Technical evaluation

vCISO Lite versus ProcessUnity

Two TPRM platforms with different centers of gravity. ProcessUnity is a TPRM specialist with a shared vendor-risk exchange (Global Risk Exchange — 370k+ profiles absorbed from the 2023 CyberGRX merger). vCISO Lite ships TPRM inside a broader vCISO + GRC + services SKU with a Starter tier at $299/mo (5 vendors + 5 vendor questionnaires answered per month), DC-TPIR as a codified vendor-incident-response product, and a re-derivable Evidence Graph substrate under every vendor artifact.

Prepared
Method
Capability walk against ProcessUnity’s published product surface (processunity.com, processunity.com/hypertprm, processunity.com/solutions, processunity.com/about-us) and vCISO Lite’s live platform.
Sources
processunity.com, processunity.com/hypertprm, processunity.com/solutions, ProcessUnity + CyberGRX 2023 merger press release, vcisolite.com product surfaces, vcisolite.com/pricing, vcisolite.com/services, vcisolite.com/allotrope. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where ProcessUnity leads

  • Global Risk Exchange — 370,000+ vendor profiles. Absorbed from the 2023 CyberGRX merger; 1M+ vendor responses collected; 600,000+ third parties under management.[1] When a buyer’s target vendor is already on the exchange, the response is pulled from the shared profile without re-sending. Vendor-side network effects — vendors who’ve already completed a CyberGRX profile don’t want to re-do it. Real moat we cannot replicate short-term.
  • TPRM is the entire product surface. ProcessUnity is a TPRM specialist. For F500 with a dedicated 20-person TPRM team running 500+ vendor assessments per year, the specialist workflow depth is real.
  • Pre-mapped regulatory accelerators. DORA, APRA CPS 230, ABAC, LkSG surfaced as named regulatory content packs.[6] Wizard-driven quickstarts for named regulations reduce implementation friction.
  • Assessment Autofill + Evidence Evaluator. AI reads vendor-submitted evidence (SOC 2 reports, ISO certs, policy PDFs) and auto-populates questionnaire responses; Evidence Evaluator validates uploaded evidence and scores risk in real time. Real feature.
  • Enterprise TPRM specialty depth. Twenty-plus years focused on this category alone; SKU depth vCISO Lite doesn’t match on TPRM specifically.[5]

Where vCISO Lite leads

  • DC-TPIR — Dependency-Centric Third-Party Incident Response. Codified per-incident-type playbooks with MSA contractual mapping and comms templates; source methodology is Yolonda’s 2026 book Someone Else’s Breach. Executive brief on /briefs-and-specs.[2] ProcessUnity has no comparable surface — “Incident Management” appears only as a listed customer use case on their solutions page, and “Threat & Vulnerability Response” is threat monitoring, not incident response.
  • Evidence Graph — externally-anchored, SDK-licensable. Hash-chained records + per-event Ed25519 signing + RFC-3161 external timestamp anchor + transparency log live prod 2026-08-20. An auditor who distrusts vCISO Lite can re-derive the chain against the external record. SDK-licensable since 2026-08-15.[3] ProcessUnity’s audit-trail is platform-internal; no external-anchor mechanism disclosed on the product page.
  • QCD Pillar 2 — portfolio-level HHI concentration. ProcessUnity Risk Index scores individual vendors continuously. QCD Pillar 2 (Third-Party & Vendor Concentration) applies a Herfindahl-Hirschman Index concentration penalty at portfolio level, combined with Max Single-Vendor Loss for Expected Annual Cost + P90.[4] Codified from Someone Else’s Debt.
  • Vendor operations run in the tools your team already uses. Your Claude, your Cursor, your internal LLM, your partner’s agent stack — any of them can call APRI directly to compute vendor exposure, draft a CAIQ / SIG response with cited evidence, pull the vendor inventory, or submit an assessment. No separate UI, no screenshot copy/paste. Every LLM-driven action still writes to the Evidence Graph with per-event Ed25519 signing — you get LLM speed without losing a re-derivable audit chain. ProcessUnity’s TPRM AI Agents stay behind their login; your agents work around them.[7]
  • Starts at $299/mo. 5 vendors + 5 vendor questionnaires answered per month; every tier on /pricing. ProcessUnity does not publish any tier price without a scoping call.[9]
  • 250+ SCF-cross-mapped frameworks, 1,468 universal controls. ProcessUnity claims 250+ frameworks + 1,000+ controls in a parallel content library; vCISO Lite’s corpus is SCF-native so every mapped control unlocks the frameworks that share it.[6]
  • Trustworthy Autonomy. Autonomous operations layer running on the Evidence Graph. Public beta since 2026-07-07; Level 1 agent governance proven prod 2026-08-17; published evaluation harness grades the agent by task category before purchase.
  • Broader compliance program on the same SKU. vCISO Lite Enterprise bundles TPRM alongside SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, DORA, NYDFS Part 500, HITRUST, CJIS, CMMC, ISO 42001, NIST AI RMF and productized services. ProcessUnity is TPRM only — broader compliance requires a second platform.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue. Direct-buy platform; no enterprise-implementation cycle to unlock the base capability.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
SMB and mid-market operators evaluating TPRM as one input in a broader compliance program, and mid-market TPRM buyers comparing a specialist platform against an integrated vCISO+GRC+services SKU with a direct-buy pricing floor.
Evaluation frame
Ten capability categories the TPRM buyer typically weighs. Not: everything each vendor does.
Comparison basis
Both vendors’ published product surfaces (product pages, solution pages, pricing pages) and press-release history (including the CyberGRX merger). Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

