AIRA

Cyber risk analysis, augmented.

HOSTED IN FRANCE
SOVEREIGN AI

Your risk assessments take weeks.
Your risks
won’t wait.

92% of teams spend more than a day on a risk assessment, 58% more than a week. AIRA gives that time back to your analysts, without taking anything away from their judgment.

See the method
Contract readable before signing No agent to install
LINKEDIN POLL “How long does a cyber risk assessment take you?”
Under a day 6 %
1 to 7 days 34 %
1 to 2 weeks 30 %
2 to 4 weeks 28 %
58 % of teams spend more than a week on it.
THE RISK ASSESSMENT YOUR REGULATIONS REQUIRE
ISO 27001 NIS2 DORA GDPR
No advertising trackers
21
FRAMEWORKS SUPPORTED
NIS2 NIS2 2024/2690 ReCyF DORA DORA RTS 2024/1774 GDPR AI Act CRA RGS HDS SecNumCloud ANSSI hygiene guide ISO 27001 NIST CSF 2.0 NIST SP 800-53 NIST SP 800-171 PCI DSS SOC 2 CIS Controls SWIFT CSCF
THE AIRA HUB

Connect. Contextualize. Prioritize.

Your assets, threats, controls and obligations live today in tools that do not talk to each other. The Hub connects them, and it is from those connections that prioritized risks emerge. Hover an element for the details.

AIRA HUB
Connects, contextualizes,
prioritizes
01Assets & applications
what must be protected

Servers, applications, data, third parties: AIRA builds the inventory of your estate and keeps it up to date.

02Owners & teams
who is accountable

Every asset carries a named owner. Accountability becomes explicit, and follow-ups automatic.

03Threats
who or what can attack

Attack scenarios drawn from frameworks and threat intelligence, tied to the assets actually exposed in your organization.

04Vulnerabilities
the exploitable weaknesses

Technical and organizational weaknesses, correlated with threats and assets so you only handle what truly matters.

05Security controls
what reduces the risk

Existing or planned measures, continuously assessed: AIRA computes residual risk, not just inherent risk.

06Standards & regulations
what you must comply with

ISO 27001, NIS2, DORA, GDPR: what your regulations expect becomes the measures the assessment expects, checked against your actual controls.

07Incidents & CTI
what actually happened

Your incident history and threat intelligence: real-world experience readjusts your likelihoods, instead of a frozen score.

08Business impact
cost, operations, reputation

Every risk is translated into a quantified business consequence, the only language that makes an executive committee decide.

Centralized
All your scattered data finally brought together
Connected
Automatically links the elements to one another
Contextualized
Builds coherent risk scenarios
Actionable
Prioritizes risks and supports the decision
ONE PLATFORM, THREE PILLARS

The whole risk assessment,
from asset to decision

From threat scenarios to the signed risk letter, AIRA automates what takes weeks and leaves the judgment to your analysts.

Threat scenarios

AIRA builds the scenarios that target your actual assets, from your inventory and threat intelligence, instead of a generic list copied from one workshop to the next.

Learn more (in French) →

Every scenario is tied to your actual assets, with its threat actors, vectors and likelihood. You see what is aiming at you, not a generic threat list.

Scoring and residual risk

Every risk is scored before and after your actual measures, on your own matrix, then translated into business impact.

Learn more (in French) →

Treatment plans with an owner and a due date, operational risks grouped into major risks, decision history kept. Your leadership reads business impact, not technical references.

A risk letter ready to sign

Threats, vulnerabilities, scenarios, measures and the owner's decision: the assessment comes out as one document your leadership signs.

Learn more (in French) →

The frameworks that apply to you (NIS2, DORA, ISO 27001…) feed the assessment: they set the measures expected on each asset, and a missing measure stays a visible gap. A measure entered once serves them all.

THE PRODUCT, SCREEN BY SCREEN

See AIRA before
you create your workspace

Six screens, six questions you are already asking yourself. Pick the one you care about.

Your risks, scored and prioritized

Every risk is scored before and after controls, then placed on your matrix, the one you configured, not a scale imposed on you.

  • Fully configurable impact / likelihood matrix
  • Inherent and residual scoring, history kept
  • Operational risks grouped into major risks
Risk matrix IMPACT ↑ / LIKELIHOOD →
54321
2
1
3
1
4
2
R-014 Compromise of the CRM customer database After controls: High

An analyst that knows your context

The assistant answers from your assets, your risks and your frameworks : not from a generic model trained on the web.

  • It answers on your real scope, not on generalities
  • It drafts your summaries and your risk analyses
  • Model hosted in France: your data does not leave
Which critical assets have no tested backup?
A
Three critical assets out of five: Core Banking API, Payment gateway and CRM customer database. The first two already have an open action.
Inventory · 5 assets ISO 27001 · A.8.13

Your whole estate, kept current

Servers, applications, data, third parties: AIRA keeps the inventory of what you have to protect, with a named owner on every asset.

  • Business owner and technical owner on every row
  • Criticality and environment, filterable in one click
  • Bulk import from the exports you already have
ASSETOWNERCRITICALITYENVIRONMENT
Core Banking APIM. Le GuenCriticalProduction
Base clients CRMS. FerreiraHighProduction
Portail RHA. DialloMediumProduction
Passerelle de paiementM. Le GuenCriticalProduction
Analytics sandboxL. NguyenLowTest

The work, asset by asset

For every asset in your scope, the expected measures and their actual status. No more spreadsheet kept on the side.

