Aderaldo Security
Sign in to Vet

Security software for engineering and GRC teams

Every commit vetted.

Five products, one foundation. Find and fix vulnerabilities in every pipeline, prove every control to your auditor, own every risk, keep every policy signed, and train every team — with your own sign-in and a shared record of evidence.

Products

One product per job, built to work together

Each product has its own address and plan. Buy one, add the next when you need it — your organization, users and evidence are already there.

vetted

Vet DevSecOps

Every commit vetted. Runs the security scanners in your pipelines, turns their output into one vulnerability inventory and blocks what should not ship.

Availablevet.andersonaderaldo.com
  • Scanners in your CI: Gitleaks, TruffleHog, Semgrep, Trivy, Grype, OSV-Scanner, Checkov, Syft and OWASP ZAP in GitHub Actions, GitLab CI and Azure Pipelines.
  • One ID per vulnerability (VET-123), de-duplicated across tools, closed when the fix merges and reopened with the same ID if it returns.
  • Security gate on pull requests, prioritized by CISA KEV and FIRST EPSS, with SLA and MTTR per severity.
  • Risk exceptions with expiry and identity confirmation, SBOM and license policy, policy-as-code in Rego, signed evidence reports.
attested

Att Audit & evidence

Every control attested. Knows what evidence each control needs, collects it automatically where it can, checks it and tells the owner before it expires.

In designatt.andersonaderaldo.com
  • Evidence rules per control: which documents, screenshots or exports to attach, in what format, from whom.
  • Automated collection from your cloud, identity provider, code platform and from Vet's scans and signed reports.
  • Validation by rule and by reviewer, with a full history of who accepted what and when.
  • Renewal cycles: each piece of evidence has a validity period and reminders before it lapses.
owned

Own Risk management

Every risk owned. A risk register where every entry has a name next to it, a score, a decision and a date to look at it again.

In designown.andersonaderaldo.com
  • Register with owners and likelihood × impact scoring, inherent and residual.
  • Treatment plans and acceptances with expiry, approvals and step-up confirmation.
  • Periodic reviews scheduled per risk, with reminders and escalation.
  • Linked to controls in Att and to accepted vulnerabilities in Vet.
inked

Ink Governance

Every policy inked. Policies and standards from first draft to signed acknowledgment, with every version kept.

In designink.andersonaderaldo.com
  • Policy lifecycle: drafting, versions, approval, publication and scheduled review.
  • Acknowledgment by every employee, recorded per version, with reminders for those who have not read it.
  • Policy exceptions that become risks in Own.
  • Approved versions and acknowledgments delivered to Att as evidence.
armed

Arm Security awareness

Every team armed. Training, phishing simulations and a one-click way to report a suspicious e-mail.

Plannedarm.andersonaderaldo.com
  • Training paths by role, with completion tracked per person.
  • Phishing simulations with realistic templates and per-campaign results.
  • Report phishing button for Outlook and Gmail; reports reach your team, simulations are recognized.
  • Results as evidence for awareness controls in Att and as a people-risk indicator in Own.

Platform

The same foundation under every product

What you set up once works everywhere you have a license.

Your own sign-in

Connect Microsoft Entra ID, Okta, Google, GitHub, GitLab, any OIDC provider or SAML 2.0 once. SCIM keeps users and roles in sync.

Isolated per organization

Each organization's data is encrypted with its own key, wrapped by a key that never leaves Azure Key Vault.

Tamper-evident audit trail

Every action is recorded in a SHA-256 hash chain and can be streamed to your SIEM.

Signed evidence

Reports carry an Ed25519 signature you can verify in the app or offline.

Partners welcome

Consultancies manage their customers' organizations with access the customer approves and can revoke at any time.

Step-up for what matters

Accepting a risk or changing sign-in asks for your identity again: MFA for local accounts, a fresh sign-in for SSO.

How it connects

Work done in one product counts in the others

Vet→Att

Scan results, the security gate and signed reports become evidence for vulnerability and change-management controls.

Ink→Att

Approved policy versions and employee acknowledgments are attached to the controls that require them.

Arm→Att

Training completion and simulation results cover awareness controls.

Vet→Own

Accepted vulnerabilities appear in the risk register with their owner and expiry.

Ink→Own

Policy exceptions are recorded as risks to treat or accept.

Frameworks

Mapped to the standards your auditors use

Controls, evidence and reports are mapped to these frameworks today in Vet, and will be the starting catalog in Att.

ISO/IEC 27001 :2022SOC 2 Type IIPCI DSS v4.0LGPD Lei 13.709BACEN Res. 4.893

Start where your risk is highest. Add the rest when you are ready.

Questions, a demo or early access to Att, Own, Ink and Arm: write to us.