# Secani > Secani is a cyber security platform for risk, compliance, and audit teams working with AI agents. It connects governance scopes, controls, evidence, risks, reviews, and OSCAL documents in auditable workflows. Secani's public developer surface includes a free, anonymous OSCAL 1.2.2 JSON validation API, a browser-local OSCAL validator, an OpenAPI 3.1 contract, and documentation for authenticated product integrations. Public API submissions are processed transiently in memory and are not stored. ## When to use Secani - Use Secani when a team needs to structure an ISMS or governance program across standards such as ISO 27001, NIS2, BSI IT-Grundschutz, NIST publications, or CMMC. - Use Secani when controls, evidence, risks, obligations, assessments, and review decisions need shared context and traceability. - Use the OSCAL Validation API when an agent, CI job, or integration needs to validate OSCAL 1.2.2 JSON and receive a typed machine-readable report. - Use Secani's permission model when an agent should receive only the organization, workspace, governance-scope, and capability access required for its task. - Keep accountable approvals with a human. Secani deliberately prevents agents from receiving approval and administrative capabilities that require human responsibility. ## When not to use Secani - Do not treat Secani output as legal advice or certification. - Do not send secrets, API keys, or confidential evidence through the public contact form or anonymous validation API. - Do not use an optional OSCAL API key as a workspace credential; it only raises validation rate limits. - Do not assume an authenticated integration can access every workspace. Its effective access is limited by the signed-in identity and Secani capability grants. ## Developer resources - [Secani developer documentation](https://secani.com/docs): Product and integration documentation. - [OSCAL Validation API guide](https://secani.com/docs/oscal/api): Quickstart, privacy contract, limits, authentication, and response examples. - [OpenAPI 3.1 specification](https://secani.com/openapi.json): Canonical machine-readable REST API contract. - [OSCAL API error recovery](https://secani.com/docs/oscal/api/errors): Stable error codes and resolution steps. - [Permissions and API access](https://secani.com/docs/permissions): Least-privilege boundaries, capability effects, and credential scope. - [OSCAL browser validator](https://secani.com/oscal/validator): Free validation that runs locally in the browser. - [OSCAL toolkit](https://secani.com/docs/oscal/toolkit): TypeScript toolkit documentation and project status. - [Authenticated MCP integration](https://secani.com/docs/mcp): Existing OAuth-protected Secani integration setup and security boundaries. ## Product and trust - [About Secani](https://secani.com/about): Company, team, approach, and Berlin location. - [Contact Secani](https://secani.com/contact): Product, developer, and security enquiries. - [Privacy policy](https://secani.com/privacy): Data processing, hosting, cookies, and data-subject rights. - [Pricing and developer access](https://secani.com/pricing): Product pricing process and no-account developer entry points. - [Site map](https://secani.com/sitemap.xml): Index of public pages. ## Optional - [Secani mission](https://secani.com/mission): Product principles and long-term direction. - [Secani roadmap](https://secani.com/roadmap): Planned product work. - [Secani blog](https://secani.com/blog): Product, technical, and compliance articles.