Risk module · visual summary for the board
Cyber risk analysis and document AI
Your NIS2 risk analysis, and the AI that knows your documents.
Torus runs your scenario-based risk analysis all the way to the pre-filled official ILR templates, and answers questions about your own documents, citing its sources. One instance reserved for your organisation, hosted in France.
- The four ILR NIS2 templates, pre-filled
- An instance reserved for your organisation, hosted in France
- Built by the author of the ENI book on ISO/IEC 27005
To validate
To review
Available
In drafting
Documents, analyses and deliverables in the same instance.
The problem
A risk analysis to produce, evidence to provide… and the answers scattered across your documents.
- NIS2
- DORA
- GDPR
- ISO/IEC 27001
- ISO/IEC 27005
- Internal audits
- Client requirements
NIS2 requires a risk analysis kept up to date; an audit asks for consistent policies; a client asks for evidence. The work already exists at your end, scattered across an information security policy, procedures, spreadsheets and messages. Redoing it costs more than finding it.
What Torus does
From your documents to the deliverable, without losing the source.
Torus finds the information in your knowledge bases, analyses it with specialised agents and produces deliverables your team reviews and validates.
-
Documents
Policies, procedures, contracts and case files, sorted into separate knowledge bases with their own access rights.
-
Analysis
A question, an agent or a scenario-based risk analysis: every result rests on identified sources.
-
Deliverable
A document reviewed by a human, ready for your board, an audit or the regulator.
The AI proposes, your team decides: no rating and no deliverable is validated without a human.
Risk module · cyber pack
A scenario-based risk analysis, ready for your board and the regulator.
Torus proposes scenarios fitted to your context, prepares the rating of current and target risk, then a treatment plan. Your team reviews every proposal. Deliverables come out as PDF and Excel, and the ILR NIS2 templates are pre-filled.
- A method, not a prompt. The analysis follows the principles of ISO/IEC 27005. Torus is built by Jean-Charles Pons, author of the ENI book on that standard.
- Scenarios, not an inventory. The analysis starts from risk scenarios fitted to your context, without first requiring a complete asset inventory.
- Explicit rating rules. Risk only goes down when a confirmed control or a selected measure acts on it. Accepting or transferring a risk never lowers its rating.
- Human validation. Scenarios, ratings and treatments are reviewed and validated by your team.
Sample data · the target depends on the measures selected.
Cyber pack
Cyber agents and the Risk module.
The cyber pack is added to the Torus platform. It brings agents that work on cybersecurity and data protection frameworks managed by Torus, an incident tracking space and the Risk module.
- Frameworks managed by Torus. The pack's agents work on reference bases selected and maintained by Torus, separate from your documents.
- Drafts, never decisions. Policies, procedures or gap analyses remain drafts for your team to validate.
- Optional. The pack is bought on top of the platform: without it, Torus remains fully usable on your documents.
Module
Agent
Agent
Agent
Agent
Every agent works read-only and cites its sources.
The Torus platform
Ask your documents a question. Torus answers and cites its sources.
Torus searches the knowledge bases you have access to, answers from the retrieved passages and shows its sources. It summarises, compares, extracts or prepares a draft to review.
- Your documents, nothing else. Torus answers from the authorised bases and flags what it cannot find instead of inventing it.
- Visible sources. Every answer opens a Sources panel: document, knowledge base and a short excerpt.
- AI under a ZDR contract. Only the question and the retrieved excerpts reach the model, which does not keep them.
Does our access review procedure state how often it happens and who approves it?
On frequency, yes: the procedure sets a quarterly review. Approval by the line manager is mentioned, but no document says how it is recorded. I can prepare a checklist for validation.
Visible sources · AI under a ZDR contract
Deliverables
What you can show to your board, your auditor, the regulator.
Every deliverable stays tied to its sources and to the validated revision. The files open in your usual tools.
Risk module · detailed analysis report
XLSX
nis2-scenario-analysis.xlsxRisk module · official ILR template, pre-filled
DOCX
access-control-policy.docxCyber pack · sourced draft to review
The PDF reports of a validated revision are archived exactly as they were produced: a document already handed over is never silently regenerated.
Security & data
One instance per client, hosted in France.
Using AI on sensitive documents calls for guarantees. Torus is built so that your data stays inside your instance.
01
No base, no index, no account shared with another client.
02
Instances operated by Torus at OVHcloud, in France.
03
Only the question and the retrieved excerpts reach the model, which does not keep them: that is the point of the Zero Data Retention contract.
04
Answers and deliverables remain material to check before circulation.
Demo
A demo on your documents and your risks.
We start from a real case: a question about your procedures, a risk analysis to run or a NIS2 template to prepare. You see what Torus does, and what it does not.
- A human answers
- Demo in French or English
- No commitment