either direction: answering them all "No" does not lower your score, and answering them all "Yes" does not raise it.
Every question is labelled Scored Control or Evidence & Context Only as you answer it, and your report states the same split for your own answers.
The 5 unscored questions are excluded deliberately, not pending work. Two are free text and a headcount — there is no yes/no to score. The other three ask whether you expose systems publicly, whether you use an MSP, and whether you have had incidents in the last two years. Those record your situation, not a control you have implemented, and the engine awards full marks for "Yes": scoring them would credit an organisation for having a larger public attack surface, or for having had incidents.
Evidence as the Foundation of Trust
In statutory regulatory defense (NIS2, DORA, EU AI Act), trust does not derive from self-attestations or slide decks. It comes from real, organized technical evidence — with continuous decay tracking and cryptographic tamper-evidence now live for report versions, evidence-artifact uploads, and reviewer accept/reject decisions alike, all chained in one continuous per-tenant sequence. Continuous live-stream evidence ingest (rather than discrete upload/review events) remains on our roadmap.
- Structured Evidence (Live)
- Cross-Reg Reusable (Live)
- Continuous Decay (Live)
- Report Chain — HMAC-SHA256 (Live)
- Evidence-Artifact Hash Chain (Live)
The 10 Deterministic Computation & Scale Engines
10 engines are live and computing on your real data today. The other 2 are public roadmap — not yet built.
- ENG-01Live Today
Vivid Maturity Index (VMI) & Severe Gap Penalty Engine
VMI = ((∑ w_i · s_i) / ∑ w_i) × 100 − 60×(severe gaps / severe controls) − 20×(moderate gaps / moderate controls), floor 0
Calculates the core Vivid Maturity Index (0–100) from weighted questionnaire answers, minus a proportional penalty for the share of severe and moderate controls that came back as gaps — a cost that can’t be averaged away by unrelated compliant answers.
- ENG-02Live Today
Continuous Evidence Freshness Decay Engine
Confidence(t) = C_0 · e^{-λ(t - t_0)}, where t_1/2 = ln(2)/λ ≈ 693 hours (28.8 days)
Continuously decays evidence freshness over time from each artifact's real upload timestamp, so unrefreshed audit proof loses 50% validity every ~28.8 days — computed live, not stored, so it never goes stale itself. A real, authenticated cloud webhook event (Compliance Workspace+) that references the evidence's control ID resets this clock too, without a fresh re-upload.
- ENG-03Live Today
FAIR Monte Carlo Financial Loss Simulator
ALE = Σ LogNormal(magnitude) over Poisson(Beta-PERT(frequency)) events, 10,000 real simulated years
Live for a real loss distribution over your own estimates: a genuine 10,000-iteration Monte Carlo simulation (Beta-PERT-sampled event frequency, LogNormal-sampled loss magnitude, both calibrated from a Min/Most-Likely/Max range you enter) produces a full annualized-loss distribution — mean, median, P10/P90 — not one fabricated number. Every input is your own estimate; there is no real per-tenant financial dataset behind it. Real GDPR (Art. 83) and NIS2 (Art. 34) statutory ceilings, cited from their primary texts — see the Verified Regulatory Source Library below — are now shown as references alongside the distribution. The EU AI Act ceiling is not built in yet, pending its primary text.
- ENG-04Live Today
Multi-Framework Cross-Mapping Engine
Gemini-assisted clause mapping over a hand-curated control-to-framework citation reference (NIS2, ISO 27001, DORA, NIST CSF)
Maps evidence artifacts against NIS2, DORA, NIST CSF 2.0, and ISO 27001 citations using a real Gemini-assisted call. AI-generated draft output — review before relying on it for an actual audit. Fails honestly if the AI service is unavailable.
- ENG-06Live Today
NIS2 & DORA Incident Register
User-submitted incident records, timestamped and tracked per NIS2 Article 23 24h/72h notification guidance
Log real incidents and track them against NIS2 Article 23 24h/72h notification guidance. Empty until you create an incident.
