Kyūdō
Self-sovereignty over GRC
The gapThe answerSignalsReasoningvs. SaaS GRC
Architecture review
Kyūdō
Self-sovereignty over GRC

Your GRC platform should run where your security stack runs.

Sovereignty-grade, AI-native GRC inside your Azure tenant. Microsoft-native evidence pipeline. Compliance Graph reasoning. Citation discipline as a default, not as a configuration toggle.

1,400+ controls · 80+ frameworks○ Microsoft-native · in-tenant deployment○ SOC 2 Type II in progress
Book an architecture review Read the architecture brief
Sensei · reasoning trace · in-tenant
graph traversal
Query
Show evidence for access-control posture across SOC 2, ISO, 800-171.
evidence
EV-4821
Defender XDR · endpoint
94%
control
AC-3.1.6
NIST 800-171 · access control
STRM same88%
control
CC6.1
SOC 2 · logical access
STRM partial85%
control
A.9.2.1
ISO 27001 · user access mgmt
STRM stronger82%
policy
POL-112
Conditional Access · Entra ID
91%
confidence ≥ 70% · all entities citeddeterministic · Article 13 lineage
The architectural gap

Three assumptions the current GRC generation was built on.

Each assumption introduces a structural consequence that no configuration toggle can resolve. The gap is architectural, not operational.

01data-plane location
Assumption

The data plane is allowed to live in vendor cloud.

Consequence

Trust data crosses a vendor boundary your Microsoft Security stack was specifically architected not to cross. That trade was tolerable when GRC was annual paperwork. It isn’t now.

02reasoning substrate
Assumption

A relational data store is sufficient.

Consequence

Pairwise framework mappings, no graph traversal, no semantic relationship rating, no STRM. Adding a framework is an integration project, not a graph operation.

03AI as reasoning
Assumption

Generative AI can substitute for traceable reasoning.

Consequence

Fluent output, no citation, no confidence threshold, no Article 13 lineage. The AI feature is a marketing layer, not a reasoning discipline.

The architectural answer

Three architectural defaults that replace the assumptions.

Each default is structural. It cannot be toggled off because it is a property of the architecture, not a configuration option.

01

Sovereign deployment, structural by default

Every Kyūdō service runs inside your Azure subscription. Private endpoints on every service. System-assigned managed identities. No cross-tenant data plane: by architecture, not by contract.

Deployment
Inside customer Azure subscription
Service exposure
Private endpoints · no public ingress
Identity
System-assigned managed identities
Cross-tenant data plane
None (by architecture)
02

Microsoft-native evidence pipeline

Read-only access to the Microsoft Security signals your organization already produces. Each signal is typed against the controls it evidences. No new attack surface for trust data.

Access
Read-only · least privilege
Authentication
Managed identity
Sources
Defender XDR · Sentinel · Purview · Entra ID · Azure Policy
Per-artifact
Hash · lineage · confidence · timestamp
03

Compliance Graph reasoning

Controls, evidence, frameworks, and policies are typed entities in a Compliance Graph. Sensei retrieves deterministically, cites per output, and routes to human review below the confidence threshold.

Substrate
Typed Compliance Graph
Retrieval
Deterministic · trace reproducible
Confidence threshold
≥ 70% · else human review
Citation
Per output · source nodes named
The signal pipeline

Microsoft Security signals become governed evidence.

Six signals your organization already produces. Each is converted into typed, governed evidence inside your tenant: read-only access, least privilege, no new attack surface.

Microsoft signal
Becomes governed evidence
Mapped controls
D

Defender XDR

endpoint · identity · email · cloud

Detection signals become control validation evidence with chain-of-custody lineage. Each alert is typed against the controls it operates on.

DE.CM-1CC7.2
C

Defender for Cloud

CSPM · workload protection

CSPM findings map to controls. Drift surfaces as control regression in the graph, not as orphan alerts in a queue.

ID.RA-3CC4.1
S

Sentinel

SIEM · SOAR telemetry

Telemetry becomes continuous evidence of control operation. Hash and lineage preserved on ingestion.

PR.PT-1CC7.3
P

Purview

DLP · classification · labels

DLP and classification events become data-protection evidence, automatically mapped to privacy and transmission-protection controls.

PR.DS-5CC6.7
E

Entra ID

identity · conditional access

Identity posture and conditional access evaluations feed access-control assurance continuously. The control boundary is the same identity boundary your tenant already enforces.

