Now building — early access

Prove what works.

Turn activity across Jira, Entra, GitHub, cloud and more into verifiable control evidence — automated, continuous, and ready before the auditor asks.

Pre-launch. We're building the first version now with a handful of design partners.

The problem

The evidence already exists. It's just scattered.

ISO 27001, NIS2, DORA, ISAE 3402, SOC 2 — and the security questionnaire that lands in your inbox every time a customer's procurement team gets nervous. Someone on your team is still doing this by hand:

Jira / JSM Confluence Microsoft 365 Entra ID GitHub ServiceNow Azure / AWS Backups SIEM
  • Collecting screenshots for the auditor's evidence pack
  • Digging up the Jira ticket that proves a change was approved
  • Checking whether access reviews actually happened this quarter
  • Finding incident evidence after the fact, from memory
  • Confirming backups were tested — not just scheduled
  • Reviewing which privileged accounts still make sense
  • Chasing suppliers for their latest security review
  • Answering the same 200-question security spreadsheet, again
How it works

Kildana watches the systems you already use, and turns activity into evidence for the controls you define.

01

Connect

Point Kildana at Jira/JSM, Microsoft 365 & Entra, and GitHub to start. Everything else comes in as evidence uploads or via API.

02

Define your controls

Plain rules, in your words — "privileged production changes must be approved and traceable" — mapped to where the evidence actually lives.

03

Continuous monitoring

Kildana checks controls on a schedule, not once a year — so drift gets caught in weeks, not at the next audit.

04

Evidence on demand

"Prepare evidence for ISO 27001 A.8.8, Q3." A portal your auditor can use — not a folder of screenshots.

flowchart LR
  A["Jira change"] --> B["Approval"]
  B --> C["Git commit"]
  C --> D["Deployment"]
  D --> E["Who performed it"]
  E --> F["Production system"]
  F --> G["Control: Change Management
Evidence available"]
Not a black box

AI interprets the evidence. It is never the evidence.

DETERMINISTIC

What stays a plain system check

  • MFA enabled — read straight from the identity provider
  • Access revoked within 24 hours of offboarding — timestamps
  • Change approved before it was executed — timestamps
AI-ASSISTED

What actually needs judgment

  • Does this ticket demonstrate the rollback plan was tested?
  • Does this policy satisfy what the framework requires?
  • Explaining why a control shows a gap — not just that it does
CONTROL DRIFT — LAST 30 DAYS
  • 7 production changes had no documented rollback plan
  • 2 privileged accounts have not been reviewed this quarter
  • 4 terminated users retained access for more than 24 hours
  • Backup test evidence is missing for one customer environment
  • A supplier security review expired 42 days ago
Starting narrow, on purpose

Five controls, done properly, beats fifty done badly.

V1 CONTROLS
Change management Privileged access User onboarding / offboarding Patch & vulnerability management Backup & restore testing
V1 INTEGRATIONS
Jira / JSM Microsoft 365 & Entra GitHub + manual / API evidence for the rest
Who it's for

Built for the team that keeps getting asked to prove it.

Not enterprise banking procurement — the companies that sell to them, and to regulated customers generally, and are tired of assembling proof by hand.

SaaS companies, 20–500 peopleGrowing fast enough that "we'll just remember" stopped working a while ago.
MSPs & IT outsourcersProving control over environments you manage for someone else.
Cloud & infrastructure providersWhere "show us your change process" is a recurring customer request.
Fintech suppliersFeeling DORA and NIS2 land on your desk even though you're not the bank.
Cybersecurity companiesWho should not be the ones caught without their own evidence.
Suppliers to banks & public sectorAnswering the same security questionnaire for the fifth time this year.
ISO 27001 SOC 2 NIS2 DORA ISAE 3402

Kildana produces evidence for these frameworks — it doesn't replace your auditor or certify you. Think of it as the thing that makes the next audit take days, not weeks.

Early access

We're looking for a handful of design partners.

If you're assembling audit evidence by hand right now — for ISO 27001, SOC 2, a customer questionnaire, or anything else — we'd like to build this with you, not just for you.