- ENG-07Live Today
Third-Party Vendor Registry
Flat vendor registry: criticality, category, and compliance status per vendor you add
A flat registry of the vendors you add, with criticality and compliance status. Not a recursive sub-processor or 4th-party dependency graph — that mapping is roadmap.
- ENG-08Live Today
HMAC-SHA256 Report & Evidence Chain
H_k = HMAC-SHA256(H_k-1 ∥ LinkType ∥ RefID ∥ TenantID ∥ ContentHash ∥ Timestamp)
Live for assessment/report version history, evidence-artifact uploads, reviewer accept/reject decisions, and authenticated cloud telemetry events (Compliance Workspace+): each new event is chained to the tenant's prior link server-side (the signing key never reaches a client), inside a tenant-scoped Firestore transaction so concurrent writes never race. One continuous sequence per tenant covers all four event types.
- ENG-09Live Today
Remediation Spend Optimizer
Maximize ∑(ΔVMI_j · x_j) subject to ∑(Cost_j · x_j) ≤ Budget, x_j ∈ {0, 1}
Live for real VMI-point allocation: an exact 0/1 knapsack, solved via bounded dynamic programming (not a greedy approximation), finds the highest-VMI-point-gain subset of your assessment's real open gaps within a budget you set. ΔVMI per gap is computed by literally re-running the same VMI formula that produces your live score, not re-derived by hand. Cost is your own estimate per gap — ENG-03 (the FAIR/Monte Carlo financial-loss engine) is live now too, but the two aren't wired together yet: this optimizer still targets VMI-point gain, not ENG-03's simulated €ALE.
- ENG-11Live Today
CRA Article 14 Reporting Register
Per-stage elapsed time against Regulation (EU) 2024/2847 Art. 14: 24h early warning, 72h notification, then 14 days (vulnerability, from corrective-measure availability) or one calendar month (severe incident, from the submission of the 72h notification)
Live as a private register and clock for actively exploited vulnerabilities and severe incidents in products you place on the EU market. It files nothing: no connection to ENISA, the EU Single Reporting Platform, any national CSIRT, or any market surveillance authority, and no automated submission. Every notification recorded is your own note of what you filed and when. All six stage timings are verified against Regulation (EU) 2024/2847 as published in the Official Journal of 20.11.2024 — the read corrected the severe-incident final report, which had been anchored 30 days from discovery rather than one calendar month from the submission of the 72h notification.
- ENG-12Live Today
DORA Register of Information Export
Vendor registry rows projected onto 4 of the 15 templates in Commission Implementing Regulation (EU) 2024/2956: B_05.01, B_02.01, B_02.02 (one row per contract per Annex III service type) and B_06.01
Live as a data-preparation aid: exports your vendor registry into four of the register's fifteen templates as plain CSV. It is not xBRL-CSV, is not validated against the EBA taxonomy, and cannot be filed with the Central Bank of Ireland or any other competent authority — every file says so in row 1 and carries DATA-PREP in its filename. All 45 column codes across the four templates, and all 19 Annex III service types, are verified against Annex I as corrected by the corrigendum of 19.9.2025, and independently against the EBA XBRL 4.0 taxonomy an automated submission is checked by.
- ENG-05Roadmap
EU AI Act 66-Node Governance & FRIA Engine
Risk_AI = Classify(Annex III) ⊕ FRIA(Human Rights) ⊕ GPAI_eval
Planned: automate Article 6 risk classification, Article 27 Fundamental Rights Impact Assessments, and GPAI systemic risk testing. We now hold the verified primary text of Regulation (EU) 2024/1689, so this is no longer blocked on sourcing — we are deliberately holding until the EU AI Office publishes the official FRIA questionnaire template Article 27(5) requires it to produce, rather than build our own version that could diverge from it. Not yet built.
