Control library and framework mapping
One library, mapped across frameworks, so a control proven once is proven everywhere it appears. Readiness is derived from the mapping, not asserted next to it.
oddly Security
A control library that scores itself from the evidence behind it. Security questionnaires answered from claims you have already attested. A risk register that recomputes instead of aging. Detectors that name a regression before a customer's security team does.
Built for the operator who owns compliance without owning a compliance department, and for the security lead whose evidence currently lives in a spreadsheet, a shared drive and their own head.
A control with no evidence source mapped to it scores zero and says so on the page. The honest gap is the feature. A green control nobody can evidence is the thing that fails an audit.
A control drops a level the moment its newest artefact falls outside its own service level, with no human involved in the demotion. Nobody marks a control healthy by hand.
Changes that touch access, money, stored data or the control plane itself cannot be released by the automation that wrote them. They need a named attestation on the exact commit under review.
oddly Security is not a document store with a dashboard on it. Each surface below is a running process with its own inputs, its own schedule and its own failure mode.
One library, mapped across frameworks, so a control proven once is proven everywhere it appears. Readiness is derived from the mapping, not asserted next to it.
Evidence arrives from the systems that already hold it, and every claim keeps a pointer back to the artefact it came from. A claim that loses its source loses its level.
Import a buyer's questionnaire, assemble the answers from attested claims, export it back in their format. The bottleneck in enterprise sales stops being your calendar.
A public page for what you can say openly, and a gated path for what needs a signature first. Both read the same posture, so they cannot disagree with each other. That surface is oddly Trust.
Scores derive from adapters over live posture rather than from a workshop held last quarter. A risk whose underlying control regressed moves without anyone reopening the register.
Cloud accounts, services and regions on one side, the automated decision systems and models you actually run on the other, both under a schema that survives being asked about in an assessment.
The estate is reconciled against what is really deployed, rotation is orchestrated rather than remembered, and drift between the two is a detector, not a discovery.
Every credential, every system, every account, closed out against a list that is generated rather than maintained. The evidence is the run, not a screenshot of it.
Continuity is reported from what has actually been exercised. Management system readiness, including the ISO 42001 track, is assessed against the same evidence model as everything else, not bolted on beside it.
Every control sits on one of five rungs. The rung is computed from the evidence, so it moves on its own, in both directions.
Detectors run against the posture itself. Each one exists because it has a specific way of being wrong that a dashboard cannot show you.
A control, a system or a person that everything else quietly depends on, surfaced before the dependency is discovered by their resignation.
The written policy and the running behaviour have diverged. Named as a gap between two things you already have, not as a request to write more policy.
A credential whose rotation schedule and actual rotation history no longer agree.
The parts of the estate where nothing would notice. Coverage is measured against the inventory, so growing the estate lowers the score until monitoring follows.
Whether an alert would actually reach a human inside the response window, tested rather than assumed.
oddly Security and oddly Commerce are not separate companies wearing the same logo. They run on the same engine: the same evidence model, the same gate classifier, the same rule that a system may not release its own control plane. One points that machinery at your marketing spend. The other points it at your security posture.
Deterministic commerce intelligence for merchants: benchmarks, prescriptions, and actions that are previewed before they are taken.
How it worksSecurity and maturity operations for the team that has to prove it: controls, evidence, questionnaires, risk and continuity. Its public face is oddly Trust, the trust centre a buyer can open without asking you first.
Open oddly Trustoddly Security is being built with a small number of teams who will have to live with the answer. If evidence is currently something you assemble under deadline, that is the conversation.