Security and privacy assessments, on the record.
Turaru takes a new system from intake to a signed decision. The business describes the change and links the design. Your architects review it, raise the risks, and the people accountable accept them. Every step is recorded with who did it and when.
Sign in to Turaru Sign in with your organisation's Microsoft account.How an assessment runs
Intake
A project lead answers a short set of questions and attaches the design document. Answers are drafted from the document and confirmed by the person.
Review
A security architect works through your organisation's own control areas, with the design and the intake answers beside them.
Risks
Risks are raised into a register with a rating and an owner. Medium and high risks go to the business owner and the CISO to accept or reject, with reasons.
Sign off
When every risk has a decision the assessment signs off. The record, the drafts, the edits and the signatures stay together.
Where it runs and who can see it
| Hosting | AWS, Sydney region. One deployment, each organisation's data walled off from every other. |
| Sign in | Microsoft Entra ID only. Roles come from your directory. Turaru holds no passwords. |
| AI | Runs in your own AWS account through Amazon Bedrock. Turaru never holds a credential for it. Every suggestion is labelled and kept apart from what a person wrote. |
| Your assessment design | Control areas and questions are yours to write and publish. Nothing is provisioned that you did not put there. |
| Built by | MindShield Security, Aotearoa New Zealand. |