F500 dedicated TPRM programs
If the buyer runs a 20-person TPRM function assessing 500+ vendors/year and the primary constraint is assessment cycle time, ProcessUnity’s shared exchange saves them time we cannot. This page does not litigate whether F500 TPRM programs should choose ProcessUnity — they should evaluate it directly.
External attack-surface scanning
Neither vendor competes primarily on external vendor scanning. For that specific need (continuous external cyber ratings on vendors), see BitSight / SecurityScorecard / Panorays.
Vendor-side exchange strategy
ProcessUnity’s 370k-profile Global Risk Exchange (ex-CyberGRX) is a real moat. This page does not attempt to substitute for the vendor-side network effect — buyers with big vendor tails should weigh it directly.

Capability coverage

Ten capabilities§3

Amber = ProcessUnity ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

Regulatory accelerators · DORA · APRA CPS 230 · ABAC · LkSGpre-mapped content packs · questionnaire templates · control mappingsTPRM AI Agentsspecialized agents for intake, due-diligence, remediationAssessment Autofill · Evidence EvaluatorAI reads uploaded evidence → populates questionnaire responsesProcessUnity Risk Indexcontinuous controls-driven vendor rating · internal signals + external threat feedsTPRM workflow platformvendor records · assessments · lifecycle · onboarding → offboarding · 250+ regulation packsGlobal Risk Exchange · 370,000+ curated vendor profilesex-CyberGRX · 1M+ vendor responses · shared community data
ProcessUnity stack, bottom-up.The dashed base — Global Risk Exchange, the 370k-profile vendor exchange absorbed from the July 2023 CyberGRX merger — is the load-bearing moat. Every layer above it is workflow, scoring, or AI orchestration reading from that shared vendor data.
§4.1

Vendor-incident-response as productized capability

ProcessUnity's 'Incident Management' appears as a customer use case; DC-TPIR ships as a product.

ProcessUnity

'Incident Management' is listed as a customer use case for the ProcessUnity Platform on the solutions page, not as a productized product line. 'Threat & Vulnerability Response' is a threat-monitoring product — continuous monitoring of emerging threats — not a codified per-incident-type response playbook.

Inputs
Threat intelligence feeds; vendor risk index scores; alert triggers.
Outputs
Alerts and workflow tasks against the general TPRM platform.
Evidence
Public solutions page (processunity.com/solutions) lists 'Threat & Vulnerability Response' and 'TPRM AI Agents' as products; 'Incident Management' as a customer use case.
Fails when
Buyer needs a codified, named playbook per third-party incident type (data breach at vendor, ransomware at vendor, business-continuity failure, regulatory disclosure obligation), with contractual-mapping and communication templates.
vCISO Lite DC-TPIR

DC-TPIR ships codified per-incident-type playbooks with MSA contractual mapping and comms templates, every step Ed25519-signed to the Evidence Graph so a regulator, insurance carrier, or M&A diligence reviewer can prove after the fact that response happened per playbook — without trusting vCISO Lite.

