CERTIMAND EVIDENCE / EARLY ACCESS

AI does the
investigation.
You have
the evidence.

Know which access needs attention, why it matters, and what proves it. AI connects the evidence across your people, identities and engineering systems.

No sign-up. Synthetic data. See the reasoning for yourself.

THE ACCESS EVIDENCE LOOP01 / 03
HR rosterEntra IDGitHub
AI INVESTIGATION

One departure.
Two different realities.

01
Employment endedHR record · 01 Sep, 17:00 UTC
02
Directory account disabledEntra snapshot · confirmed
03
GitHub access still presentOrganisation membership · attention needed
Action neededEvery claim has a source.
Source → Check → Explanation → Evidence

Illustrative scenario from the working synthetic demo.

BUILT ON EXPERIENCE
IN DEMANDING ENVIRONMENTS

Goldman SachsABN AMROEuropean Patent Office

Founder’s prior professional experience.
Not Certimand customers or endorsements.

LESS CHASING. MORE CLARITY.

From scattered records
to an answer you can defend.

Your directory tells one part of the story. Your HR roster and downstream access tell the rest. Certimand brings them into the same investigation.

01

Bring the evidence together

Start with a defined population across HR, Entra and GitHub. Preserve the source, timestamp and what is missing.

One scope. Existing systems.
02

Let AI do the first investigation

AI explains the discrepancy, cites the facts and drafts the next action. Versioned rules establish the control result.

Useful reasoning. Visible sources.
03

Keep proof of the outcome

Review the action, verify a later snapshot and export the evidence. A closed ticket alone does not prove access was removed.

Human decisions. Reproducible results.

AI WITH SOMETHING TO STAND ON

An explanation is useful.
A trail of evidence
is valuable.

A prompt can summarise a spreadsheet. A dependable evidence process also needs source coverage, approved policy, history and proof of what changed.

Inspect a real demo finding
Source factsSeparate from AI interpretation
Control logicPinned and reproducible
Missing dataVisible, never a silent pass
RemediationVerified against a later snapshot
Your authorityAI proposes. People decide.

A FOCUSED START

Three sources.
One evidence workflow.

The public MVP demonstrates four checks using synthetic HR, Entra and GitHub records. Live customer connections are the next stage, subject to an agreed pilot scope.

H

HR roster

The employment facts: who joined, who left, and when.

Synthetic import model
E

Microsoft Entra ID

The directory facts: account status, ownership and authentication evidence.

Synthetic snapshot model
G

GitHub

The downstream facts: membership and workload ownership.

Synthetic snapshot model
See control coverage and limitations

FOR YOUR NEXT ACCESS REVIEW

Start with one
evidence problem.

For European businesses still stitching together access records by hand. A strong initial fit is a finance or technology team using Microsoft Entra and GitHub without a settled cross-system evidence process.

Already well served by your IGA or GRC platform? We start by checking whether there is a gap worth solving.

DESIGN-PARTNER PILOT

A fixed scope.
A tangible outcome.

One Entra tenant, one HR roster, one GitHub organisation. Agree the controls, evidence and success criteria before connecting anything.

  • Source and evidence-gap inventory
  • AI explanations tied to observed facts
  • Owned findings and verification steps
  • Reproducible evidence package

Fixed-fee validation.
Subscription intended for recurring use.

Check the fit

Scope, price and delivery dates agreed in writing. Early access; live onboarding is not yet self-service.

AUTHORITY YOU CAN PROVE.

European ambition.
Engineering substance.

Founded by Gustavo Rodríguez Suárez, with engineering experience at Goldman Sachs, ABN AMRO and the European Patent Office.

Certimand brings that background in identity, cloud and regulated environments to a repeatable software product for businesses across the EU.

Our starting point is access evidence. The long-term direction is reusable assurance infrastructure for digital services and critical supply chains, built around data provenance and accountable AI.

Meet the founder on LinkedIn

A FEW STRAIGHT ANSWERS

Before we talk.

Is this another compliance dashboard?

The focus is investigating access discrepancies and preserving the evidence behind them. We aim to fit alongside your existing identity, GRC and ticketing tools. The demo lets you judge the workflow before a sales conversation.

What does the AI actually do?

The live demo uses a generative AI model to explain selected findings, draft verification steps and prepare a management briefing from bounded synthetic evidence. It cannot change control outcomes or modify accounts. AI output is labelled and requires review.

Does Certimand certify DORA compliance?

No. The intended product supports evidence for defined identity and access controls. Applicability, legal interpretation and acceptance remain with your organisation and its advisers. The full DORA framework is outside this MVP.

Can our existing tools do this already?

Possibly. Microsoft Entra, IGA and GRC products already offer useful reviews and automation. Certimand is relevant only if a specific cross-system investigation or evidence task remains difficult. We check this before proposing a pilot.

Can partners use Certimand?

We welcome IAM partners, managed security providers and specialist compliance advisers who see the same recurring evidence problem across clients. Contact us about validating a repeatable partner offer; a multi-customer partner portal is not yet available.

LET’S FIND THE RIGHT STARTING POINT

Which access question
is taking too long
to answer?

Tell us about your systems and the evidence you need. We’ll use that to assess whether a focused pilot makes sense.

No mailing list. No customer identity files.
Just enough context to start a useful conversation.

Prefer a direct introduction? Contact Gustavo on LinkedIn.