  • Expected measures are derived from the asset type
  • Status is editable from the inventory, the scope or the assignment screen
  • A ruled-out measure stays visible, with its rationale
Core Banking API 12 EXPECTED MEASURES
IAC-01Privileged access managementDeployed
CRY-03Encryption of external trafficDeployed
MON-05Centralized loggingIn progress
VPM-02Continuous vulnerability scanningGap

Who does what, and by when

Every gap becomes an action owned by a person, with a due date and progress. Delays show up without anyone having to look for them.

  • The owner is picked from your org chart
  • Assets and measures attached to the action, adjustable
  • Being late is computed, not declared
A
Roll out continuous vulnerability scanning
Reduces risk R-014 · 2 assets concerned
Overdue
OWNERS. Ferreira
DUE DATE30/09/2026
PROGRESS40 %

Your frameworks, as input to the assessment

AIRA works out which frameworks actually apply to you and derives the measures expected on each asset. Their gaps feed the assessment, not a separate spreadsheet.

  • 21 frameworks, ready to use
  • A measure entered once feeds several frameworks
  • Gaps surface as you go, not the night before the audit
FRAMEWORKSTATUSRATIONALEGAPS
ISO/IEC 27001ApplicableTarget certification14
NIS 2ApplicableLegal obligation9
DORAApplicableLegal obligation11
PCI DSSNot applicableNo card payments-
FROM ASSET TO TREATED RISK

How your inventory becomes
an action plan

Four steps, and each one feeds on the previous. You never enter the same thing twice.

STEP 01

Your scope

You describe what you have: assets, owners, entities, line of business.

  • Bulk import or guided entry
  • A named owner on every asset
STEP 02

What applies to you

AIRA derives the frameworks that genuinely apply to you, and the measures expected on each asset type.

  • 21 frameworks supported
  • Derived from your sector, regions and data processed
STEP 03

What is missing

The gap between expected and deployed surfaces on its own, asset by asset, and feeds the residual risk. No spreadsheet kept on the side.

  • Gaps tracked per framework
  • Nothing to recompute by hand before an audit
STEP 04

What you do about it

Every risk to reduce becomes an action with an owner, a due date and progress. Being late is computed for you.

  • Owner picked from your org chart
  • Decision history kept
Up and running in minutes
SOVEREIGNTY & TRUST

Your data stays in France.

AIRA and your data are hosted in France, with French operators. Security and data protection by design.

Where your data lives, in detail (in French) →
FR
Hosted in France
Infrastructure operated in France
Encryption
Encrypted traffic, and backups encrypted before they even leave our servers.
GDPR by design
Compliance and data minimization by design.
One isolated workspace per client
A dedicated database : not one more row in a shared one.
AI hosted in France
The model runs at a French provider. Your data does not go to a US vendor.
PLANS

Plans that grow with you

Pick the plan that matches your size: we get back to you within one business day. Custom for tailored enterprise contracting.

Starter
For your first risk assessments.
Analyses / month15
Users5
★ POPULAR
Professional
To structure and scale up.
Analyses / month40
Users10
Enterprise
For a structured organization.
Analyses / month100
Users20
Custom
Large account, multi-entity.
Custom quote
Tailored contract · purchase order
Analyses / monthTailored
UsersTailored

Wire transfer billing on every plan: request, invoice, then your workspace opens as soon as the transfer clears. Custom: quote, tailored contract and security review, with support.

THE QUESTIONS WE GET

Before you decide

How does AIRA change a risk assessment run in workshops and spreadsheets?

It removes the re-keying, not the judgment. In workshops and spreadsheets, the inventory gets copied over, threats are listed by hand and scoring is redone at every review. AIRA starts from your inventory, builds the scenarios, scores each risk before and after your actual measures and prepares the risk letter: your analysts validate and decide instead of re-keying. And everything stays in France, your data as well as the AI model.

Do we need to install an agent or connect our systems?

No. AIRA does not connect to your infrastructure and installs nothing on your side: you describe your scope, or import it from the exports you already have. That is a choice, not a temporary limitation, there is no access to your systems to grant, so no added attack surface, and nothing for your infrastructure team to sign off before you start.

How long before we are up and running?

Your workspace opens as soon as the transfer clears, provisioning itself takes one to two minutes. The real ramp-up time is then down to you: it depends on describing your scope. A first inventory of around thirty assets can be entered or imported within a day, and the applicable frameworks are derived on their own from there.

Is our data isolated from other clients?

Yes, and not merely by an application-level filter. Every client gets its own workspace, with its own database, your data is not extra rows in a shared table. A faulty query therefore cannot surface another organization's data, because it simply is not in the same place.

What if our needs go beyond the published plans?

That is what the Custom plan is for: quote, invoice, purchase order, tailored contract and a supported security review. It is also the normal route for a multi-entity organization or one with a formal procurement process. Write to us and we will start from your constraints rather than from a pricing grid.

Take back control of
your cyber risk.

A demo on your actual context, not a generic walkthrough. Contract readable before signing.

See pricing