How it works

Don't search the database. Navigate the consequences.

Most compliance tools give you a list of results. CyberTRIZ gives you the chain. Start from a machine, a regulation, a risk, a control, a procedure, an action or a proposed change, and follow what it touches until you reach the answer you actually needed.

24,607Regulatory articles indexed
16,140Controls in the library
77,779Standards catalogued
349,587Vulnerabilities tracked
The idea

Anything can be the centre

The interface does not change depending on where you start. Whatever you select moves to the middle, and everything connected to it arranges around it. Click any connection and it becomes the new centre.

  • Machine
  • →
  • Function
  • →
  • Risk
  • →
  • Failure mode
  • →
  • Impact
  • →
  • Control
  • →
  • Requirement

Level 1 — Overview

The centre shows only relationship families and how many of each: 31 risks, 47 controls, 126 requirements, 14 procedures.

Level 2 — Expand

Open one family and see the highest-ranked items in it, ordered by relevance rather than alphabetically.

Level 3 — Recentre

Click any item and the whole map reorganises around it. A breadcrumb records how you arrived.

Any depth

Depth one shows direct relationships only. Depth two and three reveal derived paths, always with the route shown.

Four ways to use it

Explore, impact, change, solve

The same map answers four different questions, depending on what you need it for that day.

1

Explore

What is related to this? Risks, controls, obligations, procedures, actions, evidence and dependencies, ranked by relevance to your context.

2

Impact

What affects this, and what does this affect? Upstream causes and downstream consequences, out to the business service and the customer.

3

Change

What needs reassessment if this changes? Controls to review, procedures to revise, tests to repeat, training to refresh, obligations touched.

4

Solve

When the fix creates a second problem, CyberTRIZ names the contradiction and proposes inventive directions to resolve it.

Worked example

From an instrument to patient safety in six steps

A laboratory HPLC looks like an isolated piece of equipment. It is not. This is the chain the Navigator walks, and every link is stored, sourced and explainable.

  1. HPLC systemMachine, QA laboratory, GxP critical
  2. Calibration manipulationCritical risk, directly linked, control coverage 62%
  3. Incorrect measurementFailure mode with a detection gap
  4. Out-of-specification resultQuality event requiring investigation
  5. Wrong batch release decisionSevere, and regulatory reportable
  6. Product quality and patient safetyThe reason the control exists at all
And in the other direction

Which obligations demand the control

Walk back up and the Navigator shows why each control is required, citing the article rather than asserting it.

  1. Calibration management controlPreventive, scheduled, owner named
  2. Calibration procedureControlled SOP, four-eyes approval
  3. EU GMP Annex 11Electronic records and audit trail requirements
  4. 21 CFR Part 11Electronic signatures, record integrity
  5. Evidence and trainingWhat proves it works, and who is qualified to do it
Trust

Three levels of relationship, never blended

A regulatory platform that cannot tell you where a relationship came from is a liability. Every connection in CyberTRIZ carries its class, its source and its confidence, and the map draws each one differently.

Solid line

Verified direct

An explicit, authoritative relationship held in the source of truth and reviewed by a human. Counts fully towards coverage.

Dashed line

Derived and explainable

Produced by a deterministic rule across canonical identifiers. The full route is always shown, so you can check the reasoning yourself.

Dotted line

AI suggested

A semantic candidate awaiting review. Clearly labelled, never counted as verified coverage, and never silently written into the knowledge base.

The database is the memory. The AI is the interpreter.

The relational database stays authoritative. Language models interpret what you asked, choose where to start, request the paths and explain the result. They do not invent the relationships. That distinction is what makes the output usable in an audit.

What you can start from

Every object type, one interface

Machine or equipment, application, SaaS service, function, process, risk, failure mode, impact, control, regulation, requirement, rulebook, rule, procedure, URS, statement of work, corrective action, preventive action, improvement action, change, incident, evidence, role, competency, course, vendor, product, CVE, industry.

Context filters

Industry, jurisdiction, environment, criticality and relationship class. A regulation with twenty thousand connections becomes the two hundred that apply to you.

Role perspectives

The same object seen as a CISO, a CIO, a data officer, a quality manager, an auditor or the board. Same data, different relevance.

Generated outputs

Rulebooks, benchmarks, CAPAIA plans, change impact assessments, evidence packs and board summaries, produced from what is on screen.

Questions

Common questions

Is this a graph database?

No. The relational database remains the authoritative source. A universal node and edge layer sits on top of it and is generated from the same tables, which keeps auditability, traceability and existing imports intact while giving you graph-style navigation.

Where do the relationships come from?

From the regulatory corpus, the control library, the standards catalogue, the vulnerability feeds and your own registers. Each edge stores its source, its class and when it was last reviewed.

Can it use our own data?

Yes. Asset registers, CMDB, identity, scanners, backup logs, HR and learning records can be connected so the map reflects your environment rather than a generic template.

What happens when a regulation changes?

The change propagates through requirements, rules, controls, procedures, evidence and training, and the Navigator lists exactly what needs revisiting, with dates.