Skip to content

Launch daySastrum is generally available today.Book a guided demo

Governance, turned into operational intelligence.

Sastrum is the GRC platform for regulated enterprises. Scope your risk universe in minutes, let Lumina draft the controls and policies, and keep a named maker and checker on every decision — across governance, compliance, audit and incidents.

More tools, less visibility.

The problem.

  1. 01Regulations change faster than teams can read them.
  2. 02Evidence is stale by the time it is collected.
  3. 03Policies sit in PDFs, disconnected from the controls they govern.
  4. 04Nine tools produce nine versions of the truth, and the board still gets a heat-map it cannot act on.

From scope to signed policy

From a blank tenant to an approved policy, in one flow.

One real risk from the Indian banking universe, traced through the platform. The workflow is the product.

Sample organisation
  1. 01

    Tell Sastrum who you are.

    Seven steps: industry, sector, sub-sector, presence, jurisdictions, frameworks, profile. Lumina prunes the risk universe to what applies: here, 35 risks across six categories for a mid-size bank regulated by RBI, SEBI, CERT-In and MeitY.

    Lumina · Risk Universe builderUniverse

  2. 02

    Onboard the risks that matter.

    Each catalogue risk carries inherent and residual ratings, its framework drivers and a four-pillar view: governance, technical, people, physical.

    Risk CatalogTable view

  3. 03

    Lumina suggests controls; you accept or reject.

    For RSK-4012 ransomware, the accepted set included endpoint application whitelisting, secure endpoint storage, an advanced ransomware training programme and a governance framework: one per pillar, each logged.

    Lumina · AI Suggest ControlsRSK-4012

  4. 04

    A governance gap becomes a drafted policy.

    Policy Studio drafts one policy against a risk and its gap control, with a reasoning summary citing the clauses it relied on. Policy Factory does the same in batches.

    Governance · PoliciesPOL-AI-010

  5. 05

    Nothing is published without people.

    Preview

    Maker, Checker, Head of Department, Strategic Director. Each stage sees the history, the AI rationale and the linked risks, with an SLA clock.

    Approval InboxPOL-AI-010

  6. 06

    Controls are watched, not just filed.

    Preview

    Control tests by pillar, a live event feed, and a regulatory watch that turns a new circular into a triage queue with the affected policies and controls.

    Real-time Control Tests · Regulatory WatchLive feed

The same flow, recorded

See it running.

Five moves through the platform, taken from product recordings of the sample organisation. Nothing is re-created: these are the screens as they behave.

  1. Scope & Risk

    Risk Universe

    The applicability scope is answered step by step — industry, sector, presence, regulators — and the risk catalogue narrows to what applies.Sample organisation
  2. Policy

    Policy Factory · Batch drafting

    Selected risks are de-duplicated by policy archetype, then drafted in parallel. Finished drafts land in Policy Studio for review.Sample organisation
  3. Lumina

    Lumina · AI Suggest Controls

    Lumina proposes a control bundle across all four pillars and shows the reasoning behind it. Each suggestion is accepted or rejected by a person.Sample organisation
  4. Controls & Frameworks

    Control Mapping · Approval Workflow

    The drafted policy is mapped to the controls it governs and to the framework clauses each provision satisfies, then routed through maker, checker, head of department and director.Sample organisation
  5. Monitor

    Real-time Control Tests

    Mapped controls run on a schedule and report back by pillar, each with its own run history, source and current state.Sample organisation

One foundation. Four modules. Lumina across all of them.

Governance is the foundation: frameworks, one control library organised by four pillars, and policies. Compliance, Audit and Incident Management run on top of it. Lumina — Sastrum's AI layer — scopes the risk universe, suggests controls and drafts policies into the same records. Assurance and Risk Appetite are add-on modules.

Explore the platform
SastrumGovernanceControl Repository

Governance

Control Repository

158

Controls

111

Key controls

53

Implemented

ControlTitleStatusFw
CTL-G-0101Access Control PolicyNot implemented4
CTL-G-0102Information Security Master PolicyImplemented3
CTL-G-0104Incident Response PolicyImplemented1
CTL-G-0105Third-Party Risk Management PolicyPartial2
CTL-G-0110Business Continuity & DR PolicyImplemented2

Built the way a regulator reads it.

