Automated assessment intake
Use guided imports, connectors, collectors, and questionnaires to create a consistent starting point instead of a manually rebuilt spreadsheet for every customer.
MSSP, consultant, and reseller program
Manage several customer organizations from one portfolio while each customer keeps control of its evidence, encryption boundary, approvals, and access.
Risk-first managed delivery
Project X IT gives service providers a repeatable way to onboard customers, collect evidence, explain risk in business terms, generate remediation roadmaps, and keep progress visible over time.
Use guided imports, connectors, collectors, and questionnaires to create a consistent starting point instead of a manually rebuilt spreadsheet for every customer.
Prioritize findings by the function, owner, MTD, exposure, data, vendor, and operating cost they affect, so executives see decisions instead of raw tool output.
Convert gaps into owner-assigned work, evidence requirements, retest expectations, due dates, risk decisions, and recurring service opportunities.
Reuse the same evidence across NIST CSF, SOC 2 Type 2, ISO 27001, privacy, continuity, and customer-defined requirements without pretending one checklist proves security.
Map vendors to functions, systems, data, contracts, spend, assurance reports, exceptions, and accountable business owners.
Where approved, automation can accelerate summaries and remediation drafting, but customer evidence remains protected, server-authorized, and reviewable before decisions are accepted.
A repeatable service model
Small businesses often lack complete inventories, role maps, system security plans, BIAs, and control evidence. The Workbench gives your team a guided way to reverse engineer that picture and keep it current.
Collect accounts, groups, privileged access, jobs, software, services, ports, login sources, network flows, cloud resources, vulnerabilities, devices, applications, databases, and data hints.
Connect people, positions, departments, executive ownership, business functions, allocations, systems, permissions, vendors, costs, dependencies, and sensitive data.
Document MTD, RTO, RPO, financial exposure, operational consequences, threat scenarios, control coverage, materiality, and accountable risk decisions.
Turn the observed baseline into an owner-approved target for least privilege, segmentation, secure configuration, recovery, staffing, and continuous monitoring.
Generate policies, procedures, reports, evidence packages, framework maturity views, and a defensible record of adherence and exceptions.
Request exact customer access and let the customer approve the role, scope, and expiration. Platform and customer authorization are enforced by the server on every request.
Law firms and breach counsel can coordinate separately scoped client assessments for healthcare organizations following incidents, alleged HIPAA violations, or regulatory inquiries. Each client remains isolated and controls access. The platform supports evidence and risk assessment; it does not determine legal compliance, create privilege, or provide legal advice.
How it works
Commercial fit
The partner model is designed for portfolios of smaller customers while preserving direct enterprise pricing for larger organizations.
Affordable flat customer-workspace basis intended for consultant and MSSP delivery.
Contracted employee-band pricing with partner eligibility and scoped service delivery.
Pricing uses the customer's total employee count and contracted scope, even when a consultant participates.
Final pricing, partner terms, and service scope require a written agreement. Customer evidence access is never created by payment or partner status alone.
Start a partner trial
After signup, continue to the authenticated Consultant Portal, open Account Settings, and verify a TOTP authenticator before future logins enforce MFA.
Production launch will also require verified email delivery, executed partner terms, billing enrollment, and the production controls documented in the assurance guide.