Skip to content
Security assessment & remediation

Security assessments that end in proof, not a PDF

How HexaFlow designed and built SCORA: a platform that measures an organisation against nine security frameworks, turns every gap into owned work, checks and reads the evidence that closes it, and hands an auditor the record — in English and Arabic.

One finding, start to finish
Product
SCORA · scorasec.com
What we did
Product, design, engineering, AI
Languages
English · العربية
Markets
Gulf & international
Year
2026
9security frameworks, from NIST CSF 2.0 to Saudi NCA and Abu Dhabi ADEK
14assessments in the catalogue
895questions, each written in plain language
7checks on every evidence file before anyone can open it
2AI passes over every document — read in full, then judged
2languages, with Arabic content authored, not machine-translated
The problem

Assessments end in a PDF. Security doesn't.

Most organisations can't answer a simple question — how secure are we, actually? — so they pay a consultant to run a workbook once a year and leave a report. The report lists the gaps. Then nothing structured happens to them.

Nobody owns the findings. Nobody checks that a fix was really made. And when an auditor asks eighteen months later whether encryption was enforced, the answer is a policy document that says it should be — which is exactly the kind of evidence that proves nothing.

SCORA was built to close that loop: measure, assign, fix, prove, and keep the proof. The rest of this page follows one finding all the way round it.

01 Assess

A framework, asked the way people actually talk.

Control language assumes you already know the answer. SCORA asks each question the way the person answering would describe their own systems, with context on what is being asked and why it matters — so an IT manager can complete it, not just an assessor.

  • Branching skips what doesn't apply. The NIST CSF 2.0 baseline carries 89 branching rules, so a 170-question framework becomes a sitting, not a project.
  • Split between people and teams. By section or by single question, to a named person or to a whole department — who answers first can claim it.
  • Evidence while answering. Attach the document that proves a “Yes”, and it gets read before the score is final.
  • Save and resume, with every answer attributed to the person who gave it.
scorasec.com/assessments/iso-27001-readiness
Data Protection · Question 14 of 123
62%
Do you encrypt sensitive data at rest in databases or file systems?

Encrypting stored data protects it if physical devices or storage systems are compromised.

Yes
No
Not applicable
Unknown
Data-protection-policy.pdf
Supporting evidence · 1.8 MB · 38 pages
Falls short
Answered by Omar Haddad · IT & InfrastructureSave & next
Who is answering what
SectionHeld byAnswered
GovernanceGovernance & Risk14 / 14
Data ProtectionOmar Haddad9 / 11
Identity & AccessIT & Infrastructure6 / 12
Incident ResponseMaya Fares0 / 8

A team slice can be answered by anyone in it — or claimed, so two people never answer the same question.

02 The evidence is read

A “Yes” is a claim. The document is the proof.

Our example answered Yes and attached a 38-page data-protection policy. A policy that says data should be encrypted is not evidence that it is. SCORA reads the document and says so — and the finding stands despite the “Yes”.

Pass one

Read everything

Every page, in as many chunks as it takes — with the task's acceptance criteria in hand, so the one relevant screenshot on page 212 is noticed rather than summarised away.

Pass two

Then judge

The criteria and those observations, weighed against each other: satisfied, falls short, or cannot assess — with what the evidence showed and what it didn't.

The verdict advises; it never decides. A contributor is warned before submitting weak evidence, and the manager sees the verdict beside the Verify button. If they accept anyway, the report says so.

scorasec.com/remediation/tasks/encryption-at-rest
Encryption at Rest
Data Protection · High · due in 30 days
Falls short
Data-protection-policy.pdf
1.8 MB · read 38 of 38 pages · 4 passes
Clean
What the evidence showed
  • A dated data-protection policy requiring encryption of sensitive data (§4.2).
  • A named policy owner and an annual review date.
What it did not show
  • Any evidence encryption is enforced on a single endpoint or server.
  • Database-level encryption for the systems that hold customer data.

The contributor is warned before submitting and must acknowledge it — it never blocks, but going ahead is recorded. The manager sees it before verifying.

03 Score

Two scores, because fixing things should move one of them.

Domain-level maturity rolls up into an overall score and a readiness level, weighted per framework. That score is the dated record, and it never changes.

Beside it sits a second: the same answers re-scored as if every verified fix had been in place. The gap between the bars is work that has been proved — not promised.

