Security & privilege

Candor is the whole point. We protect it.

An exercise only works if people say what's actually broken. Tabletop.ai is built so they can, protected by attorney-client privilege and kept separate by strict, per-organization data controls.

Security & privilege

Privileged by design. Isolated by default.

The whole point of running an exercise under counsel is candor. Teams can name real gaps without creating a discoverable roadmap for an adversary or a plaintiff. Tabletop.ai is built to protect that candor, technically and legally.

Attorney-client privilege by design

Exercises and their reports are set up to stay legally protected from the start: run under your lawyers, written as legal work product, not as notes an opponent could demand in court.

Every organization's data is walled off

A database rule tags every record to its owner, so each organization is sealed off from the rest. Business units never see each other's data; the head office sees only what its role permits.

Single sign-on and least-access roles

Sign in through your company login (single sign-on with Microsoft, Google, or SAML). Access is role-based and kept to the minimum, so participants see only their seat.

Every request runs as the signed-in user

App requests run as the person making them, checked against those same data rules. All-access admin credentials are never used to serve live traffic.

Data handling

Separation that holds across every business unit.

Each organization walled off

A database rule tags every record to its organization. Business units are invisible to one another, and the head office sees only what its role allows.

Requests run as the signed-in user

App requests run as the person making them, checked against those same data rules. All-access admin credentials are never used to serve live traffic.

Sign-in and access

Single sign-on with Microsoft, Google, or SAML. Roles are kept to the minimum, and participants only ever see their own seat in an exercise.

Compliance posture

Built for board-visible, regulated programs.

Ready for regulators

Produce the board-visible, documented record of cyber governance that regulators and examiners increasingly expect, with a clear trail from exercise to decision to fix. Aligned with SEC examiner expectations.

Mapped to the NIST framework

Results map to the six areas of the NIST cybersecurity framework, giving you a consistent, standards-anchored way to report readiness over time.

Built on the FEMA HSEEP method

Exercises follow a recognized way to design and evaluate drills, so the process itself stands up to scrutiny, not just the result.

Tabletop.ai supports your compliance program; it is not a substitute for legal advice, a security audit, or a guarantee of any regulatory outcome. Privilege determinations rest with your counsel.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.