oddly

oddly Security

Security operations that keep their answer, not ones that rebuild it every audit.

A control library that scores itself from the evidence behind it. Security questionnaires answered from claims you have already attested. A risk register that recomputes instead of aging. Detectors that name a regression before a customer's security team does.

Built for the operator who owns compliance without owning a compliance department, and for the security lead whose evidence currently lives in a spreadsheet, a shared drive and their own head.

Nothing defaults to green

A control with no evidence source mapped to it scores zero and says so on the page. The honest gap is the feature. A green control nobody can evidence is the thing that fails an audit.

Freshness is computed

A control drops a level the moment its newest artefact falls outside its own service level, with no human involved in the demotion. Nobody marks a control healthy by hand.

The gate is a person

Changes that touch access, money, stored data or the control plane itself cannot be released by the automation that wrote them. They need a named attestation on the exact commit under review.

What it runs

oddly Security is not a document store with a dashboard on it. Each surface below is a running process with its own inputs, its own schedule and its own failure mode.

Controls

Control library and framework mapping

One library, mapped across frameworks, so a control proven once is proven everywhere it appears. Readiness is derived from the mapping, not asserted next to it.

Evidence

Claim sources and claim extraction

Evidence arrives from the systems that already hold it, and every claim keeps a pointer back to the artefact it came from. A claim that loses its source loses its level.

Sales

Security questionnaires, answered from your own claims

Import a buyer's questionnaire, assemble the answers from attested claims, export it back in their format. The bottleneck in enterprise sales stops being your calendar.

Sales

Trust centre and NDA-gated disclosure

A public page for what you can say openly, and a gated path for what needs a signature first. Both read the same posture, so they cannot disagree with each other. That surface is oddly Trust.

Risk

Risk register that recomputes

Scores derive from adapters over live posture rather than from a workshop held last quarter. A risk whose underlying control regressed moves without anyone reopening the register.

Estate

Cloud and model estate inventory

Cloud accounts, services and regions on one side, the automated decision systems and models you actually run on the other, both under a schema that survives being asked about in an assessment.

Secrets

Secret rotation, orchestrated and reconciled

The estate is reconciled against what is really deployed, rotation is orchestrated rather than remembered, and drift between the two is a detector, not a discovery.

People

Offboarding with a provable surface

Every credential, every system, every account, closed out against a list that is generated rather than maintained. The evidence is the run, not a screenshot of it.

Continuity

Continuity reporting and management system readiness

Continuity is reported from what has actually been exercised. Management system readiness, including the ISO 42001 track, is assessed against the same evidence model as everything else, not bolted on beside it.

The evidence ladder

Every control sits on one of five rungs. The rung is computed from the evidence, so it moves on its own, in both directions.

0No evidence sourceNothing is mapped. Scored zero and said out loud.
1Point in timeOne dated artefact, no recurrence.
2On a cadenceRepeated evidence on a schedule.
3ContinuousContinuously evidenced and fresh within its service level.
4Drift testedContinuous, fresh, and actively tested for drift.

What watches the watcher

Detectors run against the posture itself. Each one exists because it has a specific way of being wrong that a dashboard cannot show you.

Single point of failure

A control, a system or a person that everything else quietly depends on, surfaced before the dependency is discovered by their resignation.

Documentation drift

The written policy and the running behaviour have diverged. Named as a gap between two things you already have, not as a request to write more policy.

Rotation drift

A credential whose rotation schedule and actual rotation history no longer agree.

Detection coverage

The parts of the estate where nothing would notice. Coverage is measured against the inventory, so growing the estate lowers the score until monitoring follows.

Notification reachability

Whether an alert would actually reach a human inside the response window, tested rather than assumed.

One architecture, two products

oddly Security and oddly Commerce are not separate companies wearing the same logo. They run on the same engine: the same evidence model, the same gate classifier, the same rule that a system may not release its own control plane. One points that machinery at your marketing spend. The other points it at your security posture.

oddly Commerce

Deterministic commerce intelligence for merchants: benchmarks, prescriptions, and actions that are previewed before they are taken.

How it works

oddly Security

Security and maturity operations for the team that has to prove it: controls, evidence, questionnaires, risk and continuity. Its public face is oddly Trust, the trust centre a buyer can open without asking you first.

Open oddly Trust

Design partners first.

oddly Security is being built with a small number of teams who will have to live with the answer. If evidence is currently something you assemble under deadline, that is the conversation.