Platform overview
What Aranis is, the six risk domains it covers, and who the platform is built for.
What Aranis is
Aranis is a SaaS governance, risk, and compliance platform. It started as a third-party risk management tool and today covers six risk domains that share one scoring methodology, one control library, and one risk register — instead of six spreadsheets that never agree.
The central idea is that supplier risk, cyber risk, privacy risk, and organizational risk are not separate disciplines: they are cuts through the same exposure. A business process depends on a product, which depends on an asset, which depends on a supplier. When those objects live in one place, the question "what happens if this supplier goes down" has a computed answer rather than an estimated one.
The six domains
Organizational Risk (ISO 31000): the corporate risk register, with context, areas, business processes, products and services, and business impact analysis. It is the layer the other domains hang from.
Cyber Risk: asset × threat matrix, control library, organizational vulnerability, and the CAIQ questionnaire. Privacy Risk: processing activities, canvas, data map, and the privacy reports — ROPA, DPIA, LIA, TIA, and DIA. TPRM: supplier assessment, respondent portal, surface scanning, and action plans.
Continuity (ISO 22301): continuity plans, recovery strategies, and their controls. AI Risk: the newest pillar, tied to category RC11, covering the development and operation of AI systems.
What runs across all of them
Some capabilities belong to the whole rather than to one domain. Ara is the platform's analytical intelligence: it answers questions about your data, runs discovery interviews, and helps fill records in. The Trust Center publishes your security posture on a public page. The document repository holds policies with a review and publication workflow. The risk acceptance letter formalizes acceptance with an owner and a signature. And Business Intelligence builds panels over any of the domains.
How a supplier assessment works
The questionnaire is assembled from the supplier's criticality profile and sent to the respondent through a tokenized link — no account required on their side. They answer YES, NO, PARTIAL, or NA, with justification and evidence; PARTIAL and NA answers go through AI validation. In parallel, surface scanning collects publicly observable signals on the supplier's domain, to corroborate or contradict what was declared. The result is maturity per pillar and a Risk Score per risk category, with no thresholds hardcoded.
Who it is for
For governance, risk and compliance, information security, privacy, and contract management teams that need a systematic, repeatable, auditable process. It is especially relevant to organizations subject to Brazil's LGPD, which establishes joint liability between controller and processor, and to regulated sectors such as finance, healthcare, and critical infrastructure.