Everything you need to evaluate Kyūdō
Straight answers on what Kyūdō is, who it fits, how it deploys inside your Microsoft Azure tenant, what it covers, and how it is priced. Each answer stands on its own.
About Kyūdō
Kyūdō is an AI-native governance, risk, and compliance (GRC) platform that deploys inside your own Microsoft Azure tenant as containerized microservices. It converts Microsoft Security signals (Defender, Sentinel, Purview, Entra ID, and Azure Policy) and signals from AWS, GCP, Oracle, and other platforms into audit-ready evidence, mapped across 80+ frameworks through a Secure Controls Framework crosswalk. Kyūdō covers GRC, third-party and vendor risk, risk management, and AI governance, with continuous reporting and a Trust Center. Your compliance data never leaves your tenant.
Kyūdō is the Japanese martial art of archery, and the name means the way of the bow. It was chosen because kyūdō treats the shot as the product of disciplined, repeatable form rather than a single lucky release. The platform applies the same idea to compliance: audit readiness becomes the result of continuous, well-governed practice instead of a last-minute scramble.
Kyūdō is built by a Microsoft Solutions Partner for Security and a member of the Microsoft Intelligent Security Association (MISA), based in Costa Mesa, California. Kyūdō is built to run inside each customer's Microsoft Azure tenant, so the company never holds a copy of customer compliance data.
Kyūdō is a unified GRC platform that spans four categories most vendors sell separately: governance, risk, and compliance (controls, evidence, policy); third-party and vendor risk management (TPRM/VRM); enterprise risk management; and AI governance. Instead of stitching point tools together, Kyūdō runs them on one Compliance Graph inside your Azure tenant, so a control mapped once satisfies obligations across all four domains. This is what lets cyber GRC and AI governance live in a single system.
Kyūdō solves the gap between security telemetry and provable compliance. Most regulated organizations already run Microsoft Defender, Sentinel, Purview, and Entra ID, but turning that signal into audit-ready evidence still means manual collection, screenshots, and point-in-time assessments. Kyūdō continuously converts those Microsoft Security signals into governed, audit-defensible evidence inside your tenant, so proof is already available when an auditor, regulator, customer, or board asks. Readiness becomes continuous instead of a periodic reconstruction.
Sovereignty-grade means your compliance data stays inside your own Microsoft Azure tenant, with no cross-tenant data plane and no vendor-side copy of your evidence. Kyūdō deploys as containerized services in your tenant under the Azure Managed Application model, so the platform operates where your data already lives. The provider holds standing least-privilege access scoped only to the managed resource group, not to your compliance data or wider tenant. For regulated and data-residency-bound organizations, this removes the SaaS data-export problem.
Yes. Kyūdō is AI-native in an architectural sense: AI reasons over a governed Compliance Graph connecting controls, evidence, risks, policies, vendors, and frameworks, rather than serving as a chat feature added to static records. Sensei AI Advisor retrieves deterministically from that graph, cites the source nodes behind every answer, and routes low-confidence results to human review. All AI inference runs inside your own Azure tenant, so prompts and evidence never leave your environment.
Fit and qualification
Kyūdō is a strong fit for regulated, Microsoft-centric organizations that need provable compliance without exporting data to a SaaS vendor. That includes mid-market and enterprise teams running Microsoft 365 or Azure, defense and aerospace suppliers working toward CMMC, financial services and healthcare organizations with data-residency obligations, and any company exposed to the EU AI Act. If sovereignty or data residency is a procurement requirement and Microsoft is your primary security stack, Kyūdō is built for you.
Kyūdō fits regulated organizations at almost any stage, from early startups through mid-market and enterprise. Pricing doesn't scale with headcount, so your whole team works in the platform. If you only need SOC 2 today, Kyūdō gets you audit-ready, and the Secure Controls Framework crosswalk maps that same work to ISO 27001, HIPAA, and the frameworks you'll face next. Evidence built once carries forward, so one audit becomes the foundation for continuous readiness as you grow.
