Skip to content

Platform overview

One control library. Four modules. Lumina across all of them.

Every Sastrum module reads and writes the same records (frameworks, controls, policies, risks, evidence and tasks), so nothing is re-keyed and everything is traceable.

Controls
158
Key controls
111
Control pillars
4
Starting risk universe
35
Permission areas
9

Read from the application, 18 Sep 2026.

Module map

What each module owns, and what it writes back.

Select a module to see the records it owns and the modules it hands work to. The record layer beneath is one set of records, not five copies of it.

One shared record layer

  • Frameworks
  • Controls
  • Policies
  • Risks
  • Evidence
  • Tasks

Governance

Owns

  • Frameworks
  • Controls (158)
  • Policies
  • Taxonomies
  • SoD rules
  • Organisation

Links to

  • Lumina writes controls and policies here
  • Compliance maps obligations to controls
  • Audit scopes from controls

From scope to signed policy

From a blank tenant to an approved policy, in one flow.

One real risk from the Indian banking universe, traced through the platform. The workflow is the product.

Sample organisation
  1. 01

    Tell Sastrum who you are.

    Seven steps: industry, sector, sub-sector, presence, jurisdictions, frameworks, profile. Lumina prunes the risk universe to what applies: here, 35 risks across six categories for a mid-size bank regulated by RBI, SEBI, CERT-In and MeitY.

    Lumina · Risk Universe builderUniverse

  2. 02

    Onboard the risks that matter.

    Each catalogue risk carries inherent and residual ratings, its framework drivers and a four-pillar view: governance, technical, people, physical.

    Risk CatalogTable view

  3. 03

    Lumina suggests controls; you accept or reject.

    For RSK-4012 ransomware, the accepted set included endpoint application whitelisting, secure endpoint storage, an advanced ransomware training programme and a governance framework: one per pillar, each logged.

    Lumina · AI Suggest ControlsRSK-4012

  4. 04

    A governance gap becomes a drafted policy.

    Policy Studio drafts one policy against a risk and its gap control, with a reasoning summary citing the clauses it relied on. Policy Factory does the same in batches.

    Governance · PoliciesPOL-AI-010

  5. 05

    Nothing is published without people.

    Preview

    Maker, Checker, Head of Department, Strategic Director. Each stage sees the history, the AI rationale and the linked risks, with an SLA clock.

    Approval InboxPOL-AI-010

  6. 06

    Controls are watched, not just filed.

    Preview

    Control tests by pillar, a live event feed, and a regulatory watch that turns a new circular into a triage queue with the affected policies and controls.

    Real-time Control Tests · Regulatory WatchLive feed

The same flow, recorded in the product.

Watch the product tour

The four-pillar model

Every risk and control, seen four ways.

Sastrum codes controls by pillar, so a cyber risk is never answered by technology alone.

Control implementation status

Control Repository · 158 controls · read 18 Sep 2026

  • Fully implemented53
  • Not implemented71
  • Other statuses34

111 flagged as key controls

  1. GovernanceCTL-GPolicies, standards, committees and attestations.
  2. TechnicalCTL-TIdentity, endpoint, network, logging and cryptographic controls.
  3. PeopleCTL-PJoiner-mover-leaver, awareness, privileged-user behaviour.
  4. PhysicalCTL-YData-centre access, CCTV, vaults, visitor management.

Shared services

The workspace every module uses.

One set of working surfaces sits under all four modules, so a task raised in Compliance and a task raised in Audit are the same kind of record.

  • Task ManagementAll tasks, workflow actions, status and extensions.
  • Evidence LibraryArtefacts bound to their parent record, with retention and integrity status.
  • Knowledge BaseArticles, documents and FAQ, in the same place as the work.
  • GRC CalendarEvery module's deadlines on one calendar.
  • ReportsReport generation on every register.
  • Audit TrailEvery recorded change, filterable by module, event, actor and date.

One platform, five conversations.

01 · CISO

Scope the risk universe to your regulators and get a four-pillar control set, not a blank spreadsheet.

SeesRisk CatalogControl Repository

Lumina · Risk MetaverseRisk Catalog

Lumina · Risk Metaverse

Risk Catalog

  • 35 risks · six categories
  • Inherent and residual ratings
  • Framework drivers per risk
GovernanceControl Repository

Governance

Control Repository

  • 158 controls · 111 key
  • Four-pillar codes CTL-G/T/P/Y
  • Framework count on every control
  1. RCSA / KCSASelf-assessment campaigns by department, with a maker and multi-level review.
  2. Key Control TestsScheduled tests rated Satisfactory, Some Weaknesses or Weak, then validated.
  3. Key Risk IndicatorsThreshold or yes/no indicators with RAG status and breach alerts.
  4. Treatment Plans & AppetitePlans open when residual risk exceeds the appetite band, advisory or enforced.

Add-on modules

Assess, test, watch, treat. When you are ready for it.

Licensed per tenantLicensed per tenant and switched on without a new deployment.

Risk & Assurance add-ons

Deployed your way.

Security & Trust

  1. 01SaaS with pre-configured defaultsA fast start on Sastrum-managed infrastructure.
  2. 02SaaS with configurationTailored to your programme and organisation structure.
  3. 03Single-tenant or on-premiseFull control and data residency, including on-premise AI models.

See the platform on your own frameworks.

Tell us your sector and the regulators you answer to, and the demo opens with a universe already scoped to them.