  • Gaps ranked by impact against effort, so remediation has an order.
  • An executive brief and a technical summary, drafted by AI from the same assessment — in the reader's language.
  • PDF and Excel reports, and a read-only link to share results without an account.
scorasec.com/dashboard
Avg. maturity
46% → 73%
Active
3
Verified fixes
147
Maturity over time
As assessedAfter remediation
SME Cyber Health Check
ISO/IEC 27001:2022
NIST CSF 2.0 baseline
04 Assign

Every gap becomes a task — and finds its owner.

When the assessment is submitted, each finding becomes a task named for the work, not the question: “Encryption at Rest”, not “Do you encrypt sensitive data?”. It arrives with acceptance criteria, a reason it matters, implementation steps and a due date drawn from the recommended timeframe.

  • Routed automatically. Departments own security areas; each task goes to the team that owns its area.
  • A suggested owner — whoever in that team carries the fewest open tasks. A manager accepts one, or all of them at once.
  • Nothing assigned silently. Every acceptance writes a timeline entry, an audit row and a notification.
  • Work nobody can take is named. An area no department covers is flagged with the reason, not handed to someone at random.
  • Daily reminders for work coming due or overdue, and for unanswered assessment sections — never sent twice in quick succession.
scorasec.com/remediation/tasks
5 tasks have suggested owners · ISO/IEC 27001:2022 readiness
TaskRouted toOwnerStatus
Encryption at Rest
Data Protection
IT & InfrastructureOmar Haddadsuggested · 1 openUnassigned
Endpoint Protection (EPP/EDR)
Endpoint Security
IT & InfrastructureLina Salehsuggested · 1 openUnassigned
Multi-Factor Authentication
Identity & Access
IT & InfrastructureTariq Nabilsuggested · 1 openUnassigned
Incident Response Plan
Incident Response
Security OperationsMaya Faressuggested · 2 openUnassigned
Information Security Policy
Governance
Governance & RiskNoor Abbassuggested · 0 openUnassigned
Tested Backup Restores
Business Continuity
No department—Unassigned
1 task needs an owner

No department covers Business Continuity. Give it to a team and the backlog re-routes itself.

Suggestions go to whoever in the owning team carries the fewest open tasks.

05 Upload & check

A security product can't be a way in.

Evidence arrives from people outside the security team, as PDFs and Office documents. That is precisely how malware gets into organisations — so no file is opened by anyone until it has passed seven checks.

  • Straight to storage. Signed uploads mean file bytes never pass through the application server.
  • A type that lies is hostile. A “.pdf” whose bytes are an executable is quarantined, not waved through as a mistake.
  • Refused by what it does. Office macros, remote templates, PDF launch actions and zip bombs are stopped by structure, before any scanner — there is no signature to wait for.
  • Flagged for the reviewer. PDF JavaScript, auto-open actions and embedded files are allowed through, but marked.
  • Malware-scanned, with a scanner that proves itself nightly against a known test signature. A scanner that is down is never read as clean.
  • Kept as long as it matters. Assessment evidence for three years, remediation evidence for one — each file fingerprinted with SHA-256.
Supporting evidence · Encryption at Rest
bitlocker-compliance-report.pdf Clean · read
Upload authorisedA signed URL for exactly this file — name, size, type. 25 MB a file, 250 MB a task.
PASS
Sent straight to storageThe bytes never pass through the application server.
PASS
Arrival confirmedThe size in storage must match what was declared, or it is rejected.
PASS
Content matches its typeThe first bytes must be what the file claims to be.
PASS
Structure inspectedMacros, remote templates, launch actions and zip bombs are refused outright.
PASS
Malware scanClamAV, self-tested nightly. A scanner that is down is never read as clean.
PASS
Read by AIEvery page, against this task’s acceptance criteria.
PASS
06 Review

Done is not the same as verified.

A task moves through six states — unassigned, in progress, done, submitted, verified, returned — and the line between done and submitted is deliberate: finishing the work and asking for it to be checked are two different acts.

