Menu Browse

Popular Use Cases

Public Demo Tenant

Click around the real product.
No signup, no sales call.

Sign in to a fully populated tenant — "TechNova Solutions", a fictional 40-person SaaS company mid-way through their ISO 27001 journey. Real workflows, real anomalies, real audit trails. Resets every night.

How to Sign In

Three accounts. One password. Pick a role.

Each account shows the product through a different lens — owner, manager, member. Same data, different permissions and dashboards.

Tenant Owner

Alex Rivera

Full access. Best for end-to-end exploration — billing, settings, every workspace.

Tenant Manager

Sarah Kim

Manages risk, ISO, and supplier work without org-admin scope. Good for everyday operator view.

Tenant Member

James Thompson

Read-mostly contributor. Best for seeing the experience of an everyday team member.

Same password across all three accounts. · Login URL: https://autociso.io/console/auth/login

Reset Schedule

Fresh state every night at 00:00 UTC.

The demo tenant is dropped and reseeded from a known-good baseline once per day. Anything you create, edit, complete, or delete during the day will be gone by morning — and the next visitor sees the same starting point you did.

That means you can click every button. Approve risks, close gaps, send (mock) supplier assessments, fail control tests — explore destructively. The reset is the safety net.

00:00 UTC

Tenant database dropped

The entire `demo_org_technova` MongoDB database is removed, plus org-scoped records in the central database.

00:00 UTC

Seed script runs

The canonical seed (`scripts/seed-tenant-demo.js`) re-creates the org, users, employees, assets, audits, ISO projects, risks, suppliers, maturity history, and vCISO workspace.

00:01 UTC

Tenant ready

You can sign back in immediately. Auth0 user accounts persist — only the tenant data is reset.

Daytime

Shared with other visitors

Multiple people may be exploring the same tenant. If something looks unexpected, that is probably why — log out, back in, or wait for the next reset.

Worth a Look

Eight things to click before you leave.

The seed data is built around real scenarios — a stage-1 audit looming, an admin who hasn't verified MFA, a contractor whose access was never revoked. Pull on any thread.

Live ghost account on a CRITICAL asset

Risk Register · Audits

A `svc-prod-deploy` admin on the Production DB Cluster has no matched employee. Walk into the Risk Register and watch how AutoCISO scored it 8.5/10 inherent and queued a 48-hour investigation.

Two ISO 27001 projects side-by-side

ISO 27001 · Projects

An archived v1 at 38% (the messy first attempt) and a live v2 at 70% with 5 BLOCKING gaps still open. Stage 1 audit is "in 3 weeks" — see exactly which controls move the needle.

AI-guided risk interviews

Risk · Interview

3 interview sessions in flight, 12 steps captured. Watch the AI turn a free-form conversation into structured risk records with inherent/residual scores and treatment strategy.

Supplier assessments with real findings

Suppliers · CloudSec AI Inc

CloudSec AI Inc has a full assessment loop: 37 questions answered, 3 findings, MSA + DPA + Security Addendum on file. Try the assessment review dialog and PDF export.

Compliance Cockpit catching offboarding gaps

Compliance Cockpit

3 terminated employees still have active access (Brian, Olivia, Raj). The cockpit flags them as offboarding violations with one-click remediation tasks.

Audit anomalies with downloadable source

Audits

12 audits across 6 assets — 11 with the original CSV/SVG you can download from GridFS. See how an upload becomes findings becomes a remediation queue.

vCISO workspace with month-over-month readiness

vCISO Workspace

18 roadmap items, 6 management decisions, 3 monthly snapshots. Latest readiness sits at 67 — see how the program tracks over time.

Maturity arc you can replay

Maturity

6 maturity sessions (5 completed, 1 in progress) with 5 snapshots showing real progression from 42% → 79%. Open one and see how the score moves.

Common Questions

Before you sign in.

Is the demo really public?
Yes. The credentials on this page are intentional — they let anyone sign in to a sandboxed tenant called TechNova Solutions. There is no real customer data inside.
When does the demo reset?
Every night at 00:00 UTC. Anything you create, edit, or delete in the demo tenant is wiped and reseeded from a known-good baseline.
Can I break the demo?
You cannot break it permanently — the nightly reset restores everything. But you may bump into other people's in-flight changes during the day. If something looks off, log out and back in, or wait for the next reset.
Does anything sent in the demo go to real services?
No. Email is captured by a no-op mail service, all employee identities use the @technova-demo.test domain, and integration credentials are placeholders.
Why share the password publicly?
Because the entire tenant is throwaway. There is nothing valuable inside, and the friction of a signup form is exactly what we want to remove for a "kick the tires" experience.
What if I want my own tenant?
Sign up for the free trial — your own data, your own org, no shared state, and the audit trail is permanent. Link below.
423 ghost accounts found in the last 30 days

Liked the demo? Spin up your own.

Free trial, your own org, your own data — and an audit trail that never resets.