Audit-grade cyber risk · on-premises
Risk numbers your auditor can re-run.
Bayescope turns the evidence in your estate into ranked, reproducible risk — and the single change that removes the most risk per euro. Deterministic mathematics, a tamper-evident evidence trail, reports a named human signs. No number is ever set by AI. Nothing leaves your building.
Illustrative. Probability shown on the full 0–100% scale, never rescaled.
The problem
Scores you can't question. Advice ranked by colour code.
Security tools give you scores you can't question, alerts without context, and advice ranked by severity label. The ones that could help most won't run where your data has to stay. And under NIS2 and DORA, it's no longer the tool's problem — management signs for the result. Bayescope exists so that what you sign is something you can defend: every number walks back to its evidence, every decision to a named person.
How Bayescope thinks
Bayesian updating, Monte Carlo simulation, and the theory of constraints — decades-old, unglamorous, auditable mathematics, pointed at your security.
It observes what's true today, finds what doesn't fit, names the one constraint that shapes everything, learns from how real attacks have unfolded, and ranks what's most likely to happen to you — updating as the evidence changes.
Observe
Build a live model of the environment — assets, identities, controls, exposure.
Detect anomalies
Find what doesn't fit the expected shape of a healthy environment.
Binding constraint
Name the chokepoint that shapes everything — the single point of most leverage.
Adapt analogues
Draw on real historical incidents as structural templates, not predictions.
Generate scenarios
Instantiate attack campaigns against this environment, staged end to end.
Rank by Monte Carlo
Simulate thousands of runs; rank by likelihood with confidence intervals.
Act
Recommend the change that reduces the most risk per euro — with the delta shown.
Update
New evidence moves the posteriors. The loop closes, and stays honest.
The loop closes — and stays honest.
Shows its work
The security analysis you can cross-examine.
Pick any probability. Walk it back to the evidence that produced it, the prior it started from, and every update along the way. Defensible to your board, your auditor, and yourself.
Binding constraint: phishing-resistant MFA on remote access — the single change that most collapses the attacker's viable paths.
Illustrative. Full 0–100% scale, never rescaled to flatter the data.
Leverage & sovereignty
Not every risk is worth fixing first.
Bayescope simulates thousands of attack scenarios drawn from real historical incidents, finds the binding constraint that most reduces your risk, and tells you the single change with the biggest effect — with confidence intervals, not guesswork.
Every simulation stores its seed and full input state. Given the same inputs, the result is bit-identical — reproducible for you, your auditor, and next quarter's you.
On-premises. Fully air-gapped. Local AI inference.
The entire analysis engine works with zero data leaving your building — built for regulated, sovereignty-sensitive organisations that cloud-only tools can't serve. Only the AI layer is optional, and it runs a model inside your install.
Regulation
Built for the 2026–27 audit cycle.
NIS2 is no longer a directive on the horizon; it is national law with auditors attached. Slovakia's Act 366/2024 puts essential entities on a recurring certified-audit cycle under SNAS-accredited auditors. Czechia's Act 264/2025 took effect on 1 November 2025 with an independent cybersecurity auditor role written into the decrees. DORA's Register of Information is an annual, machine-readable supervisory submission. Bayescope's regulation packs cover NIS2, DORA and twelve national transpositions — country-gated, versioned, and updated without a redeploy — and every report it signs is built to be handed to the person auditing you.
From assess to respond
One engine, one evidence base, five capabilities.
Posture & compliance
Verified-vs-attested control status — verified only with machine evidence behind it — a gap register ranked by simulated risk, and 40 controls mapped across CIS v8, NIST CSF 2.0, ISO 27001, NIS2, DORA and twelve EU national transpositions.
Investment & roadmap
Risk reduction per euro across the portfolio. The funded set, sequenced into a roadmap, with the probability delta on every initiative — and signed, white-labelled reports that export only after a named human approves them.
Adversary emulation
Seven adversary archetypes search your environment for routes to their objective — model-only, technique level, never an attack kit. Run them all and get one merged list of the closures that cut the most paths.
AI SOC analyst
Deterministic triage and case correlation with a transparent autonomy ladder — the AI recommends, the human decides, and automation is earned against measured accuracy. Proactive hunting proposes queries where you are blind, not where you are already looking.
Investigate & remediate
Tiered, approval-gated playbooks with a counterfactual pre-flight — the modelled effect shown before anyone clicks approve. Outcomes are checked afterwards, and a remediation that did not work becomes evidence like any other.
Scenarios, framework mappings and regulation packs are versioned, reviewable content — editable without a deploy, and every prior carries the source it came from. The method is the product.
Evidence in, action out
It reads the tools you already run — and writes to none of them without your say-so.
Intake is read-only and flows through one guarded path, so every source is held to the same rules. Twelve native integrations across SIEM, EDR, identity, vulnerability management, SOAR and network, with a further nineteen platforms supported by push. A control only reads verified when a machine said so; a person's word stays attested, however senior the person.
Your tools stay yours: Bayescope integrates over their APIs and bundles none of them. Anything that could change a system runs behind an approval gate, on your own tooling, and is refused outright above the tier you have authorised.
For consultants
Senior-analyst work across your whole client portfolio.
Multi-tenant console, white-label reports, and per-client pricing that grows with your practice — not your headcount. One expert, many clients, consistent quality.
Certified auditors get their own seat: read-only access to the evidence chain and pinned reviews — see below.
Illustrative portfolio — expected loss per client, riskiest first.
For auditors
Evidence a certified auditor can verify without trusting us.
Bayescope was built on the assumption that someone hostile to it will check its work. The evidence trail is append-only — enforced by the application and again by the database, so a record cannot be edited or deleted even by us — and every reasoning chain recomputes from its own prior, evidence and likelihood ratios, so a tampered trail is detectable rather than merely unlikely. Reviews pin to the exact attestation they examined and go stale when it changes. Nobody can review their own work; the schema forbids it. And a compliant review never flips a control to verified — only machine evidence does that. If you audit under Act 366/2024, Act 264/2025, NIS2 or DORA, ask us for an auditor seat. It's free, and it will make your audit shorter.
The trail is hash-chained: each entry is hashed onto the one before it as it is written, so an edit anywhere breaks every hash after it. An auditor can export a client's whole history — the trail, every Bayesian update, each cycle with the seed that produced it, the assumption register and the control verifications — as a signed package, and check it with the verifier that travels inside it: standard-library Python, no installation, no network, and a non-zero exit if one byte moved. The signature proves the package came from that installation. It is not our word for the contents, and it is deliberately not a vendor counter-signature: the software runs on your hardware, and we are not in the loop of your audit.
See Bayescope reason through your environment.
Book an audit-grade assessment. In four to six weeks you get a ranked, evidence-backed analysis, a funded roadmap, and a signed report — and you'll understand exactly how every number was produced, because you can re-run it.