Kim's Unified AI Cyber Security and GRC ToolSign in

CBB Bahrain · VARA Dubai · PCI DSS · ISO 27001 · ISO 42001

Stop keeping five trackers. Assess once, prove it across every rulebook.

One workspace for the CBB and VARA rulebooks alongside PCI DSS, ISO 27001 and ISO 42001 — 13 libraries, every control mapped, cross-referenced and tracked for your whole team.

Built for banks, virtual asset firms, stablecoin issuers, fintechs and the consultancies that advise them.

Kim's Unified AI Cyber Security and GRC Tool

2,098
controls documented
496
cross‑standard mappings
13
rulebooks and standards unified

No charge for 7 days. Cancel before the trial ends and nothing is taken. Already have an account? Sign in.

What changes

One workspace instead of five trackers

Before

  • A separate spreadsheet for each rulebook and standard
  • The same control answered differently in three places
  • Evidence scattered across mailboxes and shared drives
  • Cross-mapping done by hand, and out of date the day after
  • No single answer to “where are we?” before a board meeting
  • Audit season spent rebuilding the pack from scratch

After

  • One workspace covering every rulebook and standard you hold
  • One verdict per control, carried to its equivalents automatically
  • Evidence attached once, following the crosswalk to every linked control
  • The mapping shipped with the product and maintained for you
  • A live dashboard, by standard and by category, at any moment
  • A board-ready PDF and an evidence pack in two clicks

See it

The product, not a mock-up

Screens from a live workspace mid-assessment.

Product tour
A live workspace: the dashboard by rulebook and by category, the crosswalk, and the category rollup.
Overview dashboard
Overview dashboardProgramme-wide progress, a compliance pie per rulebook and a category breakdown — live, with no configuration.
Crosswalk
CrosswalkOne real-world control across the standards that share it. Set the status once and the linked clauses follow.
Category rollup
Category rollupEvery control by theme, with the rulebooks and standards covering each one — where a single assessment does double duty.

Who it is for

Built for the teams that carry the obligation

Banks and financial institutions

Hold CBB Rulebook Volume 6 alongside your ISO 27001 programme without running two trackers, and show the regulator the same answer you show the board.

CASPs and virtual asset firms

CBB CASP and the VARA Dubai rulebooks — Company, Compliance & Risk, Technology, Market Conduct, Exchange, Broker-Dealer, Custody and VA Issuance — as pre-loaded control libraries with scope and evidence per control.

Stablecoin issuers

The CBB Stablecoin Issuer Module and VARA VA Issuance side by side, with PCI DSS for the card rail, so a single assessment covers the regimes you actually operate under.

Fintechs and payment companies

PCI DSS v4.0.1, ISO 27001 and the CBB requirements in one place, with the overlap between them mapped rather than re-answered.

Consultancies and advisers

A separate workspace per client, each billed and isolated on its own, and reports that carry your client's branding rather than ours.

Why it is different

Not another control spreadsheet with a login

  • Regulatory rulebooks and international standards in one library — most tools give you one or the other.
  • Built for the GCC: CBB Bahrain and VARA Dubai are first-class libraries, not a custom framework you have to type in yourself.
  • A real crosswalk, not a theoretical mapping — clusters taken from published cross-reference tables, so one verdict carries to the equivalent clause in the other standards.
  • Evidence follows the map. Attach a file once and it appears on every linked control.
  • Baseline push: work your strongest framework end to end, then apply it across the crosswalk in a single action. Manual overrides are preserved.
  • Multi-tenant SaaS with database-enforced isolation, mandatory two-factor authentication, and no card data on our servers.
  • White-label reporting: your logo, your header and footer, on every page.

Who built it

Founder-led, practitioner-built

Kim

“I built this after years of running the same controls through a different spreadsheet for every framework, rulebook and standard. It is designed, maintained and supported by me, from the Kingdom of Bahrain.”

