Our product

ESTA

ESTA runs an organisation's ISO 27001 management system inside its own infrastructure — the scope, the risk register, the controls and the evidence behind them.

The ESTA dashboard, showing compliance status across the ISO 27001 control set.

The problem

Compliance evidence in most West African financial and infrastructure organisations is collected by hand — spreadsheets, email threads, screenshots taken the week before an audit — and is stale the moment it is filed.

The global compliance platforms assume a SaaS-native stack. They connect to cloud services over vendor APIs, which works well until the systems that matter are an on-premise core banking platform, local middleware, or self-hosted security tooling that no integration catalogue has ever heard of. The evidence that most needs collecting is the evidence they cannot reach.

How it works

  1. Establish

    Define the scope, record the risks against a stated methodology, and decide which of the 93 Annex A controls apply — each with a written justification. The Statement of Applicability is versioned and has to be approved by someone other than whoever prepared it.

  2. Evidence

    Attach the document, record or link that shows a control is real, against the control itself. Evidence carries a validity period and is approved by a second person, so what counts is attested and current rather than merely uploaded.

  3. Sustain

    Internal audits, management reviews, corrective actions and continuity exercises run on the same record, so the management system produces the proof of its own operation that a certification body asks to see.

The Statement of Applicability in ESTA, listing Annex A controls with their justification, owner and attached evidence.

Where it runs

Regulated organisations frequently cannot send raw configuration, log or access-review data outside their own infrastructure. That is not a preference to be negotiated — for a licensed institution it is often the reason a compliance tool is rejected before anyone looks at what it does.

ESTA is deployed where the data already is: inside your environment, on your hardware or your tenancy, behind your own network controls. Nothing about the evidence, the risk register or the audit trail has to leave it.

What it covers

ISO/IEC 27001:2022
Clauses 4 to 10 and all 93 Annex A controls, with the Statement of Applicability, risk treatment plan, internal audit and management review the standard requires.
Ghana Data Protection Act, 2012 (Act 843)
Mapped onto the same control set, so a control implemented once is evidenced once and answers to both.
Bank of Ghana Cyber and Information Security Directive
Crosswalked alongside Annex A for regulated financial institutions.
The ESTA risk register, showing scored risks with their treatment decisions and owners.

Evidence you can defend

ESTA had automated collectors for AWS, Microsoft 365 and Okta. They returned passes they had not verified, so they were removed rather than shipped. Evidence in ESTA is attached by a person and approved by another one — slower than a green dashboard, and considerably harder to argue with.

Every piece of evidence carries who attached it, who approved it, and the period it is valid for. The same separation applies to the Statement of Applicability, to risk acceptance and to the continuity plan: whoever prepared a thing cannot be the one who authorises it. An auditor asking "who signed this off, and when" gets an answer from the record rather than from somebody's memory.

The ESTA evidence register, showing each item with its approval state and validity period.

Status

Currently in user acceptance testing. It is being run end to end against a full ISO 27001 implementation — scope, risk register, Statement of Applicability, evidence, internal audit and management review — by testers working through the same task backlog a real organisation would.

A pilot case study will follow once the environment it runs in can be described.

Name the process that costs you the most

Tell us which one, and roughly what it costs you in hours or cedis. We'll come back with either three questions or a proposed 30-minute call.

Book a scoping call