SEAM

Active
cyber riskcomplianceknowledge graphsISO 27001Neo4j

Most compliance work still lives in spreadsheets: static snapshots of controls, evidence and findings that go stale the moment they're saved. SEAM takes a different approach — modelling the organisation, its systems, controls, risks and audit findings as a graph (Neo4j, with a temporal layer), so questions like "what does this finding actually touch?" or "how has this risk moved over the year?" become queries rather than archaeology.

Around the core platform sit companion tools:

  • AuditPrep — audit preparation and self-assessment across ISO 27001:2022, Cyber Essentials, ISO 9001 and ISO 14001, with control ratings, justification notes and exportable evidence packs.
  • SecScan — a Dockerised multi-language static analysis framework feeding code-level findings into the graph.
  • OrgGraph — organisational mapping as a socio-technical substrate, including work on LLM evaluation architecture aligned to ISO 42001 and EU AI Act post-market monitoring.

Supporting research includes a knowledge graph of ICO-reported breaches used to ground risk priors in real incident data, and an evaluation ontology (SHACL) for conformance findings.

If your organisation is facing an audit, building a compliance function, or wants risk reporting that reflects how things actually connect — get in touch.

← All projects