Inputs
Third-party incident signal (vendor breach notification, threat-intel alert, regulatory disclosure trigger, vendor tier data, contractual exposure, business dependency graph).
Outputs
Per-incident-type response playbook · contractual-obligation mapping · communication templates · executive briefing PDF · Evidence Graph record of every action taken.
Evidence
Source methodology is Yolonda's 2026 book Someone Else's Breach, referenced on /about as foundational IP inside the platform.
Fails when
N/A — ProcessUnity has no equivalent productized capability to compare against.
§4.2

Vendor-risk data model + shared exchange

ProcessUnity's core moat is the 370k-profile Global Risk Exchange absorbed from CyberGRX. vCISO Lite's data model is the customer's own evidence chain.

ProcessUnity

Global Risk Exchange — 370,000+ curated vendor risk profiles absorbed via the 2023 CyberGRX merger. Proprietary Tier 1 / Tier 2 / Tier 3 CyberGRX assessment formats. Access-control layer gates buyer access per contractual subscription. Validation pipeline where CyberGRX analysts historically reviewed vendor evidence submissions before publishing to the network.

Inputs
Vendor-completed profiles (network side); customer subscription; per-vendor targeting.
Outputs
Pre-completed vendor risk profile pulled from the shared exchange, delivered into the buyer's TPRM workflow.
Evidence
1M+ vendor responses; 600k+ third parties under management (per processunity.com/about-us).
Fails when
Buyer's target vendor is not on the exchange — the buyer sends a questionnaire to the vendor and waits.
vCISO Lite

Vendor records + tiering + business context inside the customer's own compliance program. compute_vendor_exposure MCP tool measures blast-radius per vendor from the customer's evidence chain. No shared vendor-side network — vCISO Lite operates against the customer's data, not a shared exchange.

Inputs
Customer's vendor inventory; APRI-completed vendor questionnaires from evidence chain; contractual data; incident history.
Outputs
Vendor tiering + per-vendor exposure computation + QCD Pillar 2 HHI concentration + questionnaire completions signed to Evidence Graph.
Evidence
Every vendor record and assessment writes to the Evidence Graph; every APRI call is caller-entitlement-scoped, tool-call-audit-trailed, and observe-first with confirmation gates on writes.
Fails when
Buyer's primary constraint is 'we have 500+ vendors and the assessment cycle is our bottleneck' — for that constraint, ProcessUnity's shared exchange saves time we cannot.
§4.3

Evidence integrity substrate

ProcessUnity records land in a platform-internal store. vCISO Lite writes to a re-derivable, externally-anchored chain.

ProcessUnity

Vendor records, questionnaire responses, evidence uploads, Risk Index scores, AI-agent actions — all land in the platform's internal store. Standard TPRM audit-trail pattern. No external-anchor mechanism, no cryptographic per-event signing, no transparency log surfaced on any product page.

Inputs
Every vendor action, assessment update, evidence upload, risk-index refresh, AI-agent output.
Outputs
Internal audit records readable through the platform UI + export.
Evidence
Public product surface has no reference to RFC-3161, Ed25519, or transparency-log mechanisms.
Fails when
Adversarial auditor asks to verify a specific vendor assessment independently against an external record; the audit-trail requires trusting ProcessUnity to trust the record.
vCISO Lite Evidence Graph

Every vendor artifact — questionnaire responses, risk decisions, APRI answers, autonomous actions — is Ed25519-signed and anchored to an external RFC-3161 timestamp authority, so a SOC 2 auditor or cyber-insurance carrier can prove the chain wasn't tampered with, without trusting vCISO Lite.

Inputs
Every agent action, evidence artifact, policy decision, framework mapping, vendor-incident response step.
Outputs
Sealed evidence chain · external timestamp attestation · re-derivable proof.
Evidence
Auditor re-derives the chain against the RFC-3161 attestation record; verification does not depend on trusting vCISO Lite. SDK-licensable since 2026-08-15 — partners and insurance carriers can embed the same integrity properties in their own pipelines.
Fails when
Buyer's existing audit tooling has not been briefed on RFC-3161 verification; onboarding the audit firm to the chain takes one call.
§4.4

Where the AI actually runs — locked in the vendor's UI vs callable from the buyer's stack

ProcessUnity's AI is a workflow feature inside ProcessUnity. vCISO Lite's AI is a set of vendor operations any agent your team runs can call — Claude, Cursor, your own LLM, a partner's stack. The audit chain survives across all of it.