Kim · kim_abdalian@yahoo.com

Pricing

Priced per seat, with nothing held back

$833

per seat / year

  • 3-seat minimum — $2,499 for the first year
  • Add or remove seats one at a time, pro-rated
  • Seats reassignable for the whole term
  • 7-day free trial, cancel any time
  • Every feature included — no tiers, no add-ons

What it replaces

  • The five-to-seven spreadsheets one programme usually runs on
  • The hand-built cross-mapping between them, and the drift that follows
  • The scramble to assemble an evidence pack at audit time
  • The 496 shared requirements you would otherwise map by hand

Security & architecture

Built to be looked at by the people you answer to

Tenant isolation in the database

Every row carries an org id and PostgreSQL Row-Level Security enforces it. A query that forgets the filter returns nothing, not someone else's data.

Evidence in a private bucket

Never public. Files are served through signed URLs that expire in 60 seconds.

Encrypted in transit and at rest

TLS 1.2 or better on the wire, AES-256 at rest.

Two-factor authentication, mandatory

Every account, no exception, with a 30-minute idle timeout and 90-day password rotation.

Backed up daily, with point-in-time recovery

So a bad afternoon is recoverable, not a rebuild.

Hosted in the EU

Frankfurt (eu-central-1). Evidence and assessment data stay in the region.

Sessions end on their own

A 30-minute idle timeout, shared across open tabs, so an unattended screen does not stay signed in.

No card data on our servers

Payments are taken by Lemon Squeezy as Merchant of Record, which also handles global VAT and sales tax.

Read the full security policy →

Questions

Asked before you have to ask them

Do you cover the VARA rulebooks?

Yes — all eight: Company, Compliance & Risk Management, Technology & Information, Market Conduct, VA Exchange Services, VA Broker-Dealer Services, VA Custody Services and VA Issuance, at the 19 May 2025 version.

Are the CBB and VARA rulebooks crosswalk-linked to the standards?

Deliberately not. The clause-level crosswalk covers PCI DSS, ISO 27001 and ISO 42001, where published cross-reference tables exist. Linking a regulator's rulebook to a security standard on a shared category alone would mark one framework compliant on another's evidence — exactly what an auditor would challenge. The cross-regime view is on the Category rollup instead, where a category spanning CBB, VARA and ISO 27001 shows the combined count.

How is evidence stored?

In a private bucket, never public. A file is served through a signed URL that expires in 60 seconds, so a copied link is useless a minute later. Attach a file to one control and it appears on every crosswalk-linked control in the other standards, tagged with where it came from; remove it once and it is gone everywhere.

Can we export everything?

Yes, and without asking us. A board-ready PDF, a CSV of any selection of standards, and an evidence pack as a ZIP with every attached file foldered by standard and control plus a manifest. There is no lock-in: your assessment data leaves in open formats whenever you want it.

How does tenant isolation work?

Every row carries an org id and PostgreSQL Row-Level Security enforces it in the database, not in application code. A query that forgets the filter returns nothing rather than someone else's data. Server Actions re-check role and membership on every write.

What happens when a standard is revised?

The control library is reference data maintained centrally and shipped to every workspace. Your statuses, notes and evidence are yours and are never touched by an update.

What if someone leaves?

Seats are reassignable for the whole term. Remove a member and the seat frees immediately for the next person, at no extra cost.

Start with your strongest framework. The rest follows.

7 days free with every feature on. Work one standard end to end, push it across the crosswalk, and see the others move.

Prefer to talk first? kim_abdalian@yahoo.com · WhatsApp +973‑3671‑9993

Made in Bahrain · Serving the GCC and beyond · Founder-led, practitioner-built

Covering: PCI DSS v4.0.1 · ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · CBB Bahrain - Crypto-Asset (CRA) · CBB Bahrain - Stablecoin Issuer (SIO) · VARA Company · VARA Compliance & Risk · VARA Technology & Information · VARA Market Conduct · VARA VA Exchange · VARA VA Broker-Dealer · VARA VA Custody · VARA VA Issuance.

© 2026 Kim. All rights reserved.

Kim's Unified AI Cyber Security and GRC Tool” and its structure, control taxonomy, category framework, and cross‑standard crosswalk mappings are the proprietary intellectual property of Kim. Unauthorized copying, reproduction, distribution, sublicensing, or resale — in whole or in part — is strictly prohibited without prior written consent. Access is licensed, not sold, subject to the accompanying End User Licence Agreement.

Contact Kim · kim_abdalian@yahoo.com · +973‑3671‑9993

Pricing · Terms of Service · Privacy Policy · Refund Policy · Security Policy