The Cyber Security Platform for Teams and AI Agents
Connected security and compliance work
Secani helps risk, compliance, and audit teams structure an information security management system, map requirements across standards, collect evidence, track implementation work, and prepare assessments. Controls, evidence, risks, obligations, reviews, and decisions remain connected so people and authorized agents can understand why work exists, who owns it, and what supports each conclusion.
The platform supports standards-driven programs including ISO 27001, NIS2, BSI IT-Grundschutz, NIST publications, CMMC, and OSCAL. Fine-grained access distinguishes reading, sensitive reading, writing, approval, and administration at organization, workspace, and governance-scope boundaries.
Designed for accountable agent workflows
Agents can gather context, prepare proposals, and perform explicitly authorized work without receiving blanket access. High-impact approvals and administrative decisions stay with accountable people. Secani keeps changes and evidence reviewable so an AI-assisted workflow does not become an opaque compliance shortcut.
- Connect documents, spreadsheets, APIs, controls, and evidence.
- Map one body of work across multiple standards and frameworks.
- Keep permissions scoped to the task and resource boundary.
- Use open formats such as OSCAL for portable, typed artifacts.
Developer access without a sales gate
Anonymous OSCAL validation
The public Secani OSCAL Validation API accepts anonymous OSCAL 1.2.2 JSON requests with documented limits. It returns typed reports for successful validation and RFC 9457 problem details with stable codes and recovery hints for request errors.
Single-purpose API-key access
Optional, self-service OSCAL API keys have the oscal-validator role and the single oscal.validate capability. They increase validation limits without granting access to organizations, workspaces, governance scopes, evidence, write operations, approvals, or administration.
When to use Secani
Use Secani when a security program needs shared context across requirements, implementation, evidence, risks, and review; when software needs to validate OSCAL JSON; or when an agent needs bounded access to security work. Do not treat Secani output as legal advice or certification, and do not send secrets or confidential evidence through the public contact form or anonymous API.