Page map
Every route in the app, what the page is for, and the guide that covers it.
Routes are listed as they appear in the address bar; dynamic segments are shown
as [id]. Every page is visible to all roles unless the table says otherwise,
though which sections exist depends on the customer segment.
Main
| Route | Purpose | Guide |
|---|---|---|
/ | Overview dashboard | Overview |
/controls | Control list across enabled frameworks | Controls |
/controls/[id] | One control: status, owner, evidence, policies, risks, logs | Control detail |
/evidence-vault | Evidence list; ?evidenceId= opens one item | Evidence vault |
/policies | Policy list | Policies |
/policies/[id] | Policy editor; ?version= shows a historical version | Policy editor |
/assets | Asset inventory | Assets |
/data-sources | Connected data sources | Data sources |
/data-sources/[id] | One connection: sync log, settings | Data sources |
/security/findings | Security findings list | Findings |
/security/findings/[id] | One finding | Findings |
/security/certificates | Certificate inventory and expiry | Certificates |
/risk/register | Risk register | Risk register |
/risk/register/create | New risk form | Create and edit risks |
/risk/register/[id] | One risk: scoring, treatments, links | Create and edit risks |
/risk/reports | Live risk reports, snapshots, and PDF downloads | Risk reports |
/tasks | Work derived from every entity | Tasks |
/cortex | Cortex chat | Cortex |
/cortex/[id] | One Cortex conversation | Cortex |
People and vendors
| Route | Purpose | Guide |
|---|---|---|
/personnel/directory | People directory | People directory |
/personnel/awareness | Training plans, campaigns, policy acknowledgements | Training and acknowledgement |
/vendors/register | Vendor register | Vendor register |
/vendors/register/[id] | One vendor: assessment, contacts, evidence, DPA | Vendor detail |
/vendors/questionnaires | Questionnaire templates | Questionnaires |
/vendors/questionnaires/[templateId] | One template and its assignments | Questionnaires |
Audit and trust
| Route | Purpose | Guide |
|---|---|---|
/audit/calendar | Audit calendar | Audit calendar |
/audit/internal | Internal audit list | Internal audit |
/audit/internal/[id] | One internal audit: scope, tests, findings, report | Internal audit |
/audit/external | External audit engagements and evidence packages | External audit |
/trust-center | Trust page builder | Builder |
/trust-center/requests | Access requests to the trust page | Requests |
Privacy
| Route | Purpose | Guide |
|---|---|---|
/privacy | Privacy overview | Privacy |
/privacy/review | Inbox: drift, proposals, intake, AI drafts | Inbox |
/privacy/review/sources | Third-party OAuth grants observed in your identity provider, mapped to vendors | Connected apps |
/privacy/data-map | Data map explorer | Data map |
/privacy/ropa | Records of processing | Records of processing |
/privacy/ropa/article-30 | Article 30 register view and export | Records of processing |
/privacy/assessments | Assessment list | Assessments |
/privacy/assessments/[id] | One assessment | Assessments |
/privacy/monitoring | Monitored sites | Monitoring |
/privacy/monitoring/[monitorId] | One monitor and its scan history | Monitoring |
/privacy/monitoring/[monitorId]/scans/[scanId] | One scan result | Monitoring |
Settings and account
/settings and every tab under it are admin-only.
| Route | Purpose | Guide |
|---|---|---|
/settings?tab=general | Organization name, logo, deletion | General |
/settings?tab=billing | Billing status and the billing portal | Billing |
/settings?tab=context | Organization context for Cortex and policies | Context |
/settings?tab=members | Members and roles | Members |
/settings?tab=mfa | MFA requirement | Security |
/settings?tab=frameworks | Enable and disable frameworks | Frameworks |
/settings?tab=privacy | Controller details, covered regulations, data-subject regions, security-measure catalog | Privacy settings |
/settings?tab=developer | API keys | Developer |
/settings?tab=integrations | Integration settings | Integrations |
/account | Your profile, organization access, and notification preferences | Account |
/checkout-success | Return page after payment details are saved | Billing |
/org/select | Pick an organization | Sign in and accounts |
/org/new | Create an organization | Create your organization |
/mfa-required | Shown until you enrol MFA when the organization requires it | Security |
/oauth/mcp/consent | Approve an MCP client | MCP server |
Public
| Route | Purpose | Guide |
|---|---|---|
/sign-in | Sign in | Sign in and accounts |
/sign-up | Create an account | Sign in and accounts |
/trust/[trust-id] | Public trust page | Public trust page |
/training/attest/[assignmentId] | Training or policy attestation opened from an email link | Training and acknowledgement |
/vendor/assessment/[assignmentId] | Questionnaire a vendor fills in | Questionnaires |
Addresses that forward elsewhere
| If you open | You land on | Guide |
|---|---|---|
/evidence-vault/[id] | /evidence-vault?evidenceId=[id], with the item open in a drawer | Evidence vault |
/personnel/[id] | /personnel/directory | People directory |
/vendors/register/[id] of a merged vendor | The surviving vendor | Vendor detail |
/audit | /audit/internal | Internal audit |
/privacy/grants | /privacy/review/sources | Connected apps |
/settings as an editor or viewer | / | Roles and permissions |
Related
Last updated on