Every asset and data registry, mapped to what it must comply with.
Aigis keeps a living inventory of your assets and data repositories (מאגרים), classifies them, and binds each to the obligations it triggers - ROPA, security levels and controls derived from what the asset actually is.
Living
Inventory, not a spreadsheet
Per-asset
ROPA & obligations
Basic→High
Registry security levels
Asset-first
The single SSoT anchor
Inventories that rot, disconnected from duty
You can't govern what you can't see - and a stale asset list sees nothing.
Inventories that rot
A spreadsheet of assets, out of date the day after it's made, disconnected from the obligations each asset triggers.
No line of sight to data
Where regulated data actually lives - repositories, drives, systems - is unknown until an incident or an audit finds it.
Registries mapped by hand
Data registries (מאגר) and their security levels tracked manually, never reconciled with the controls they require.
Assets and registries as governed data
Classified, connected, and bound to the exact duties each asset carries.
Asset-first inventory
Each asset is the single anchor its risks, controls and evidence hang off - not a duplicate mapped per framework.
Data registries (מאגר)
First-class data repositories with basic, intermediate and high security levels, each binding the controls that level requires.
Per-asset ROPA
ROPA membership derived from each asset: does the ROPA obligation apply, does the asset hold personal data, is it still in use.
What connects to what
Assets and their connections mapped - by you, or discovered by your own agent - so the graph builds itself.
Classification drives controls
Personal-data and sensitivity classification determine which obligations and Annex-A controls surface for each asset.
Asset → risk → control
One resolver ties assets to the risks they carry and the controls that treat them, read-time and always current.