ProcessUnity

TPRM AI Agents + Assessment Autofill + Evidence Evaluator all live inside the ProcessUnity UI. The buyer accesses the AI through ProcessUnity's screens; no public API or agent-facing surface for external LLMs to invoke.

Inputs
Uploaded vendor evidence, questionnaire templates, framework mappings — all provided through the ProcessUnity UI.
Outputs
Auto-populated questionnaire responses (analyst reviews inside ProcessUnity); risk scoring inside the Risk Index dashboard.
Evidence
Public product page names the three AI features as platform capabilities. Nothing on the public surface describes an external-agent-callable interface.
Fails when
Buyer's security team lives in Claude / Cursor / their own LLM and wants vendor-risk work to happen there. Or a partner (insurance carrier, M&A diligence, MSP) wants to wire vendor answers into their own agent stack. Or an autonomous agent needs to invoke vendor operations continuously. None of these compose with ProcessUnity's platform-internal AI.
vCISO Lite APRI

APRI exposes vendor operations (compute_vendor_exposure, create_vendor_assessment, get_vendor_inventory, submit_vendor_assessment_for_review) as callable tools any MCP-speaking client — Claude, Cursor, custom LLM, autonomous loop — can invoke, so vendor-risk work happens where your team already sits.

Inputs
Whatever context the invoking agent has — a question, a document reference, a vendor alert, a workflow step from another MCP server (Jira, GitHub, Slack). Composes with everything else the buyer's agent stack does.
Outputs
Cited answers grounded in the customer's evidence chain · questionnaire responses with per-question citations · vendor tier changes · exposure computations · scoped M&A data rooms. Every output signed to the Evidence Graph regardless of which agent invoked it.
Evidence
Three architectural guarantees make the composability safe: caller-entitlement scoped (APRI uses the invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519-signed on the Evidence Graph, so an auditor re-derives who did what regardless of human-vs-Claude), and observe-first (writes go through a confirmation gate — no silent mutation by an autonomous agent).
Fails when
Buyer's primary constraint is 'pre-completed vendor profiles at scale' rather than 'my team's agents need to reach vendor operations' — ProcessUnity's Global Risk Exchange is not something APRI substitutes for.
§4.5

Portfolio-concentration risk

ProcessUnity Risk Index scores individual vendors. QCD Pillar 2 applies portfolio-level HHI concentration analysis.

ProcessUnity

ProcessUnity Risk Index — 'the industry's first controls-driven risk rating.' Combines internal control intelligence (assessments + Global Risk Exchange profiles) with external security signals (threat feeds; sources not named on the public page). Continuous refresh on external signals; per-vendor score.

Inputs
Internal assessment data + external threat feeds.
Outputs
Continuous per-vendor risk score, tunable weights.
Evidence
Public product page describes the index as continuous and controls-driven.
Fails when
Buyer needs portfolio-level concentration analysis — 'we depend too heavily on one vendor category or one vendor.' Individual-vendor scoring does not surface this. Buyer overlays a separate concentration analysis or accepts the blind spot.
vCISO Lite QCD Pillar 2

QCD Pillar 2 tells your CFO — as a dollar figure — how much you're on the hook for if your most-concentrated vendor exposure turns bad. ProcessUnity's Risk Index scores vendors one at a time; the portfolio-concentration answer isn't in it.

Inputs
Vendor inventory + per-vendor Max Single-Vendor Loss estimate + portfolio-level HHI computation.
Outputs
Expected Annual Cost from concentration · P90 tail figure · portfolio-level risk narrative for board reporting.
Evidence
Codified from Yolonda's 2026 book Someone Else's Debt as productized IP inside the QCD product.
Fails when
Buyer needs continuous refresh on individual vendor cyber ratings (ProcessUnity's Risk Index is designed for that) rather than portfolio concentration analysis (QCD Pillar 2 is designed for that).