AC.L2-3.1.6CC6.1
A

Azure Policy

configuration management

Policy evaluations become real-time configuration-management evidence. Compliance state is a property of the resource, not a quarterly export.

CM.L2-3.4.2CC8.1
○ Read-only access○ Least privilege○ System-assigned managed identity○ No new attack surface
The reasoning layer

Five mechanisms that make the outputs defensible.

Each mechanism is a structural property of the platform, not a feature flag. The architecture forces defensibility. It does not offer it as an option.

01

Compliance Graph

Controls, evidence, frameworks, policies, and risks are typed entities in a single graph. One traversal resolves posture across every framework the graph contains, not a pairwise mapping per framework pair.

One traversal resolves
SOC 2 · ISO 27001 · HIPAA · CMMC · EU AI Act · ISO 42001 · NIST AI RMF
02

CMCAE · Capability Maturity & Completeness Assessment Engine

Every control is scored for completeness on a 0–100 scale and capability maturity on a 1–5 scale. Recalculation happens on every Microsoft Security signal, not on a quarterly review cadence.

Recalculation cadence
on-signal · 0–100 completeness · ML 1–5
03

STRM crosswalking · NIST IR 8477

Framework relationships carry semantic strength ratings: same, partial, stronger, weaker. The relationship is a typed edge in the graph with a defined rating, not a manual annotation in a spreadsheet.

Mapping rating
same · partial · stronger · weaker — typed edge
04

Sensei reasoning with citation

Sensei retrieves from the Compliance Graph deterministically. Every output is cited per source node. Below the confidence threshold, the query routes to human review, not to a best-effort answer.

Discipline
≥ 70% confidence · cited per output · else human review
05

Deterministic retrieval

Every artifact carries provenance properties. The retrieval trace is reproducible on demand. An auditor can re-execute the same traversal and receive the same result, deterministically.

Per-artifact properties
hash · lineage · confidence · timestamp · graph-cited
Deployment

45 minutes. Azure resources, graph database, signed artifact.

A Helm-packaged deployment into your Azure subscription. Private endpoints, managed identities, and the Compliance Graph database provisioned in a single operation. Microsoft-verified.

Time to deploy45 minutes

From approval to running infrastructure. Helm-packaged deployment into your Azure subscription with graph database provisioning.

ArtifactHelm-packaged · signed

Signed deployment artifact with integrity verification. No manual configuration of individual services.

FootprintAzure resources + graph database

Standard Azure resources plus a graph database for the Compliance Graph. All within your existing subscription and security perimeter.

VerificationMicrosoft-verified

Microsoft Solutions Partner for Security. MISA member. Azure Marketplace co-sell. Verified by the same ecosystem your security stack runs on.

Compared with SaaS GRC

The architectural diff is the governance diff.

Eight dimensions where the deployment model changes the governance outcome. Not a feature comparison: an architecture comparison.

Dimension
SaaS GRC pattern
Kyūdō
Data plane location

Vendor cloud

Inside your Azure tenant

Trust data residency

Vendor SOC 2 boundary

Your Azure subscription · no cross-tenant data plane

Microsoft Security integration

API summaries, periodic

Read-only · least-privilege · managed identity · signal-by-signal

Reasoning substrate

Relational with AI overlay

Typed Compliance Graph traversed by Sensei

Confidence discipline

Generative output

≥ 70% threshold · route to human review below

Citation

Marketing-grade

Deterministic retrieval · source-cited per output

AI Act / Article 13 lineage

Roadmap or absent

Default property of every artifact

Framework crosswalking

Pairwise

STRM (NIST IR 8477) set-theoretic with strength rating

For security architects evaluating displacement

Lead a security program where governance visibility is as continuous as threat detection.

Your organization invested in continuous threat detection. Governance evidence should run the same way: inside the same tenant, on the same signals, with the same citation discipline. The gap between threat visibility and governance visibility is an architectural choice, not an inevitability.

A 90-minute architecture review. Your Azure tenant, your security stack, your compliance requirements. We walk through the deployment model, the evidence pipeline, and the reasoning layer, against your environment.

Book an architecture review · 90 min Read the architecture brief
○ Microsoft Solutions Partner · Security○ MISA member○ Azure Marketplace · co-sell○ SOC 2 Type II in progress
Frequently Asked

Questions, answered

Looking for more? See all frequently asked questions.