Technical evaluation

vCISO Lite versus Safe Security

Safe Security is the Forrester Wave CRQ Solutions Q2 2025 Leader, with a Fortune-500 customer base and the analyst cite the whole category gets measured against. vCISO Lite runs cyber risk quantification inside a broader vCISO + GRC + services platform from $299/mo — with a productized M&A cyber diligence service, an externally-anchored evidence chain, and risk operations your own AI agents can call.

Prepared
Method
Capability walk against Safe Security’s published product surface (safe.security, safe.security/products, safe.security/company/press-releases) and vCISO Lite’s live platform.
Sources
safe.security, safe.security/products/safe-crq, safe.security/products/safe-x, Forrester Wave CRQ Solutions Q2 2025 announcement, Gartner MQ Exposure Assessment Platforms 2025, Balbix acquisition press (Nov 2025), vcisolite.com/pricing, vcisolite.com/diligence, vcisolite.com/evidence-graph, vcisolite.com/briefs-and-specs. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where Safe Security leads

  • Forrester Wave CRQ Solutions Q2 2025 — Leader. Ranked highest in Strategy category and vision criterion. Highest possible scores in 21 criteria. Only vendor Forrester cited with FAIR-CAM capability.[6]
  • Gartner MQ Exposure Assessment Platforms 2025 — Visionary. Distinct analyst placement in the exposure category, layered on top of the CRQ Leader cite.
  • Fortune-500 customer roster. Homepage names T-Mobile, Fannie Mae, Verizon, Delta, Honeywell, S&P Global, HP, AAA, ADP, Chipotle. Case studies span Booz Allen Hamilton, San Francisco Health Plan, Aboitiz Power, OB Hospitalist Group, Carvana, Victoria’s Secret, Instacart. TPRM module hit $10M ARR in under a year.
  • RiskLens Monte Carlo engine + Cyentia IRIS dataset. Absorbed the RiskLens engine and its actuarial pedigree; historically drew on Cyentia IRIS (150K+ historical loss events, 2008-2024) for distribution calibration.
  • CTEM via Balbix acquisition (Nov 2025). AI-native exposure management unified with CRQ on one platform. AI-SPM (May 2026) covers ChatGPT/Claude/Gemini/Copilot posture. Not a vCISO Lite category.[7]
  • $170M+ raised through Series C. Palo Alto HQ, John Chambers early investor, Series C Jul 31 2025 ($70M, Avataar Ventures lead). Enterprise scale vCISO Lite doesn’t touch.

Where vCISO Lite leads

  • Per-control what-if (the FAIR-CAM primitive) shipped in production. vCISO Lite lets you quantify how a specific control’s frequency reduction and magnitude reduction shift ALE for a specific loss event, re-run through the same 10,000-iteration seed-deterministic Monte Carlo engine. Output: ALE reduction in dollars, Loss Exceedance Curve delta, NPV, payback (10% discount, 3-year). Callable from any MCP-speaking agent through APRI. Safe holds the FAIR-CAM analyst-cite; vCISO Lite ships the underlying mechanic.[1]
  • Evidence Graph — externally-anchored, SDK-licensable. Every CRQ artifact Ed25519-signed and anchored to an external RFC-3161 timestamp authority + transparency log. A SOC 2 auditor, cyber-insurance carrier, or M&A diligence reviewer can prove the chain wasn’t tampered with, without trusting vCISO Lite. Safe’s board-report surface is dollarized-narrative, not auditor-grade cryptographic evidence.[4]
  • Risk operations callable from your own AI agent stack. APRI at mcp.vcisolite.com exposes per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval to any MCP-speaking client — Claude, Cursor, custom LLMs, autonomous loops. Safe’s AI Co-Workers + SAFE X mobile assistant stay inside SAFE One; no public MCP surface, no published action catalog, no published foundation-model choice.[5]
  • QCD 5-pillar CCOD — productized M&A cyber diligence. 72-hour deliverable, defensible at the IC, methodology codified in Yolonda’s 2026 book Someone Else’s Debt. Attack Surface + Third-Party & Vendor Concentration + Data Sensitivity + Program Maturity + Integration & Post-Close Risk = one dollar figure. Safe has no M&A diligence surface.[8]
  • Own security posture published. SOC 2 Type II + ISO 27001 posture visible on /about. Safe has no public trust portal at trust.safe.security and no published SOC 2 report or ISO 27001 certificate on public pages.[9]
  • Published pricing from $299/mo at /pricing. Safe is enterprise-sales-led with no public floor.[10]
  • Published foundation-model choice. vCISO Lite discloses which model powers APRI (Anthropic Claude family). Safe’s LLM stack is a black box — no published foundation-model choice for any of its AI Co-Workers.
  • Trustworthy Autonomy proven in production. Level 1 agent governance proven in production 2026-08-17. Safe’s “100+ AI agents” and “fully autonomous CTEM” marketing describe monitor + assess + correlate + investigate + escalate + prioritize verbs; no autonomous remediation / patching / config-change execution documented.
  • Founder-direct. [email protected] reaches the founder, not an SDR queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
CISOs, CROs, and CFOs comparing an enterprise CRQ leader (Safe Security) against CRQ inside a broader vCISO + GRC + services program (vCISO Lite). Especially useful for buyers who need FAIR-CAM per-control what-if as a shipped primitive, AND cryptographically-anchored evidence for the CRQ output, AND CRQ operations callable from their own Claude / Cursor / agent stack.
Evaluation frame
Ten capability categories the CRQ buyer typically weighs — FAIR-CAM primitive, Monte Carlo engine mechanics, Loss Exceedance Curve output, evidence integrity foundation, MCP callability, insurance/analyst pedigree, CTEM/AI-SPM adjacency, M&A diligence surface, own trust posture, published pricing. Not: everything each vendor does.
Comparison basis
Safe Security’s published product surface (safe.security, safe.security/products/safe-crq, safe.security/company/press-releases) + Forrester Wave CRQ Solutions Q2 2025 announcement + Gartner MQ Exposure Assessment Platforms 2025 + Balbix acquisition press. vCISO Lite’s live platform. Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