  • One review queue for everything awaiting a manager, with the evidence and the AI verdict in front of them.
  • Returned with a reason, and the reason travels with the task — every return is counted and reported.
  • Separation of duties, made visible. Work verified by the person who did it is marked self-attested, everywhere it appears.
scorasec.com/remediation/review
Review queue
3 awaiting you
Encryption at Rest
Submitted by Omar Haddad · 2 files · attempt 1
Satisfied
What the evidence showed
  • BitLocker on 214 of 214 managed endpoints, TPM-backed.
  • Recovery keys escrowed to the identity provider.
VerifyReturn with a reason
Self-attestedWhen the person who did the work also verifies it, the report says so — in orange.
07 Close

The report an auditor can actually rely on.

The closure report is the record of what was found, what fixed it and who checked it. Its first job is honesty: a finding closed with nothing attached, signed off by the person who did it, or accepted after the evidence was judged short — each is legitimate, and each is weak. So each is flagged, on an index page, and counted on page one.

  • Every finding in full — the gap, what closing it required, the evidence handed in, what it did and didn't show, and who accepted it.
  • A progress report or a closure report, decided by the work itself — never labelled “final” while anything is open.
  • PDF, Excel and a sealed pack — every evidence file with its SHA-256, so the record can be proved intact later.
  • Findings that stop applying stay in the record, flagged, rather than quietly disappearing with their evidence.
All findings at a glance
REMEDIATION CLOSURE REPORT
Programme complete — all findings verified.
Confidence in these closures
  • 2 of 4 closures carry something a reader should weigh
  • 1 closed with no evidence attached
  • 1 verified by the same person who did the work
  • 1 accepted after an automated read found the criteria still unmet
1 finding no longer applies and is listed for the record only
FindingDomainStatusFlags
Encryption at RestData ProtectionVerified—
Endpoint Protection (EPP/EDR)Endpoint SecurityVerifiedAccepted despite gaps
Security Awareness ProgramSecurity AwarenessVerifiedNo evidence · Self-attested
Perimeter FirewallNetwork SecurityVerified—
Tested Backup RestoresBusiness ContinuityNo longer applicableNo longer applicable
bitlocker-compliance-report.pdf · SHA-256 06efdb6d0fad93310f082bd68bc4d9f2c6c3…
Built for the Gulf

Arabic is a rendering, not a translation layer.

Every screen, email, notification and generated report exists in English and Arabic. The layout mirrors; the question, the task, its criteria and its reasoning are all authored in Arabic — and the PDFs are set in an Arabic face, not a Latin fallback.

Mixed text is handled line by line, so an Arabic sentence carrying BitLocker, TPM or LUKS reads correctly instead of breaking apart.

scorasec.com/ar/remediation/tasks/encryption-at-rest
التشفير أثناء السكون
عاليةقيد التنفيذحماية البيانات
Omar Haddad
ما الذي يجب عمله

شفّر البيانات أثناء السكون — على الأجهزة الطرفية والخوادم وقواعد البيانات — بحيث لا يتحوّل فقدان الجهاز أو الوصول المادي غير المصرّح به إلى فقدان بيانات.

معايير القبول
سيتحقق مديرك من العمل وفق هذه المعايير قبل قبوله.
  • افرض تشفير القرص الكامل على جميع الأجهزة الطرفية: BitLocker على Windows (بمفاتيح مدعومة بـ TPM)، وFileVault 2 على macOS، وLUKS على Linux.
  • شفّر تخزين الخوادم على مستوى وحدة التخزين أو القرص بحسب النشر: BitLocker أو LUKS محلياً، والتشفير السحابي الأصلي (EBS، والأقراص المُدارة، والأقراص الدائمة) سحابياً بمفتاح يديره العميل حيث تستدعي حساسية البيانات.
  • فعّل التشفير على مستوى قاعدة البيانات (TDE لـ SQL Server وOracle، ووحدات تخزين مشفَّرة أو تشفير على مستوى العنقود لـ PostgreSQL وMongoDB).
مصدر هذه المهمة

هل تشفرون البيانات الحساسة المخزنة في قواعد البيانات أو أنظمة الملفات؟

سؤال التقييم الذي كشف هذه الفجوة.
The catalogue

Fourteen assessments across nine frameworks.

International baselines alongside the regional regulation Gulf organisations actually answer to. Content is authored separately from the product and imported, so a new framework is a publishing task, not a release.