Framework & control coverage

Framework depth§5

Both vendors claim 250+ frameworks. ProcessUnity’s corpus is a parallel content library with 1,000+ controls; vCISO Lite’s corpus is SCF-native with 1,468 universal controls — every SCF-mapped control unlocks the frameworks that share it. ProcessUnity ships named regulatory accelerators (DORA, APRA CPS 230, ABAC, LkSG) as pre-mapped content packs.

ProcessUnity[6]

SOC 2
ISO 27001
NIST CSF
HIPAA
PCI DSS
DORA
APRA CPS 230
ABAC
LkSG
GDPR
NIST 800-53
NIST 800-171

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Direct-buy floor vs enterprise implementation§6

ProcessUnity is Standard/Enterprise SaaS with no dollar figure surfaced without a scoping call. vCISO Lite starts at $299/mo Starter (5 vendors + 5 vendor questionnaires answered), with additional tiers on /pricing. And vCISO Lite ships productized TPRM services on top of the platform — ProcessUnity ships the platform only.

ProcessUnity

Enterprise SaaS

Standard / Enterprise tiers · no public dollar figure without scoping call[9]

Sold to
Mid-market and enterprise buyers with dedicated TPRM functions
Published tiers
None — “Explore Pricing Plans” leads to ROI calculator + demo request
Standard tier
Multi-tenant TPRM platform · per-account SaaS pricing not disclosed
Enterprise tier
“Adds a separately quoted edition fee” per the pricing page
Delivery model
Sales-led · implementation-heavy · demo-gated
Sales cycle
Request-a-demo → scoping call → implementation
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month. Additional tiers on /pricing.
Platform + services
vCISO Lite ships the platform and productized TPRM services (managed CAIQ / SIG completion, analyst-driven vendor assessments) on /services. ProcessUnity ships the platform only.
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

ProcessUnity references “Integrations” on the platform surface but does not enumerate a public catalog. vCISO Lite’s full catalog is on /features/integrations.

IntegrationProcessUnityvCISO Lite
AWSNative
AzureNative
GCPNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365Native
OktaNative
JiraNative
SlackNative
ServiceNowNative
MCP (Model Context Protocol)Native
Shared vendor exchange (Global Risk Exchange)Native
Integration catalog published?Referenced, not enumeratedFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributeProcessUnityvCISO Lite
Service modelSaaS multi-tenant · TPRM specialist · workflow chassis + shared vendor exchangeSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
Public APINot enumerated on public product surfaceREST + MCP (Model Context Protocol) tool graph · OpenAPI 3.0
SSO / SCIMNot publicly disclosed on product pageSAML 2.0 · OIDC · SCIM 2.0
Audit-trail modelPlatform-internal store · no external anchor / per-event signing / transparency log disclosedEvidence Graph · hash-chained per-event · Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Vendor-incident-response product“Incident Management” listed as customer use case; no productized product lineDC-TPIR · GA 2026-06-04 · codified per-incident-type playbooks · methodology from Someone Else’s Breach
Where the AI actually runsInside the ProcessUnity UI · buyer’s Claude / Cursor / partner agents cannot invoke vendor operations directlyCallable from any MCP-speaking client (Claude, Cursor, custom LLMs, partner stacks, autonomous loops) · every invocation Ed25519-signed to Evidence Graph · caller-entitlement scoped · observe-first on writes
Autonomous execution layerNot separately productizedTrustworthy Autonomy (public beta 2026-07-07) · Level 1 agent governance proven prod 2026-08-17 · published evaluation harness · trace format published
Portfolio-concentration risk primitiveIndividual-vendor Risk Index onlyQCD Pillar 2 (HHI concentration) codified from Someone Else’s Debt
Own complianceNot publicly disclosedSOC 2 Type II · ISO 27001 (in progress) · runs on itself

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside ProcessUnity

A PDF business case, personalized to your company, that lays out the three options — no TPRM platform, ProcessUnity, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen ProcessUnity's HyperTPRM pitch and needs to see what the integrated vCISO + GRC + services + DC-TPIR alternative actually delivers.

