Live Assessment
FAILMFA not enforced on 34 admin accounts · Priority: CRITICAL · Remediation: 2 hours WARNPatch cycle: 47 days avg · Benchmark: 14 days · 23 critical CVEs unpatched PASSEndpoint encryption: 98% coverage · BitLocker/FileVault deployed · Compliant FAILBackup testing: Last tested 8 months ago · RTO not validated · Risk: HIGH FAILMFA not enforced on 34 admin accounts · Priority: CRITICAL · Remediation: 2 hours WARNPatch cycle: 47 days avg · Benchmark: 14 days · 23 critical CVEs unpatched PASSEndpoint encryption: 98% coverage · BitLocker/FileVault deployed · Compliant FAILBackup testing: Last tested 8 months ago · RTO not validated · Risk: HIGH
AI Powered Full Stack Cyber Resilience
Gordon Security Checklist · by Mitigata

We Automate Your Audits.
So You Never Miss a Deadline.

Gordon AI generates every compliance document your auditor needs — in under 60 seconds. Pick your certification, pick a control area, and you're done. Stop drowning in spreadsheets and manual evidence collection. Start automating your entire compliance journey with Gordon AI.

Comprehensive Security Checks — automated assessment across all key security domains
Industry Framework Benchmarking — mapped to NIST, ISO 27001, CIS Controls, and Indian regulations
Prioritised Remediation Roadmap — actionable plan with effort estimates and owner assignments
60
Security checks
8
Security domains
<24 hrs
Full report
Gordon Security Checklist — Score Dashboard
ASSESSING
Platform Capabilities

Know where you stand.
Fix what matters most.

60-Point Automated Assessment

Gordon runs Comprehensive Security Checks — automated assessment across all key security domains: Identity & Access, Endpoint Security, Network Security, Data Protection, Incident Response, Backup & Recovery, Cloud Security, and Security Awareness. Each check is scored and benchmarked against industry standards.

Framework Benchmarking

Every check is mapped to NIST CSF, ISO 27001, CIS Controls, and Indian regulatory frameworks (RBI IT, SEBI, IRDAI, DPDP Act). See exactly which framework controls you pass, fail, or partially meet — with evidence for auditors.

Prioritised Remediation Roadmap

Failed checks are ranked by risk impact and remediation effort — so you always know what to fix first. Each remediation item includes step-by-step instructions, estimated effort in hours, and the risk reduction value of fixing it.

Continuous Monitoring

Gordon re-runs the assessment automatically every 30 days — tracking your security score over time, alerting you when scores drop, and showing the improvement trend as you remediate issues. Your security posture is never stale.

Board & Audit Reports

Generate board-ready security posture reports and audit-ready evidence packs in one click. Reports include your overall security score, domain-by-domain breakdown, trend over time, and comparison against industry peers in your sector.

Peer Benchmarking

See how your security score compares to other organisations in your industry, revenue band, and geography. Understand whether you are above or below the median for your sector — and what the top-quartile organisations do differently.

How It Works

Connect. Assess. Score. Fix.
In under 24 hours.

LIVE 60-POINT ASSESSMENT — SECURITY DOMAIN PROGRESS
SCANNING
Critical gap (<40)
Needs work (40–69)
Good (70–89)
Excellent (≥90)
01

Connect Your Environment

Gordon integrates with your Microsoft 365, Google Workspace, AWS, Azure, and GCP environments via read-only API connections. No agents to install, no firewall changes required. Setup takes under 30 minutes.

02

Automated Assessment Runs

Gordon automatically runs all 60 checks against your connected environment — checking MFA status, patch levels, backup configurations, encryption settings, access controls, and more. No manual questionnaires to fill in.

03

Score & Benchmark

Results are scored on a 0–100 scale across 8 domains. Your overall security score is benchmarked against industry peers, regulatory requirements, and best practice frameworks. You receive a full report within 24 hours of connecting.

04

Fix & Track Progress

Work through the prioritised remediation roadmap. Gordon automatically detects when you fix an issue and updates your score in real time. Track your security improvement journey with month-over-month trend charts.

Real-World Impact

Assessed. Scored.
Significantly improved.

FINTECH

RBI Audit Passed First Time

CHALLENGE

A payment gateway company had an RBI IT framework audit in 90 days. Their CISO had no clear picture of their current compliance posture and was worried about failing the audit.

OUTCOME

Gordon's assessment revealed 23 gaps against RBI IT framework requirements. The prioritised remediation roadmap helped them fix all critical gaps in 60 days. They passed the RBI audit on their first attempt with no major observations.

23 gaps
Identified & fixed
60 days
Remediation time
0
Audit observations
MANUFACTURING

Score Improved from 34 to 78

CHALLENGE

A ₹800Cr manufacturing company had never formally assessed their security posture. After a competitor suffered a ransomware attack, their board demanded a security report within 30 days.

OUTCOME

Initial score: 34/100. Gordon identified 31 gaps, with MFA and patch management as the top priorities. After 6 months of working through the remediation roadmap, their score reached 78/100 — above the industry median of 62.

34→78
Score improvement
6 months
Improvement time
Top 25%
Industry ranking
HEALTHCARE

ISO 27001 Certification Achieved

CHALLENGE

A healthcare technology company needed ISO 27001 certification to win enterprise contracts. They had no idea how far they were from certification requirements or how long it would take.

