Sage / Why Sage
Sage models which fix moves your risk the most, and what it will cost you.
Visibility tools report state. Turning state into a funded sequence takes judgment about relative exposure, cost and return, and that judgment is what the Sage model encodes.
| Capability | Scanner or SIEM | GRC platform | Spreadsheet + slides | Sage |
|---|---|---|---|---|
| Finds the issues | Yes | No | No | Ingests from yours |
| Maps to frameworks | Partly | Yes | Manually | Yes, continuously |
| Ranks by business impact | No | Rarely | By argument | Yes, with the reasoning attached |
| Costs the remediation | No | No | Manually | Yes |
| Models a budget scenario | No | No | No | Yes |
| Generates the board pack | No | Partly | By hand | Yes, from live data |
Sage does not replace your scanners or your SIEM; it consumes their output.
Provenance
Built by the people who get called when it goes wrong.
Sage is the platform arm of Clarity Sec. The ranking model came out of live incidents and the reviews that follow them, rather than a scoring rubric drawn up in the abstract.
What that changes
Priorities that survive contact
Gap ranking reflects what actually gets exploited and what actually gets asked in a post-incident review. Scanner severity is one input among several.
What that changes
Assessments that arrive as costed work
Pen-test and assessment findings arrive as scheduled, costed work in the program record rather than a PDF that gets filed.
What that changes
Response on the same account
Customers who need incident response reach the Clarity Sec team directly, and what happens there is captured back into the program.
Security & data handling
What Sage touches, and what it does not.
The first question a security buyer asks about an AI-backed platform is what the model sees. Here are the answers.
What we ingest
Read-only, from the tools you already run. Findings, control state and asset inventory.
Where it lives
Regional hosting with tenant isolation, so the data stays where your obligations require.
What the model sees
Ranking is explainable and traceable to the control and source behind it.
Access control
Access is scoped by role and by entity, and every read of program data is logged.
Certifications
The platform holding your program is audited to the same standard.
SOC 2 Type II
Independently audited controls, with the report available under NDA.
ISO 27001
Certified information security management system, independently audited and maintained.
SSO & SCIM
SAML single sign-on and directory provisioning, so access follows your identity system rather than a separate user list.
Role-scoped access
Permissions scoped by role and entity, so a business-unit lead sees their program and nothing beyond it.
Regional hosting
Data residency by region with tenant isolation, for programs held to local obligations.
Put Sage against the stack you run today.
We will map your current stack against the model on a call, before anything is installed.