International

NIST CSF 2.0

Organisational baseline — 170 questions, 89 branching rules

ENعربي
International

NIST CSF 2.0 · simplified

SME Cyber Health Check — 30 questions

ENعربي
International

ISO/IEC 27001:2022

ISMS readiness — 123 questions

ENعربي
International

ISO/IEC 27001 · Education

Readiness for schools and universities — 141 questions

ENعربي
Healthcare

HIPAA Security Rule

Harmonised with GDPR and ADHICS — 140 questions

ENعربي
Saudi Arabia

NCA ECC-2:2024

Essential Cybersecurity Controls — 176 questions

ENعربي
Saudi Arabia

NCA CCC-2:2024

Cloud Cybersecurity Controls — six tiered assessments

ENعربي
Saudi Arabia

NDMO

Data management and personal data protection — 190 questions

ENعربي
Abu Dhabi

ADEK School Digital Policy

School digital policy readiness — 155 questions

EN
The platform itself

Holding a company's weaknesses is a responsibility.

A SCORA account is, by definition, a list of exactly where an organisation is exposed. It is built to be treated that way.

Encrypted at the field level

Names, emails and every assessment answer are encrypted individually with AES-256-GCM — not just the disk they sit on.

Lookups without decryption

Accounts are found by a keyed blind index, so an email can be matched without being stored or searched in the clear.

Key rotation you can audit

A health check finds any record left under a retired key, and the interface never shows ciphertext if one exists.

Tenant isolation

Every query is scoped to the company. A contributor sees their own part of an assessment, not the whole organisation's gaps.

Roles that mean something

Managers, contributors and department members each see and do only what their role allows — including who may divide an assessment.

Hardened edges

Bot protection on sign-in, TLS enforced whenever mail is sent with credentials, and signed, expiring URLs for every file.

How it's built

A scoring engine, a workspace, and a pipeline that never trusts a file.

Content
  • Framework catalogue, authored separately
  • Bilingual question and remediation content
  • Conformance test vectors for scoring
Engine
  • Branching questionnaire
  • Domain & maturity scoring
  • Recommendation ranking
  • Posture projection
Workspace
  • Task generation & routing
  • Review, verification, returns
  • Notifications & reminders
  • Closure reports & packs
Evidence
  • Signed direct uploads
  • Content & structure checks
  • Malware scanning
  • Two-pass AI reading
Next.jsTypeScriptPostgreSQLPrismaRedis & BullMQClamAVS3-compatible storageAES-256-GCM field encryptionLLM document analysisReact-PDFArabic RTL

Services: Cybersecurity · AI & Machine Learning · Web Application Development · Business Process Automation

Outcome

What changed.

9
Security frameworks
Including Saudi NCA ECC & CCC, NDMO and Abu Dhabi ADEK
895
Assessment questions
Across 14 assessments, authored in English and Arabic
7
Checks on every file
Before any person can open a piece of evidence

Security assessment becomes something a team runs itself, against recognised frameworks rather than opinion

Every gap has an owner, a due date and a record of who did what

A “Yes” has to be backed by evidence that is actually read, not just attached

No evidence file reaches a person until it has passed structural and malware checks

Auditors get a closure record that states its own weaknesses instead of hiding them

Gulf organisations work in Arabic, against the regional regulation they answer to

Next

Related work.

Nexus — The business card that never goes out of date
Flagship

Nexus

NexusEnterpriseGlobal

The business card that never goes out of date

An NFC and digital business card platform that runs a whole company's cards from one console, in five languages, across the UK, Europe and the Gulf.

Next.js 16React 19TypeScript
Read case studySee Nexus live
AI Feasibility Platform — Three modules that read a feasibility study, judge it, and write a new one from scratch
Flagship

AI Feasibility Platform

Dubai MunicipalityGovernmentUAE

Three modules that read a feasibility study, judge it, and write a new one from scratch

Three modules: one reads a feasibility and fills the whole Excel model, one benchmarks it against world standards and returns a gap analysis, and one generates an entirely new professional feasibility from historical data.

AI/LLMsPythonFastAPI
Read case study
Moving Estimator — A walkthrough video in, a removals quote in seconds
Flagship

Moving Estimator

Umzugsauktion GmbH & Co. KGLogisticsGermany

A walkthrough video in, a removals quote in seconds

The customer films their own home. Computer vision identifies and counts every object, estimates dismantling, handling and transport time, and returns a priced quote.

Computer VisionObject DetectionDeep Learning
Read case study