CTEM / AI-SPM head-to-head
Safe absorbed Balbix (Nov 2025) for AI-native exposure management and shipped AI-SPM (May 2026) covering ChatGPT/Claude/Gemini/Copilot. vCISO Lite’s scanner-service surface is not a peer to Balbix at that depth. If the buyer needs unified CTEM + CRQ on one platform, Safe is the right choice — the CTEM comparison is not this page’s scope.
Enterprise TPRM head-to-head
SAFE TPRM (“world’s first fully autonomous TPRM”) hit $10M ARR in under a year. That’s a distinct product category. TPRM-only buyers should see /vs/panorays and /vs/processunity. vCISO Lite ships TPRM inside the platform but doesn’t compete on autonomous TPRM as a standalone category.
FAIR Institute badge status
Safe Security holds the FAIR-CAM analyst-cite via Forrester Q2 2025. There is no formal FAIR Institute FAIR-CAM certification — badge status is accumulated recognition (Corporate Membership + workgroup contribution + FAIRCON presence + analyst cite). vCISO Lite ships the underlying FAIR-CAM mechanic; the analyst-positioning work is on the roadmap.

Capability coverage

Ten capabilities§3

Amber = Safe Security ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

EXTERNAL DATA SOURCESCyentia IRIS150k+ loss events · 2008–2024Customer telemetrySAFE integrations · CTEM signalsPeer benchmarksindustry-vertical calibration(SAFE CRQ Calculator)calibrateSAFE ONE PLATFORMFAIR / FAIR-CAM / FAIR-MAM / FAIR-TAMmethodology stack · only Forrester-cited FAIR-CAMdrivesRiskLens Monte Carlo enginetrial count not publicly published(inherited from RiskLens acquisition)Outputs: ALE · LEC · LM · Likelihood decompBalbix (CTEM, Nov 2025)AI-SPM · AI Co-Workers · SAFE X mobileExecutive Board Reporting6 pillars · dollarized narrativeBoard readouts · auditor-narrative · Fortune-500 procurement (T-Mobile, Verizon, Delta, S&P Global)no public trust.safe.security portal
Cyentia IRIS and customer telemetry calibrate a FAIR methodology stack that feeds the inherited RiskLens Monte Carlo engine, with Balbix, AI-SPM, and SAFE X mobile riding the same platform.
§4.1

FAIR-CAM primitive — per-control what-if

Both ship the mechanic. Safe holds the Forrester analyst-cite; vCISO Lite ships the primitive in production and is doing the analyst-positioning work.