View pricing

Notes & sources

Provenance§10
  1. [1] ProcessUnity Global Risk Exchange (370,000+ curated vendor risk profiles absorbed via the 2023 CyberGRX merger; 1M+ vendor responses collected; 600,000+ third parties under management) from processunity.com/hypertprm and processunity.com/about-us (accessed 2026-09-15).
  2. [2] vCISO Lite DC-TPIR (Dependency-Centric Third-Party Incident Response) — codified per-incident-type playbooks with contractual mapping and communication templates. Executive brief on vcisolite.com/briefs-and-specs; sits under the Allotrope umbrella. Source methodology is Yolonda’s 2026 book Someone Else’s Breach, named on vcisolite.com/about as foundational IP inside the vendor-incident capability. ProcessUnity solutions page (processunity.com/solutions) lists “Incident Management” as a customer use case and “Threat & Vulnerability Response” as a threat-monitoring product — no productized third-party-incident-response product line.
  3. [3] vCISO Lite Evidence Graph (hash-chained records + per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) verified against live platform state and Refraction Kernel launch series. ProcessUnity audit-trail characteristics from processunity.com (no external-anchor / per-event signing / transparency-log mechanism disclosed on the product surface).
  4. [4] QCD Pillar 2 (Third-Party & Vendor Concentration) Herfindahl-Hirschman Index concentration penalty (HHI < 1500 = unconcentrated / 1500–2500 = moderate 0.10 / > 2500 = highly concentrated 0.25), combined with Max Single-Vendor Loss for Expected Annual Cost + P90, from vCISO Lite’s QCD methodology (codified from Yolonda’s 2026 book Someone Else’s Debt, named on vcisolite.com/about). ProcessUnity Risk Index (individual-vendor continuous scoring) from processunity.com/hypertprm.
  5. [5] ProcessUnity + CyberGRX 2023 merger (CyberGRX vendor-exchange assets folded into what is now the Global Risk Exchange) from the ProcessUnity + CyberGRX 2023 merger press release.
  6. [6] ProcessUnity framework corpus (“250+ frameworks, regulations and standards” + “1,000+ cybersecurity and enterprise controls in library” + regulatory accelerators for DORA, APRA CPS 230, ABAC, LkSG) from processunity.com/about-us and processunity.com/hypertprm. vCISO Lite framework corpus (250+ SCF-cross-mapped frameworks + 1,468 universal controls) verified against live vcisolite.com/features/compliance.
  7. [7] vCISO Lite APRI (MCP tool graph + evidence-backed answer surface; live MCP endpoint at mcp.vcisolite.com; three architectural guarantees: caller-entitlement scoped, complete tool-call audit trail, observe-first with confirmation gates on writes) verified against vcisolite.com/titanium and MCP endpoint listing at claude.ai/directory. ProcessUnity TPRM AI Agents + Assessment Autofill + Evidence Evaluator descriptions from processunity.com/hypertprm.
  8. [8] Trustworthy Autonomy (public beta 2026-07-07, Level 1 agent governance proven in production 2026-08-17, published evaluation harness) from vcisolite.com/trustworthy-autonomy and vcisolite.com/press/trustworthy-autonomy.
  9. [9] ProcessUnity pricing (Standard & Enterprise SaaS editions; “Explore Pricing Plans” leads to ROI calculator + demo request; no specific dollar figure surfaced on the primary tier without scoping conversation) from processunity.com (accessed 2026-09-15). vCISO Lite platform tiers from vcisolite.com/pricing; productized TPRM services from vcisolite.com/services.
  10. [10] vCISO Lite Enterprise SKU bundling (SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, DORA, NYDFS Part 500, HITRUST, CJIS, CMMC, ISO 42001, NIST AI RMF, TPRM, plus Trustworthy Autonomy + Evidence Graph + APRI + productized services on one contract) from vcisolite.com/pricing. ProcessUnity as TPRM specialist (broader compliance not on the same SKU) from processunity.com/solutions.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If ProcessUnity ships a productized third-party-incident-response product or an externally-anchored evidence chain since publication, corrections at /contact.
  12. This page does not compare against other TPRM / TPCRM vendors on their own merits — Panorays (attack-surface-based cyber ratings) is the closest adjacent comparison and belongs on its own page. Riskonnect is not compared here (it’s a Salesforce-native multi-domain enterprise RMIS where TPRM is one SKU of 20+; the vCISO Lite comparison against Riskonnect lives on the Risk / CRQ / Risk-Intelligence axis and belongs in a separate batch).