# CATAAM > CATAAM is a unified security and compliance platform by TheMarkups Canada Inc. It combines GRC (Governance, Risk & Compliance), Internal Attack Surface Management (iASM), and Breach & Attack Simulation (BAS) in a single product. Target users: CISOs, CPA audit firms, CISO-as-a-Service resellers, and enterprise security teams. ## Product Overview CATAAM covers the full security and compliance lifecycle: - **Multi-Framework GRC**: Manage 12 frameworks from one platform — SOC 2, SOC 1, ISO 27001, ISO 42001 (AI management systems), GDPR, India's DPDP Act (Digital Personal Data Protection Act 2023), HIPAA, PCI-DSS, NIST CSF, NIST AI RMF, COBIT 5, and ITIL. Cross-framework control mapping means one control can satisfy multiple standards simultaneously, so a second framework mostly reuses evidence you already have. - **Evidence Harvesting**: Automated evidence collection from AWS, GitHub, Jira, and other integrations via configurable harvest rules. Evidence links directly to controls and requirements. - **iASM (Internal Attack Surface Management)**: Connect AWS, Azure, or GCP accounts to auto-discover cloud assets, visualize the attack surface as a force-directed graph, run security audits, and track open findings. Asset discovery and graph browsing are free; credits are consumed only on active scans. - **BAS (Breach & Attack Simulation)**: Simulate real-world adversary techniques against AWS environments and SSH endpoints. Findings map to CVEs and MITRE ATT&CK techniques. Costs 15 credits per AWS BAS run; 10 credits per SSH probe. - **External Attack Surface Monitoring (EASM)**: Subdomain discovery via certificate transparency logs, DNS health checks (SPF, DMARC, DNSSEC), open port detection, and MITRE ATT&CK mapping. - **Executive Reporting & Risk Score**: Live risk score with 90-day trend tracking, customizable report templates, and PDF export. - **Partner & Multi-Org Management**: CISO Resellers and CPA firms manage unlimited client organizations from one dashboard. Post-paid billing at $149/framework/client/month. - **Marketplace & Vendor Risk**: Discover vetted compliance service providers and run vendor risk questionnaires. ## Pricing - **GRC**: $149/framework/month — enroll in any of the 12 frameworks and pay per framework; no upfront commitment - **GRC Enterprise**: Custom pricing with white-label and partner capabilities - **Partner Billing**: $149/framework/client/month, post-paid, no upfront commitment - **iASM Credit Packs** (pay-as-you-go, priced in CAD): - Explorer: 30 credits — CA$599 - Standard: 120 credits — CA$1,999 - Professional: 350 credits — CA$4,999 - Enterprise: 800 credits — CA$9,999 - iASM exploration (asset discovery, graph browsing) is always free ## Pages - [Home](https://cataam.com/) - [Features](https://cataam.com/features/) - [Pricing](https://cataam.com/pricing/) - [Partner Program](https://cataam.com/partner-program/) - [About](https://cataam.com/about/) - [Contact](https://cataam.com/contact/) - [Business Contact](https://cataam.com/business-contact/) - [Prompt Guard (open-source LLM prompt hygiene)](https://cataam.com/prompt-guard/) - [Get Started](https://cataam.com/get-started/) - [Terms of Service](https://cataam.com/terms/) - [Privacy Policy](https://cataam.com/privacy-policy/) - [Refund Policy](https://cataam.com/refund-policy/) ## Compliance Frameworks CATAAM automates 15 compliance frameworks from one shared control set — map evidence once, satisfy many — and is the only platform that also proves the controls work with built-in attack-surface management and breach & attack simulation. Dedicated framework guides: - [SOC 2](https://cataam.com/compliance/soc2/) — AICPA Trust Services Criteria; the report US B2B buyers ask for by name - [ISO 27001](https://cataam.com/compliance/iso27001/) — certifiable global Information Security Management System - [PCI DSS](https://cataam.com/compliance/pci-dss/) — payment-card data security - [HIPAA](https://cataam.com/compliance/hipaa/) — US healthcare data protection - [ISO 42001](https://cataam.com/compliance/iso42001/) — AI management system - [DPDP Act](https://cataam.com/compliance/dpdp/) — India's Digital Personal Data Protection Act 2023 + Rules 2025 - [Essential Eight](https://cataam.com/compliance/essential-eight/) — ACSC's eight mitigation strategies scored against Maturity Levels 0–3; Australia's cyber baseline, mandatory for federal government - [Australian Privacy Principles](https://cataam.com/compliance/australian-privacy-principles/) — the 13 APPs under the Privacy Act 1988, plus the Notifiable Data Breaches (NDB) scheme; Australia's GDPR-equivalent privacy law - [APRA CPS 234](https://cataam.com/compliance/apra-cps-234/) — APRA Prudential Standard on Information Security, mandatory for Australian banks, insurers and superannuation funds Framework comparisons: [SOC 2 vs ISO 27001](https://cataam.com/compare/soc-2-vs-iso-27001/), [GDPR vs DPDP Act](https://cataam.com/compare/gdpr-vs-dpdp/), [Essential Eight vs ISO 27001](https://cataam.com/compare/essential-eight-vs-iso-27001/), [Australian Privacy Principles vs GDPR](https://cataam.com/compare/australian-privacy-principles-vs-gdpr/). Australian-market explainers: [The ACSC Essential Eight, Explained](https://cataam.com/blog/essential-eight-explained/), [The Australian Privacy Principles, Explained](https://cataam.com/blog/australian-privacy-principles-explained/), [APRA CPS 234, Explained](https://cataam.com/blog/apra-cps-234-explained/). ## Open Source CATAAM maintains a free open-source security toolkit at https://github.com/cataam-security/cataam: - Prompt Guard — local-first prompt-egress redactor for public LLMs (details below) - CIS Benchmark Linux hardening script - NVD CVE scanner - AWS CIS posture checker - TLS/SSL audit tool for PCI DSS 4.0 - ISO 27001 risk assessment template - SOC 2 Type II evidence checklist - HIPAA Security Rule checklist ## Free Tools & Templates (no signup) Interactive tools: - SOC 2 & ISO 27001 Readiness Assessment — https://cataam.com/tools/soc2-readiness-assessment/ - Essential Eight Maturity Assessment (ACSC, Australia) — https://cataam.com/tools/essential-eight-assessment/ — rate all eight strategies; overall maturity = lowest strategy (Maturity Level 0–3). - Australian Privacy Act Assessment (13 APPs + NDB scheme) — https://cataam.com/tools/australian-privacy-act-assessment/ - AI Governance & ISO 42001 Readiness — https://cataam.com/tools/ai-governance-readiness/ - Email Security Checker (SPF/DMARC/DKIM) — https://cataam.com/tools/email-security-checker/ - Compliance Cost Calculator — https://cataam.com/tools/compliance-cost-calculator/ Downloadable templates: - Essential Eight Maturity Assessment Template (CSV, all 8 strategies × Maturity Levels 1–3) — https://cataam.com/resources/essential-eight-maturity-assessment-template/ - Australian Privacy Principles Checklist (CSV, all 13 APPs + NDB) — https://cataam.com/resources/australian-privacy-principles-checklist/ - Notifiable Data Breach Response Plan (Privacy Act 1988 / OAIC four-step) — https://cataam.com/resources/notifiable-data-breach-response-plan/ - HIPAA Security Rule Checklist (Administrative/Physical/Technical safeguards, Required vs Addressable) — https://cataam.com/resources/hipaa-security-rule-checklist/ - PCI DSS Compliance Checklist (all 12 requirements, v4.0, + SAQ scoping) — https://cataam.com/resources/pci-dss-compliance-checklist/ - DPDP Act Compliance Checklist (India, Data Fiduciary obligations) — https://cataam.com/resources/dpdp-compliance-checklist/ - ISO 27001 Statement of Applicability Template (Annex A 2022, all four themes + 11 new controls) — https://cataam.com/resources/iso-27001-statement-of-applicability-template/ - ISO 27001 Risk Assessment Template — https://cataam.com/resources/iso27001-risk-assessment-template/ - SOC 2 Evidence Checklist — https://cataam.com/resources/soc2-evidence-checklist/ ## Prompt Guard (Open-Source LLM Prompt Hygiene) Prompt Guard is a free, MIT-licensed, local-first tool that detects and redacts secrets, API keys and PII from a prompt before it reaches public large language models such as ChatGPT, Claude or Gemini. The prompt is scanned on the user's own machine (nothing is sent anywhere to scan it). Redaction is reversible: each secret is swapped for a stable placeholder like «PG:AWS_ACCESS_KEY_ID:1», the model reasons over the placeholder, and the answer is re-hydrated locally — so the real secret never leaves the machine while the response stays useful. Key facts: - Coverage: a one-line terminal wrapper (promptguard wrap -- claude/llm/ollama), a block-on-secret hook for interactive Claude Code (fail-closed — a prompt containing a secret is blocked before it reaches the model), and a browser extension for ChatGPT/Claude/Gemini web. - Detects AWS, GitHub, OpenAI, Anthropic, Google, Slack and Stripe keys, PEM private keys, JWTs, high-entropy tokens, and PII (emails, credit cards, SSNs, phone numbers, private IPs). Detection rules are plain JSON and community-extendable. - AI-governance evidence: every redaction or block becomes an immutable control event (previews only, never the raw secret) mapped to ISO/IEC 42001, NIST AI RMF and EU AI Act Article 12. Pushed into CATAAM, the events latch as evidence for the "AI prompt/data egress to public LLMs is controlled" control, turning the ISO 42001 data-egress control to PASS. - Pure Python stdlib core, zero runtime dependencies, runs on a laptop. No proxy, no cloud, no account required to redact. Links: - [Prompt Guard page](https://cataam.com/prompt-guard/) - [Source code (GitHub, MIT)](https://github.com/cataam-security/cataam/tree/main/prompt-guard) - [Blog: The SOC 2 Journey, Explained — from zero to audit-ready in 9 steps (who needs it, SOC 2 vs ISO 27001 vs NIST, Trust Services Criteria selection, controls, policies, vendors, monitoring, pen testing, trust center)](https://cataam.com/blog/soc2-journey-explained/) - [Blog: Stop secrets leaking into ChatGPT & Claude — and prove it for ISO 42001](https://cataam.com/blog/prompt-guard-stop-secrets-leaking-to-llms/) - [Launch video](https://www.youtube.com/watch?v=gFAiCBClKjE) - [ISO 42001 AI Management System](https://cataam.com/compliance/iso42001/) ## Company Operated by TheMarkups Canada Inc. Headquarters: 40-5160 Explorer Drive, Mississauga, ON L4W 4T7, Canada. Contact: contact@themarkups.com Partner inquiries: partners@themarkups.com ## OKF Context Engine (AI Context Export) CATAAM exports your compliance graph as an open, portable, AI-readable bundle using Google's Open Knowledge Format (OKF) — for Claude (via MCP), auditors, and any tool. Signed point-in-time exports, no vendor lock-in. Details: https://cataam.com/okf/ - [Meet the CATAAM OKF Context Engine (explainer)](https://www.youtube.com/watch?v=dv2ljmnjuT8) - [CATAAM OKF — the first open, AI-native compliance graph](https://www.youtube.com/watch?v=g24wEe2cbHE) ## Demos & Video Tutorials Watch CATAAM in action at https://cataam.com/demos/ or on YouTube: https://www.youtube.com/@cataam-com - [Meet CATAAM (90-second overview)](https://www.youtube.com/watch?v=qKiTMCVLsUA) - [Full Product Demo (GRC, ASM & BAS walkthrough)](https://www.youtube.com/watch?v=zt6Gse08PzM) - [SOC 2 Without the Scramble — Continuous Compliance](https://www.youtube.com/watch?v=LpFnJ09HqMc) - [Breach & Attack Simulation Explained](https://www.youtube.com/watch?v=fRHigoN7yMs) - [Auto-Create Jira Issues from Findings & Failed Tests](https://www.youtube.com/watch?v=o_2lAIZmX1U) - [Generate SOC 2 Policies & Documents with Claude (MCP)](https://www.youtube.com/watch?v=sIF8RpIgK_8) - [Connect AWS, GitHub & Azure AD — Automated Evidence](https://www.youtube.com/watch?v=ze17vokwGmg) - [Meet Prompt Guard — Keep Secrets Out of Public LLMs](https://www.youtube.com/watch?v=gFAiCBClKjE)