Safe Security

Only vendor Forrester cited with FAIR-CAM (Controls Analytics Model) capability in the Q2 2025 CRQ Wave. Positions FAIR-CAM as a core methodology inside SAFE CRQ.

Inputs
Scenario definition · control catalog · FAIR / FAIR-CAM / FAIR-MAM / FAIR-TAM methodology stack applied against SAFE One's data model.
Outputs
ALE + Loss Exceedance Curve + LM + Likelihood decomposition per scenario; controls-analytics roll-up per board-report pillar.
Evidence
Forrester Wave CRQ Solutions Q2 2025 — 'only vendor identified with FAIR-CAM capability.' No public source snippet of the control-what-if API contract or JSON response shape.
Fails when
Buyer requires the mechanic exposed as a callable API (MCP or otherwise) so an external agent can invoke controls-what-if continuously without dashboard interaction.
vCISO Lite

Per-control frequency reduction and magnitude reduction re-run the target scenario through the same 10,000-iteration seed-deterministic Monte Carlo engine. Callable from any MCP-speaking agent through APRI.

Inputs
Target scenario or risk name; the control's frequency reduction and magnitude reduction (0–1 fractions); optional implementation cost and annual cost for ROI computation.
Outputs
Baseline and projected numbers side-by-side: Expected (ALE), BestCase, Severe, Worst, and full Loss Exceedance Curve. Plus ALE reduction in dollars and percent, and ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Every invocation Ed25519-signed to the Evidence Graph. Safe holds the FAIR-CAM analyst-cite; the vCISO Lite analyst-positioning work is on the roadmap.
Fails when
Buyer's procurement filter requires the Forrester Wave CRQ Leader badge specifically today. That's Safe Security's ceded ground.
§4.2

Monte Carlo CRQ engine

Safe ships the RiskLens engine — actuarial pedigree via absorption. vCISO Lite ships 10K seed-deterministic Monte Carlo — every simulation reproducible for audit.

Safe Security

SAFE CRQ runs on the RiskLens Monte Carlo engine (RiskLens absorbed by Safe pre-2023). Historically drew on the Cyentia IRIS dataset (150K+ historical loss events, 2008-2024).

Inputs
Scenario definition · Cyentia IRIS calibration · customer telemetry · SAFE CRQ Calculator peer-benchmark distributions.
Outputs
ALE, Loss Exceedance Curve, Loss Magnitude, Likelihood decomposition per scenario.
Evidence
Marketing frames engine as FAIR + FAIR-CAM + FAIR-MAM + FAIR-TAM; trial count not publicly published; RiskLens ancestry documented via prior press.
Fails when
Auditor wants to reproduce a specific quantification against fixed inputs. Trial count and seed handling are platform-internal, not published as reproducible-for-audit primitives.
vCISO Lite CRQ engine

10,000-iteration seed-deterministic Monte Carlo. Every simulation is reproducible for audit — identical inputs produce identical outputs.

Inputs
Scenario definition drawn from the risk register; frequency low/high; magnitude low/high; control effectiveness; optional what-if control frequency and magnitude reductions.
Outputs
Baseline and projected ALE with percentile bands, full Loss Exceedance Curve, ALE reduction in dollars and percent, ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Trial count engineered for sub-30-second per-org runtime across the risk register. Every simulation is Ed25519-signed to the Evidence Graph.
Fails when
Buyer specifically requires the Cyentia IRIS dataset or an insurance-carrier-grade actuarial dataset — Safe's inherited RiskLens pedigree is genuine strength there.
§4.3

Externally-anchored evidence chain

SAFE One board-report surface is dollarized-narrative. vCISO Lite's Evidence Graph is auditor-grade cryptographic evidence.

Safe Security

SAFE One records CRQ inputs, outputs, and scenario histories in the platform's internal store. Executive Board Reporting is customizable, exportable for board packets and audit committees.

Inputs
CRQ scenario runs, control assessments, TPRM data, CTEM signals — all inside the SAFE One tenant.
Outputs
Real-time dashboards per C-suite persona; six-pillar board report (Posture, Material Risk, Incident Reporting, Compliance, Metrics/KPIs, Program Investment); Google Slides template as lead-gen artifact.
Evidence
Marketing surface confirms customizable exports and six-pillar dashboard. No hash-chain / tamper-evidence / cryptographic per-event signing / external timestamp anchor disclosed.
Fails when
Auditor, insurance carrier, or M&A diligence reviewer needs to verify the chain wasn't tampered with post-hoc, without trusting the vendor. That's what an external anchor solves.
vCISO Lite Evidence Graph

Every CRQ artifact — scenario inputs, simulation results, controls-what-if outputs, APRI answers, autonomous actions — is Ed25519-signed and anchored to an external RFC-3161 timestamp authority + transparency log. SDK-licensable since 2026-08-15.