  1. 01Four-stage approvalsMaker, Checker, Head of Department, Strategic Director, each with history and an SLA clock.
  2. 02Immutable audit trailEvery recorded change, filterable by module, event, actor and date. AI requests are logged too.
  3. 03Granular role permissionsNine permission areas; system and custom roles from a permission matrix.
  4. 04Separation of dutiesConflict rules configured in the browser and enforced on the records they govern.

Risk content mapped to the frameworks your regulator names

  • In product
  • Content pack

IndiaMapped on catalogue risks

  • RBI CSF
  • SEBI CSCRF
  • CERT-In
  • DPDP
  • MeitY
  • PCI-DSS
  • ISO 27001
  • NIST CSF

MalaysiaShips as a content pack

  • BNM RMiT
  • Shariah governance
  • PayNet
  • PDPA
  • Basel II event types

FrameworksSecurity & Trust

One platform, five conversations.

01 · CISO

Scope the risk universe to your regulators and get a four-pillar control set, not a blank spreadsheet.

SeesRisk CatalogControl Repository

Lumina · Risk MetaverseRisk Catalog

Lumina · Risk Metaverse

Risk Catalog

  • 35 risks · six categories
  • Inherent and residual ratings
  • Framework drivers per risk
GovernanceControl Repository

Governance

Control Repository

  • 158 controls · 111 key
  • Four-pillar codes CTL-G/T/P/Y
  • Framework count on every control

Configure, don’t code

Your administrators change it. Not your vendor.

Dashboards, report templates, forms, notification templates, taxonomies, review chains (with presets), surveys and separation-of-duties rules are configured in the browser, and every change is logged.

Controls
158
Key controls
111
Control pillars
4
Permission areas
9
Permissions, admin role
625
Starting risk universe
35

Structural figures read from the application, 18 Sep 2026. Not outcomes.

ConfigureTemplatesEvery change logged to the Audit Trail
  • DashboardsDashboard manager
  • Report templatesGeneration on every register
  • FormsMulti-step, tabbed
  • Notification templatesPer event
  • TaxonomiesConfigurable entities
  • Review chainsPresets · SLA escalations
  • SurveysTemplates and instances
  • Separation of dutiesConflict rules

Lumina drafts.
People sign.

Lumina is Sastrum’s AI layer. It scopes your risk universe, proposes controls across governance, technical, people and physical pillars, and drafts policies with the clauses it relied on. Every suggestion is accepted or rejected by a named person and logged. You choose the models: cloud, on-premise, or a hybrid that keeps sensitive tasks inside your perimeter.

See Lumina
01 SUGGESTAI Suggest ControlsRSK-4012

Ransomware attack on branch endpoints. One suggestion per pillar, against the frameworks in scope.

  • TEndpoint Application WhitelistingTechnical · CTL-TAccepted
  • YSecure Endpoint Storage and HandlingPhysical · CTL-YAccepted
  • PAdvanced Ransomware Training ProgrammePeople · CTL-PAccepted
  • GRansomware Risk Governance FrameworkGovernance · CTL-GAccepted

The accepted set recorded in the application for RSK-4012. Each decision has its entry in the log.

03 LOGAI Copilot Activity
  • Control accepted: Endpoint Application WhitelistingNamed person · RSK-4012Accepted
  • Control accepted: Secure Endpoint Storage and HandlingNamed person · RSK-4012Accepted
  • Control accepted: Advanced Ransomware Training ProgrammeNamed person · RSK-4012Accepted
  • Control accepted: Ransomware Risk Governance FrameworkNamed person · RSK-4012Accepted

Bring your own modelAnthropicOpenAIGoogleOllama / vLLM (on-premise)

Presets: On-prem only · Hybrid · Cloud-first. Per-task routing across policy drafting, control suggestion, control effectiveness, dashboard insights and embeddings. Keys encrypted at rest, masked on screen. Every AI request audited.

Deployed your way.

  1. 01SaaS with pre-configured defaultsA fast start on Sastrum-managed infrastructure.
  2. 02SaaS with configurationTailored to your programme and organisation structure.
  3. 03Single-tenant or on-premiseFull control and data residency, including on-premise AI models.
Alongside the platformVirtual CISOManaged GRCContent Subscription

Proven with a national bank. Built as a product for every regulated sector.

Developed with an anchor bank against 273 tendered requirements, and delivered as a sector-agnostic platform: the same product already carries Indian and Malaysian regulatory content. Tell us your sector and regulators and the demo opens with a universe that is already yours.