For internal IT teams
Proof, not assurances.
Sooner or later somebody outside IT asks whether the basics are actually being done. An auditor, an insurer, a customer running vendor due diligence, a new CFO, the board. The honest answer is usually yes, and the difficult part is showing it. Spectra Core is where the showing lives. See how an audit runs, or browse the standards libraries it runs against. If you are in a regulated institution, start with what examiners usually ask for. If you deliver IT to other companies, the MSP view fits better.
The four situations this solves
The annual audit
An auditor asks for evidence of things that happened across twelve months. Without a running record you reconstruct the year from memory and take the screenshots that week, which is both the most stressful way to do it and the least convincing. Running the audit yourself on a schedule turns that fortnight into an export.
The cyber insurance questionnaire
Renewal forms ask whether multi-factor authentication is enforced, whether backups are tested, how quickly you patch. Ticking yes takes a minute. Being able to show the check, the date, the person and the evidence behind each yes is a different exercise, and it is the one that matters if you ever claim.
The board asking whether we are secure
It is not a question that survives a technical answer. Findings in Spectra Core carry a risk level and a plain-language rationale, and the executive summary is written for the person reading it rather than the person who did the work. You get to answer in the register the question was asked in.
The person who knew everything leaves
On a small team, most of what is known about the environment is known by one or two people. An audit history is the version of that knowledge that does not resign. It also gives the person who arrives next something better than a handover call and a folder of passwords.
Built for the size most IT departments actually are
Unlimited audits, unlimited users and unlimited custom libraries at $299 a month, or $3,229.20 a year at a 10% discount, with the $499 onboarding fee waived during early access. A two-person IT department pays what a twenty-person one pays, so nobody is left off the system to keep the bill down. If your board would rather commit for a year than run month to month, the annual term is there for that reason. One generalist can be assigned every standard and work through an audit alone; the workflow does not assume a compliance function, because most organisations do not have one.
It is deliberately not a GRC platform. Those are built for organisations with staff whose whole job is compliance. This is built for the team that has to run the network and answer the questionnaire.
The libraries internal teams start with
Active Directory Configuration and Microsoft 365 Security cover the identity questions every questionnaire opens with. Backup and Disaster Recovery covers the one the board already worries about, and Network Security covers what happens when something gets through. Four libraries is a credible first audit. All fourteen are here, and you can build your own.
Working under a regulator or an examiner?
The same product, with the evidence framed for the people who ask for it in regulated institutions. For credit unions and small financial institutions.
Bring the audit you are dreading
Twenty minutes against your own environment. We pick the library that matches what is worrying you, build the first audit with you on the call, and you keep it whether or not you sign up.