Inputs
Every state change on the platform — score writes, evidence uploads, control attestations, agent actions, APRI answers.
Outputs
Signed event stream with hash-chain integrity; verify endpoint returns provenance for any single event; transparency log lets a third party re-derive the chain.
Evidence
/evidence-graph documents Ed25519 signing (shipped 2026-08-16), RFC-3161 external timestamp anchor (live 2026-08-20), SDK licensability (2026-08-15). Verifier cron transitions PENDING checkpoints to VERIFIED.
Fails when
Buyer's primary requirement is the Forrester Wave analyst-cite on the evidence surface. There is no such cite for cryptographic evidence chains today — the CRQ Wave measures methodology, not tamper-evidence.
§4.4

CRQ operations callable from your own agent stack

Safe's AI Co-Workers + SAFE X mobile stay inside SAFE One. APRI exposes CRQ operations to any MCP-speaking client — your Claude, Cursor, or custom LLM can invoke them directly.

Safe Security

SAFE X mobile assistant + AI Co-Workers (CISO, TPRM, CTEM, Continuous Monitoring, Financial Quantification, Enterprise Aggregation, Peer Benchmarking) + Agentic Workflow Engine run inside SAFE One. Marketing says 100+ AI agents.

Inputs
User interactions inside SAFE One's UI or SAFE X mobile app.
Outputs
Q&A/advisory surface; monitor / assess / correlate / investigate / escalate / prioritize verbs. No autonomous remediation / patching / config-change execution documented.
Evidence
No LLM-callable API surface documented, no MCP server disclosed, no published action catalog / tool graph, no published foundation-model choice. External Claude / Cursor / partner agents cannot invoke SAFE CRQ operations.
Fails when
Buyer's team lives in Claude / Cursor / their own LLM and wants CRQ work to happen there. Or a partner (M&A diligence firm, insurance carrier) wants to wire CRQ outputs into their own agent stack. Or an autonomous agent needs to invoke controls-what-if continuously.
vCISO Lite APRI

APRI at mcp.vcisolite.com exposes CRQ operations as callable MCP tools. Any Claude, Cursor, custom LLM, or autonomous loop can invoke per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval directly.

Inputs
Whatever context the invoking agent has — scenario ID, control candidate, risk threshold, workflow step from another MCP server.
Outputs
Same projection, delta, and ROI response the platform returns. Every invocation Ed25519-signed to the Evidence Graph regardless of which agent called it.
Evidence
Three architectural guarantees make composability safe: caller-entitlement scoped (invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519 on the Evidence Graph), observe-first (writes go through a confirmation gate). Published foundation-model choice (Anthropic Claude family).
Fails when
Buyer's primary constraint is 'we need CRQ but our agents don't need to invoke it' — Safe's inside-the-UI AI is fine for that shape.
§4.5

M&A cyber diligence as productized SKU

Safe has no M&A cyber diligence surface. vCISO Lite ships QCD 5-pillar CCOD as a 72-hour productized service.

Safe Security

Enterprise CRQ + CTEM + TPRM + AI-SPM is Safe's platform. M&A cyber diligence as a productized deliverable is not a Safe surface.

Inputs
N/A — no diligence product on public surface.
Outputs
N/A.
Evidence
Public product surface has no /diligence, /qcd, or M&A-diligence-branded page.
Fails when
Buyer is deal-team-side (PE, M&A) needing pre-close cyber-diligence deliverable in days, not weeks, defensible at Investment Committee.
vCISO Lite QCD

Quantitative Cyber Diligence — 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) productized at /diligence. 72 hours from kickoff to a deliverable defensible at the Investment Committee.

Inputs
Target company scope + engagement letter · public attack surface data · contracts and vendor list where accessible · framework attestations.
Outputs
Single-figure CCOD (Cyber Cost of Deal) with per-pillar decomposition · defensible narrative for the IC · portable format (ephemeral by design).
Evidence
Codified from Someone Else's Debt (Yolonda Smith, 2026). Published pillar-by-pillar on /diligence.
Fails when
N/A on the diligence axis — Safe has no comparable productized diligence surface.