- ENG-10Roadmap
WASM High-Scale SIMD Density & Offload Engine
Barnes-Hut O(N log N) SIMD Quadtree + 2,000 Node Browser Guard
Planned: offload large relational topology rendering into a compiled WebAssembly SIMD Web Worker for high-density graphs. Not yet built.
The 8 Domain Agents
5 agents are live today. The other 3 are a public roadmap of specialized agents we have not built yet.
- AGT-01Live
Vigilance-1
Continuous Audit Readiness Agent
AI-assisted summary of your real assessment findings, on request. Shows nothing before a real assessment exists.
- AGT-02Live
Sentinel-2
Risk Prioritization & ROI Agent
AI-assisted executive narrative over a real, already-solved ENG-09 remediation allocation. Never computes a euro figure or score of its own — it only narrates numbers you already computed. Shows nothing until you solve a real allocation.
- AGT-03Live
Guardian-3
Incident Reporting Agent
AI-assisted briefing over your real open incidents (ENG-06), referenced against the notification windows of the regime your own jurisdiction is under — NIS2 Article 23 in Ireland and the EU, the NIS Regulations 2018 in the UK — timing information only, never a compliance verdict. Shows nothing when there are no open incidents.
- AGT-04Roadmap
Prometheus-4
EU AI Act Compliance & Model Governance Agent (Roadmap)
Planned: audit AI model pipelines for bias controls, human oversight, and data lineage. Not yet built — depends on the roadmap ENG-05 governance engine, which is deliberately holding for the EU AI Office's official Article 27 FRIA questionnaire template.
- AGT-05Live
Ecosystem-5
Supply Chain Concentration Agent
AI-assisted narrative over your real Third-Party Vendor Registry (ENG-07): category concentration and data-access exposure computed from fields you entered. Never an automated sub-processor discovery — there is no real data source for that. Shows nothing until you have a vendor on file.
- AGT-06Live
Sherlock-6
Vulnerability Triage Agent
AI-assisted patching-priority briefing over your real, manually-logged vulnerabilities, sorted by real CVSS score and affected-asset count. No scan-feed ingestion, no asset-criticality correlation and no financial-exposure figure — none of those data sources exist yet. Shows nothing until you have a vulnerability on file.
- AGT-07Roadmap
Archon-7
DSA Notice-and-Action & Transparency Agent (Roadmap)
Planned: track illegal-content notice workflows and transparency reporting under the EU Digital Services Act. Not yet built.
- AGT-08Roadmap
Synthesizer-8
Multi-Agent Coordinator (Roadmap)
Planned: coordinate outputs across the other roadmap agents once they exist. Not yet built — there is no multi-agent orchestration or automated policy remediation today.
Planned: High-Density Scale Guard & WebAssembly SIMD Offload
For very large entity/vendor graphs, we plan a tiered rendering strategy — standard client-side rendering at lower node counts, a density warning at a defined threshold, and offload to a compiled WebAssembly worker beyond that. None of this exists today; current graph views render client-side with no density guard or WASM offload.
Governance Density (Sufficiency Metric)
Measuring the completeness of your defensive posture through the lens of total coverage and evidence freshness.
Coverage (Breadth)
Every endpoint, server, identity directory, and cloud service must be mapped. 99% coverage is a 100% vulnerability.
100% Asset MappingSupply Chain VisibilityIdentity PerimeterDepth (Evidence)
Moving from narrative proof to technical machine verification. Metadata exports beat static PDF manuals every time.
System Log IntegrityConfiguration StateUpload TimestampsContinuity (Time)
Governance should be a continuous state, not an annual event. Evidence freshness now decays automatically between audit cycles; broader configuration drift detection is on our roadmap.
Freshness Monitoring (Live)Persistence CheckDrift Detection (Roadmap)
Where Your Data Is Processed
Five services touch customer data. Each is named below with its region and how that was established. Two of them carry an EU commitment and three do not, soVivid Risk does not claim EU data residency — and will not until all five can. The full register, including what each service receives and the transfer safeguards, is at vividrisk.ai/subprocessors.