Kyūdō serves regulated, Microsoft-centric industries best: financial services, healthcare and life sciences, defense and government contracting, and technology companies handling sensitive or sovereign data. These sectors share three traits Kyūdō is designed for: strict data-residency or sovereignty requirements, multiple overlapping frameworks, and a Microsoft security estate (Defender, Sentinel, Purview, Entra ID) that can serve as the primary evidence source.
Yes, an Azure tenant is required. Kyūdō deploys inside your own Microsoft Azure tenant and builds evidence from Microsoft Security signals such as Defender, Sentinel, Purview, Entra ID, and Azure Policy, so Microsoft 365 strengthens coverage further. This is a deliberate design choice. By treating Microsoft as the primary telemetry source rather than one connector among hundreds, Kyūdō produces deeper, continuously governed evidence. That doesn't mean your Microsoft estate is the whole picture. Most regulated organizations run workloads across more than one cloud, and Kyūdō integrates security signals from AWS, Google Cloud, Oracle, and other platforms alongside the Microsoft telemetry. So the control evidence reflects your full environment, not just the part that lives in Azure, while the platform itself stays deployed in your tenant where your data belongs.
Yes. Kyūdō is well suited to defense industrial base (DIB) suppliers preparing for the Cybersecurity Maturity Model Certification (CMMC), which aligns to NIST SP 800-171. Kyūdō maps your Microsoft Security controls to CMMC practices through its Secure Controls Framework crosswalk, continuously collects the supporting evidence inside your tenant, and produces audit-ready reporting with provenance. Kyūdō prepares and supports CMMC readiness; it does not grant certification, which only an authorized assessor can do.
Yes. Kyūdō is built for organizations exposed to the EU AI Act, the European Union's risk-based regulation of AI systems. It maps the Act's obligations alongside ISO 42001 and the NIST AI Risk Management Framework in one Compliance Graph, tracks your AI systems and their risk classification, and continuously gathers governance evidence inside your tenant. EU AI Act obligations are phasing in through 2026, so Kyūdō treats AI governance as continuous readiness rather than a one-time assessment.
Kyūdō deploys as containerized services inside your own Azure tenant, which is the architecture sovereign and government-cloud scenarios require: the application runs where your data already resides, with no cross-tenant data plane. Whether a specific environment such as Azure Government GCC High fits your obligations is confirmed during the architecture briefing, because it depends on your tenant configuration and the Microsoft services in scope. Kyūdō's deployment model is designed for exactly these high-assurance, residency-bound environments.
Product capabilities
Kyūdō manages governance, risk, and compliance from a single control set. You define a control once, and the Secure Controls Framework crosswalk maps it across every framework you have activated, so overlapping requirements are satisfied together instead of one framework at a time. Controls are continuously tested against live Microsoft Security, AWS, Google Cloud, Oracle, and other integrated security signals, each with an owner, status, and linked evidence. The result is an always-current controls posture rather than a spreadsheet refreshed before each audit.
Kyūdō collects compliance evidence continuously and automatically from your Microsoft Security estate, including Defender, Sentinel, Purview, Entra ID, and Azure Policy. Each artifact is captured inside your Azure tenant, time-stamped, and sealed with a cryptographic chain of custody that records where it came from and when. Because collection is continuous, evidence is already current when an auditor asks, removing the manual screenshots and point-in-time pulls compliance teams usually scramble to assemble. Nothing is exported to a vendor to make this work.
Yes. Kyūdō includes third-party and vendor risk management (TPRM/VRM) as part of the platform, not as a separate product. You can inventory vendors, send and score assessments, track risk over time, and link vendor findings to the same controls and frameworks the rest of your program uses. Because it runs on one Compliance Graph, third-party risk shares context with your internal controls and evidence, so a single change in posture is reflected everywhere it matters.
