The CTRL 18 house

Four products.
One standard of proof

CTRL 18 builds systems of record for the decisions an enterprise has to defend later, to a board, an auditor, a regulator, or a court. Two of them lead: SignForge for signing, Trevos for third-party risk.

What each one proves

Anyone can claim it happened.
These leave the evidence

Every product here produces a record that survives the argument, and survives us. That is the through-line of the house, not a shared login.

  1. SignForgeE-SIGNATUREProvesthat this document is exactly what was signedLeaves behindSigning certificateW3C verifiable credentialPublic transparency-log entry
  2. ConvorgeCLMProveswho agreed to what, and whenLeaves behindImmutable contract versionInsert-only audit trail
  3. TrevosTPRMProveswhat a third party could cost you, in moneyLeaves behindBoard-ready risk PDFLoss-exceedance curveIssue and incident trail
  4. KritisCDPProveswhere your own defences actually standLeaves behindBoard reportPer-safeguard evidenceFramework audit pack
Two families, four products

Built to be used on their own

Each product stands alone and sells to its own buyer. Nothing here requires you to take the rest of the house.

Agreements

Getting to a signature, and being able to prove what was signed.

SignForge

E-signature

Enterprise e-signature with proof that outlives the vendor.

Every signed PDF carries its own cryptographic proof. Anyone can verify it offline, with no SignForge account, no particular PDF reader, and no active subscription.

758
documents signed
72.9%
completion rate
1,060
independent verifications
SignForge, the document pipeline dashboard

Convorge

Contract Lifecycle Management

The counterparty never has to adopt your software.

Intake through renewal in one system. Counterparties redline in Microsoft Word over email exactly as they do today, and Convorge turns their reply back into reviewable change requests.

Convorge, the contract portfolio at a glance

Risk & Assurance

Knowing where you stand, and where everyone you depend on stands.

Trevos

Third-Party Risk Management

Every third party, in view.

Identify, assess, monitor and govern vendor risk across the full eight-stage lifecycle, and put it in money terms a board can act on.

8
lifecycle stages covered
501
vendors pre-profiled
13
external signal dimensions
Trevos, the board risk overview

Kritis

Cyber Decision Platform

Beyond cyber risk quantification.

Map your posture to the CIS 18 Controls, project the gaps onto MITRE ATT&CK and the Kill Chain, and quantify what is left in dollars.

18
CIS Controls mapped
153
safeguards scored
3
implementation groups
Kritis, loss scenarios across the Cyber Kill Chain
Coverage

Standards these are built against

ESIGN ActeIDASUETAGDPRSOC 2ISO/IEC 27001ISO/IEC 27036ISO/IEC 27005NIST CSF 2.0NIST SP 800-30NIST IR 8286PCI DSS v4.0CIS Controls v8.1.2DPDP Act 2023SEBI CSCRF

Coverage varies by product. Each product page states exactly what it claims. SignForge supports simple and advanced electronic signatures under eIDAS; it does not hold AATL certificates or eIDAS Qualified signatures.

One demo,
whichever one you came for

Tell us which product matters most and we will show you that one first: signing, third-party risk, contracts, or your own posture.