OUTCOME

Gordon's ISO 27001 gap assessment identified 47 control gaps. The prioritised roadmap helped them achieve certification in 8 months — 4 months faster than the industry average. The certification helped them close 3 enterprise deals worth ₹12Cr.

8 months
To certification
4 months
Faster than avg
₹12Cr
New revenue
Pricing

Security Checklist is included in every plan.

Choose the plan that fits your team. Security Checklist features are highlighted below — scroll down to see the full platform included in every plan.

Monthly
Annual Save vs monthly
Free
$0
15-day trial
 
Get Started
Enterprise
$79,000
/yr
Save vs monthly
Start Free Trial
Custom
Custom
Flexible terms
 
Talk to Sales
Included Not available Text = Usage limit
Features Free Startup Enterprise Custom
Overview(3 features)
Gordon AI Credits (monthly)50 credits500 credits2,500 creditsCustom allocation
Dashboard
Account (User) Limit1 accountUp to 5Up to 20Unlimited
Assess(7 features)
Security Checklist (60-point)Strong & Standard onlyDynamic + AnalyticsDynamic Checklist
VAPT (Vulnerability Assessment)5 API + 10 Dynamic PagesCustom
Third Party Risk3 vendorsUnlimited
Financial Impact — Risk Quantification
Financial Impact — Security ROI
Security Awareness (Phishing Sim + Training)5 Campaigns10 Campaigns
Cyber ForceOn DemandOn Demand
All other platform modules included
Identify(8 features)Other modules
Monitored Domains1520Unlimited
Monitored IPs550500Unlimited
Monitored Web Apps1520Unlimited
Tech & Services
Phishing Risk (Lookalike Domain + Email Security)
Code Workspace (GitHub, GitLab, Bitbucket)2 WorkspacesCustom
Cloud Security ComplianceSingle Cloud (3 instances)Multi Cloud (10+)
Workforce Risk Monitoring
Monitor (SOC & Threat)(10 features)Other modules
SOC Overview5 SOC Reports
Alert Triage5,000 alerts/moUnlimited
Investigation50 investigationsUnlimited
Threat Hunting1 exerciseCustomCustom
Auto Response
Risk Monitoring5 Category dashboards
Threat Intelligence (Threats, IOCs, Campaigns)10 threats, 5 IOCs, 2 campaignsUnlimitedCustom
Alert Center
Brand Intelligence (Monitoring + Takedown)50 notifications1 Company monitoringFull + TakedownFull + Custom feeds
Dark Web MonitoringCredential & Org LeaksIndustry + APT + Recent leaks
Risk Transfer(2 features)Other modules
Cyber Insurance
Incident Hotline (24/7)
Compliance (GRC)(2 features)Other modules
GRC Module1 Policy creation1 framework3 frameworksAll + Custom
Unlimited Policy Generation
Extras & Integrations(3 features)Other modules
Integrations3 active15 activeAll 26+ & Custom API
Marketplace
Credit Add-on Packs
Support & SLA(4 features)Other modules
Support ChannelDocs onlyEmail (48h SLA)Hotline + CSM (8h SLA)24/7 Engineer (1h SLA)
Dedicated Security Engineer
White-label / MSSP
API Access

All plans include a 15-day free trial — no credit card required.

FAQ

Common questions
answered honestly.

The 60 checks span: (1) Identity & Access Management — MFA, privileged access, password policies; (2) Endpoint Security — EDR, patching, encryption; (3) Network Security — firewall, segmentation, VPN; (4) Data Protection — DLP, classification, encryption at rest; (5) Incident Response — IR plan, playbooks, tabletop exercises; (6) Backup & Recovery — backup frequency, testing, RTO/RPO; (7) Cloud Security — IAM, configuration, logging; (8) Security Awareness — training, phishing simulation, policy acknowledgement.
Gordon uses read-only API integrations with your existing platforms — Microsoft 365 (via Graph API), Google Workspace (via Admin SDK), AWS/Azure/GCP (via read-only IAM roles), and common security tools. No agents, no firewall changes, no access to your data. We only read configuration and policy metadata, never your actual files or communications.
Each of the 60 checks is weighted by its risk impact — critical checks (like MFA enforcement) carry higher weight than lower-priority checks. Checks are scored as Pass (full weight), Partial (50% weight), or Fail (0 weight). The domain scores are aggregated into an overall score from 0–100. The scoring model is transparent and published, so you always understand exactly how your score is calculated.
Yes. Professional and Enterprise plans include framework-specific mapping reports that show exactly which ISO 27001 controls, RBI IT framework requirements, SEBI guidelines, or DPDP Act obligations each check corresponds to. These reports are formatted for use in audit preparation and can be shared directly with auditors as evidence of your compliance posture.
Once you connect your environment (which takes 20–30 minutes), Gordon runs the automated assessment in the background. You receive your full report with scores, gap analysis, and remediation roadmap within 24 hours. For Enterprise clients with complex multi-cloud environments, the initial assessment may take up to 48 hours.
Gordon automatically detects when you fix an issue by re-running the relevant check against your environment. Your score updates in real time. You can also manually trigger a re-check on specific items. Monthly re-assessments ensure your score always reflects your current posture, not a point-in-time snapshot.
Get Started Today

What's your security score?
Find out in 24 hours.

Run a free 60-point security assessment and get your score, gap analysis, and prioritised remediation roadmap — no agents, no consultants, no waiting weeks for results.

Run Free Assessment Book a Demo