Firestore — europe-west1 (Belgium)
EUEvery customer record: assessments, evidence metadata, vendors, incidents, registers and logs. Moved on 2026-09-17 from europe-west2 — which is London, a third country for GDPR. 677 of 677 documents migrated with counts equal on both sides, and the London database has been deleted.
Gemini on Vertex AI — EU multi-region
EUCross-mapping and assistant calls. Cut over 2026-09-17 from the Developer API, which is globally routed and pinned to nothing. Google's Service Specific Terms §16 and its per-model processing table carry an EU commitment for every model used here. Prompts are not used to train Google's models, and we give no permission for them to be.
Firebase Authentication — no region available
Not EUEmail addresses and account identifiers. Identity Platform appears in none of the four lists in Google's Data Residency terms, and has never had a regionalization setting. This is not an option nobody selected — there is nothing to select.
Stripe — United States
Not EUReceives an email address, an internal id and a plan tier. Card details go to Stripe from the checkout page and never reach our server. Its DPA §6.1 names Stripe, LLC in the United States; transfers rest on the Data Privacy Framework, EEA SCCs or the UK IDTA.
Resend — United States
Not EUSends the transactional email. Receives the recipient address and, where a template repeats a form back, the name and company typed into it. Its DPA §6.1 places primary processing in the United States; transfers rest on EU SCCs and Data Privacy Framework certification.
No file storage at all
EUThere is no storage bucket in this product. The Evidence Vault holds metadata about a document — its title, control mapping, dates and review decisions — and never the document itself. Keep your own copy; we could not return it.
Verified Regulatory Source Library
Every statutory figure this platform shows — like the GDPR and NIS2 fine ceilings in the Financial Loss Estimator (ENG-03) — is transcribed directly from the real, official regulation text below, not recalled from memory. This library grows as more primary sources are supplied and verified: the EU AI Act text is not yet included, so no figures from that regulation appear anywhere in the app yet.
GDPR — Regulation (EU) 2016/679
Cited LiveOfficial Journal of the European Union, L 119/1-88, 4 May 2016
The General Data Protection Regulation. Article 83 (fine caps: €10M/2% and €20M/4% of global turnover, whichever is higher) is the verified source for the ceiling shown in the Financial Loss Estimator.
Used for: ENG-03 statutory ceiling
NIS2 — Directive (EU) 2022/2555
Cited LiveOfficial Journal of the European Union, L 333/80-152, 27 December 2022
The Network and Information Security Directive 2. Article 34 (fine caps: €10M/2% for essential entities, €7M/1.4% for important entities, whichever is higher) is the verified source for the ceiling shown in the Financial Loss Estimator.
Used for: ENG-03 statutory ceiling
GDPR Enforcement Procedure — Regulation (EU) 2025/2518
Official Journal of the European Union, L series, 12 December 2025
Procedural rules for handling cross-border GDPR complaints and supervisory-authority cooperation and dispute resolution under Articles 60 and 65.
Background reference
ePrivacy Directive — Directive 2002/58/EC
Official Journal of the European Communities, L 201/37-47, 12 July 2002
Privacy and electronic communications directive. Its penalties are set by national law, not one harmonized EU cap — which is why it is not a source for the statutory ceiling feature.
Background reference
Law Enforcement Directive — Directive (EU) 2016/680
Official Journal of the European Union, L 119/89-131, 4 May 2016
GDPR's companion instrument covering personal data processed by police and criminal-justice authorities — not commercial data processing.
Background reference
EU Institutions Data Protection — Regulation (EU) 2018/1725
Official Journal of the European Union, L 295/39-98, 21 November 2018
Data protection rules for the EU institutions, bodies, offices and agencies themselves — not applicable to commercial entities.
Background reference
A Deterministic Foundation for Global Enterprise
"The real advantage belongs to organizations that connect governance, risk, and compliance into a single, closed-loop, mathematically defensible execution mesh."