Framework & control coverage

Framework depth§5

Safe positions the CRQ platform against FAIR (primary), FAIR-CAM, FAIR-MAM, FAIR-TAM, MITRE ATT&CK, NIST CSF, SEC, DORA, NIS2, HIPAA, NYDFS 500 — deep on FAIR-family plus regulatory hooks. vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls) — every SCF-mapped control unlocks the frameworks that share it.

Safe Security[6]

FAIR
FAIR-CAM
FAIR-MAM
FAIR-TAM
MITRE ATT&CK
NIST CSF
SEC cyber
DORA
NIS 2
HIPAA
NYDFS 500

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

Enterprise sales-led vs published direct-buy§6

Safe Security is enterprise-sales-led with no dollar figure surfaced without a scoping call. Fortune-500 book. vCISO Lite starts at $299/mo Starter, with every tier price on /pricing.

Safe Security

Enterprise SaaS

Contact-sales · no public dollar figure[10]

Sold to
Fortune 500 CISOs, CROs, CFOs — T-Mobile, Verizon, Delta, Honeywell, S&P Global, HP
Published tiers
None — contact-sales for pricing
Free-trial entry
No
Delivery model
Sales-led · demo-gated · enterprise implementation
Sales cycle
Request-a-demo → scoping call → contract
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month + CRQ scenario runs. Additional tiers on /pricing.
Platform + services
vCISO Lite ships the platform and productized services (QCD M&A diligence, managed TPRM assessments) on /services.
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

Safe markets “100+ integrations” but does not enumerate the full catalog publicly. vCISO Lite’s full catalog is on /features/integrations.

IntegrationSafe SecurityvCISO Lite
AWSNativeNative
AzureNativeNative
GCPNativeNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365NativeNative
OktaNativeNative
JiraNativeNative
SlackNativeNative
ServiceNowNativeNative
MCP (Model Context Protocol)Native
CTEM / BalbixNative
AI-SPM (ChatGPT/Claude/Gemini/Copilot)Native
Integration catalog published?100+ marketed, not enumeratedFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributeSafe SecurityvCISO Lite
Service modelSaaS multi-tenant · SAFE One platform · CRQ + CTEM (Balbix) + TPRM + AI-SPM + SAFE X mobileSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
CRQ engineRiskLens Monte Carlo · FAIR / FAIR-CAM / FAIR-MAM / FAIR-TAM methodology stack · Cyentia IRIS calibration10,000-iteration seed-deterministic Monte Carlo · reproducible for audit · every simulation Ed25519-signed to the Evidence Graph
Per-control what-if (FAIR-CAM primitive)Only vendor Forrester cited with FAIR-CAM capability (Q2 2025 CRQ Wave)Per-control frequency reduction × magnitude reduction re-run through the same engine · ALE reduction in dollars + NPV + LEC delta · callable from any MCP-speaking agent through APRI
Loss dataset provenanceRiskLens ancestry: Cyentia IRIS (150K+ historical loss events, 2008-2024)QCD proprietary methodology (Someone Else’s Debt, 2026) · customer-engagement-grounded, not carrier-actuarial
M&A cyber diligence surfaceNot on public product surfaceQCD 5-pillar CCOD productized at /diligence · 72-hour deliverable · defensible at the IC
Audit-trail modelPlatform-internal store · no external anchor / per-event signing / transparency log disclosed · board reports customizable + exportableEvidence Graph · per-event Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Where the AI actually runsInside SAFE One · SAFE X mobile app · AI Co-Workers · Agentic Workflow Engine · no published MCP surfaceCallable from any MCP-speaking client via APRI at mcp.vcisolite.com · every invocation Ed25519-signed to Evidence Graph
Foundation-model choiceNot publicly disclosed for any AI Co-WorkerPublished (Anthropic Claude family) with model selection surfaced in Trustworthy Autonomy documentation
Analyst pedigreeForrester Wave CRQ Solutions Q2 2025 Leader · Gartner MQ Exposure Assessment Visionary 2025No CRQ-category analyst-cite today
CTEM / AI-SPM surfaceBalbix (Nov 2025) · AI-SPM (May 2026) for ChatGPT/Claude/Gemini/CopilotNot a peer at this depth
Own compliance postureNo public trust.safe.security portal · no published SOC 2 report or ISO 27001 certificate on public pagesSOC 2 Type II · ISO 27001 · posture published on /about

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside Safe Security

A PDF business case, personalized to your company, that lays out the three options — no CRQ platform, Safe Security, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen Safe Security's Forrester Wave CRQ Leader positioning and needs to see what the integrated vCISO + GRC + services + QCD alternative actually delivers with the FAIR-CAM primitive shipped + MCP-callable + Ed25519-signed.

