Page map

Every route in the app, what the page is for, and the guide that covers it.

Routes are listed as they appear in the address bar; dynamic segments are shown as [id]. Every page is visible to all roles unless the table says otherwise, though which sections exist depends on the customer segment.

Main

RoutePurposeGuide
/Overview dashboardOverview
/controlsControl list across enabled frameworksControls
/controls/[id]One control: status, owner, evidence, policies, risks, logsControl detail
/evidence-vaultEvidence list; ?evidenceId= opens one itemEvidence vault
/policiesPolicy listPolicies
/policies/[id]Policy editor; ?version= shows a historical versionPolicy editor
/assetsAsset inventoryAssets
/data-sourcesConnected data sourcesData sources
/data-sources/[id]One connection: sync log, settingsData sources
/security/findingsSecurity findings listFindings
/security/findings/[id]One findingFindings
/security/certificatesCertificate inventory and expiryCertificates
/risk/registerRisk registerRisk register
/risk/register/createNew risk formCreate and edit risks
/risk/register/[id]One risk: scoring, treatments, linksCreate and edit risks
/risk/reportsLive risk reports, snapshots, and PDF downloadsRisk reports
/tasksWork derived from every entityTasks
/cortexCortex chatCortex
/cortex/[id]One Cortex conversationCortex

People and vendors

RoutePurposeGuide
/personnel/directoryPeople directoryPeople directory
/personnel/awarenessTraining plans, campaigns, policy acknowledgementsTraining and acknowledgement
/vendors/registerVendor registerVendor register
/vendors/register/[id]One vendor: assessment, contacts, evidence, DPAVendor detail
/vendors/questionnairesQuestionnaire templatesQuestionnaires
/vendors/questionnaires/[templateId]One template and its assignmentsQuestionnaires

Audit and trust

RoutePurposeGuide
/audit/calendarAudit calendarAudit calendar
/audit/internalInternal audit listInternal audit
/audit/internal/[id]One internal audit: scope, tests, findings, reportInternal audit
/audit/externalExternal audit engagements and evidence packagesExternal audit
/trust-centerTrust page builderBuilder
/trust-center/requestsAccess requests to the trust pageRequests

Privacy

RoutePurposeGuide
/privacyPrivacy overviewPrivacy
/privacy/reviewInbox: drift, proposals, intake, AI draftsInbox
/privacy/review/sourcesThird-party OAuth grants observed in your identity provider, mapped to vendorsConnected apps
/privacy/data-mapData map explorerData map
/privacy/ropaRecords of processingRecords of processing
/privacy/ropa/article-30Article 30 register view and exportRecords of processing
/privacy/assessmentsAssessment listAssessments
/privacy/assessments/[id]One assessmentAssessments
/privacy/monitoringMonitored sitesMonitoring
/privacy/monitoring/[monitorId]One monitor and its scan historyMonitoring
/privacy/monitoring/[monitorId]/scans/[scanId]One scan resultMonitoring

Settings and account

/settings and every tab under it are admin-only.

RoutePurposeGuide
/settings?tab=generalOrganization name, logo, deletionGeneral
/settings?tab=billingBilling status and the billing portalBilling
/settings?tab=contextOrganization context for Cortex and policiesContext
/settings?tab=membersMembers and rolesMembers
/settings?tab=mfaMFA requirementSecurity
/settings?tab=frameworksEnable and disable frameworksFrameworks
/settings?tab=privacyController details, covered regulations, data-subject regions, security-measure catalogPrivacy settings
/settings?tab=developerAPI keysDeveloper
/settings?tab=integrationsIntegration settingsIntegrations
/accountYour profile, organization access, and notification preferencesAccount
/checkout-successReturn page after payment details are savedBilling
/org/selectPick an organizationSign in and accounts
/org/newCreate an organizationCreate your organization
/mfa-requiredShown until you enrol MFA when the organization requires itSecurity
/oauth/mcp/consentApprove an MCP clientMCP server

Public

RoutePurposeGuide
/sign-inSign inSign in and accounts
/sign-upCreate an accountSign in and accounts
/trust/[trust-id]Public trust pagePublic trust page
/training/attest/[assignmentId]Training or policy attestation opened from an email linkTraining and acknowledgement
/vendor/assessment/[assignmentId]Questionnaire a vendor fills inQuestionnaires

Addresses that forward elsewhere

If you openYou land onGuide
/evidence-vault/[id]/evidence-vault?evidenceId=[id], with the item open in a drawerEvidence vault
/personnel/[id]/personnel/directoryPeople directory
/vendors/register/[id] of a merged vendorThe surviving vendorVendor detail
/audit/audit/internalInternal audit
/privacy/grants/privacy/review/sourcesConnected apps
/settings as an editor or viewer/Roles and permissions

Last updated on