View pricing

Notes & sources

Provenance§10
  1. [1] FAIR-CAM primitive. Safe Security cited by Forrester Q2 2025 Wave as the only vendor with FAIR-CAM (Controls Analytics Model) capability. vCISO Lite ships per-control frequency reduction × magnitude reduction re-run through the same Monte Carlo engine, returning ALE reduction in dollars, NPV, payback, and Loss Exceedance Curve delta. Callable from any MCP-speaking agent through APRI. Analyst-positioning work on the FAIR-CAM alignment is on the roadmap.
  2. [2] Monte Carlo engines. Safe Security ships the RiskLens Monte Carlo engine (RiskLens absorbed pre-2023) with historical Cyentia IRIS dataset calibration (150K+ loss events, 2008-2024). Trial count not publicly published. vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo engine (default trial count; identical inputs produce identical outputs).
  3. [3] Loss Exceedance Curve output for both vendors. Safe SAFE One board-report surface produces LEC + Loss Magnitude + Likelihood decomposition per scenario. vCISO Lite ships LEC alongside Expected (ALE), BestCase, Severe, and Worst percentile bands on every scenario and every per-control what-if.
  4. [4] vCISO Lite Evidence Graph (per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) from vcisolite.com/evidence-graph. Safe Security board-report characteristics from safe.security executive reporting product surface (no external anchor / per-event signing / transparency log disclosed).
  5. [5] vCISO Lite APRI (MCP tool graph exposing per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval; live at mcp.vcisolite.com) verified against vcisolite.com/titanium. Safe Security AI Co-Workers + SAFE X mobile assistant (inside SAFE One; no public MCP endpoint, no published action catalog, no published foundation-model choice) from safe.security/products/safe-x.
  6. [6]Analyst placement. Forrester Wave CRQ Solutions Q2 2025 Leader announcement (Jun 18, 2025) — “ranked highest in Strategy category and vision criterion,” highest possible scores in 21 criteria, only vendor with FAIR-CAM capability. Gartner MQ Exposure Assessment Platforms 2025 Visionary placement. Both from Safe Security press-release history at safe.security/company/press-releases.
  7. [7] CTEM via Balbix acquisition (Nov 18, 2025) and AI-SPM launch (May 28, 2026) covering ChatGPT/Claude/Gemini/Copilot, both from safe.security press-release history. RiskLens absorption confirmed via prior press history and current SAFE CRQ methodology framing.
  8. [8] QCD 5-pillar CCOD (Cyber Cost of Deal) productized as M&A cyber diligence service from vcisolite.com/diligence. Methodology codified in Yolonda Smith’s 2026 book Someone Else’s Debt. Framework coverage (250+ SCF-cross-mapped frameworks + 1,468 universal controls) verified against live vcisolite.com/features/compliance.
  9. [9] Safe Security own trust posture: trust.safe.security portal not visible; no SafeBase/Vanta trust page surfaced; no published SOC 2 report or ISO 27001 certificate on public pages as of 2026-09-16. vCISO Lite SOC 2 Type II + ISO 27001 posture published on vcisolite.com/about.
  10. [10] Safe Security pricing (enterprise sales-led; no public dollar figure; no free-trial entry on public site) from safe.security/pricing (redirects to contact form). vCISO Lite platform tiers ($299/mo Starter through $8,500/mo Enterprise MSRP) from vcisolite.com/pricing.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If Safe Security publishes an MCP endpoint, foundation-model choice, or externally-anchored evidence chain since publication, corrections at /contact.
  12. This page compares Safe Security (Forrester Wave CRQ Leader) against vCISO Lite (CRQ inside a broader vCISO + GRC + services SKU). It does not compare against other CRQ specialists on their own merits — the buyer evaluating dedicated CRQ platforms should also see /vs/kovrr and /vs/cybersaint. Enterprise IRM alternatives at /vs/riskonnect and /vs/servicenow-irm.