Kyūdō provides enterprise risk management with a live risk register connected to your controls and evidence. Risks can be scored, assigned owners, linked to mitigating controls, and tracked as their status changes, with the supporting Microsoft Security signals attached. Because risk shares the same Compliance Graph as compliance and vendor data, a weakening control automatically surfaces as elevated risk, so the register reflects reality continuously instead of being rebuilt for a quarterly review.
Kyūdō governs the AI systems your organization deploys, mapping the EU AI Act, ISO 42001, and the NIST AI Risk Management Framework into one Compliance Graph. You can inventory AI systems, classify their risk, assign controls, and collect governance evidence continuously inside your tenant. Because cyber GRC and AI governance run on the same platform, the controls that protect your data also feed your AI-governance posture, rather than living in a separate tool. Human reviewers stay in the loop for consequential decisions.
Yes. Kyūdō manages the full policy lifecycle: authoring, review, approval, publication, attestation, and versioning. Policies are linked directly to the controls and frameworks they support, so when a control changes, the related policy and its attestations are easy to keep current. Keeping policy, controls, and evidence in one system means an auditor can trace a requirement from the written policy to the live control to the underlying Microsoft Security signal without leaving the platform.
Yes. Kyūdō includes a Trust Center, a controlled portal where you share your security and compliance posture with customers, prospects, and auditors. You decide what is public and what is gated, publishing current evidence, certifications in progress, and framework coverage drawn from live data rather than a static PDF. Because the Trust Center reads from the same continuously updated Compliance Graph, what you show externally stays consistent with what your team manages internally.
Kyūdō produces reporting tailored to three audiences: auditors, who need evidence with provenance and chain of custody; boards and executives, who need posture and risk trends; and regulators, who need framework-specific control status. Reports draw from continuously collected data inside your tenant, so they reflect current state rather than a point-in-time snapshot. Evidence artifacts can be rendered as defensible, time-stamped records, which shortens the gap between a request for proof and a complete, traceable answer.
Frameworks and mapping
Kyūdō supports more than 80 compliance and security frameworks, including SOC 2, ISO 27001, ISO 42001, the NIST Cybersecurity Framework, NIST SP 800-171, CMMC, HIPAA, PCI DSS, the EU AI Act, and DORA, among others. All supported frameworks are available to activate without a per-framework charge, because Kyūdō defines controls once and maps them across frameworks through a Secure Controls Framework crosswalk. As regulations evolve, new frameworks are added to the same crosswalk rather than rebuilt from scratch.
There is no cap on how many frameworks you can map at once, and activating more does not raise the price. Kyūdō defines each control a single time, then uses its Secure Controls Framework (SCF) crosswalk to satisfy the equivalent requirement in every framework you turn on simultaneously. Organizations commonly run SOC 2, ISO 27001, and a sector framework like CMMC or HIPAA together, reusing the same evidence across all of them. Charging per framework would contradict how the crosswalk works.
Kyūdō maps multiple frameworks through the Secure Controls Framework, a meta-framework that acts as a common control language. Each control is written once against the Secure Controls Framework, and the Set Theory Relationship Mapping (STRM) method, aligned with NIST Interagency Report 8477, defines how that control relates to requirements in each specific framework. When you activate SOC 2 and ISO 27001 together, a single piece of Microsoft, AWS, or Google Cloud security evidence can satisfy the related control in both, because the crosswalk already knows they are equivalent.
Yes. Kyūdō supports SOC 2 (System and Organization Controls 2), ISO 27001, the Cybersecurity Maturity Model Certification (CMMC), and the NIST Cybersecurity Framework, among more than 80 frameworks. Controls for each are derived from one Secure Controls Framework crosswalk, so evidence collected from your Microsoft Security estate applies across all of them at once. Kyūdō prepares and supports readiness for these frameworks with continuous evidence and provenance; certification itself is granted by an independent auditor or assessor.
Yes. Kyūdō supports the EU AI Act, ISO 42001 (the AI management-system standard), and the NIST AI Risk Management Framework, governing them in the same Compliance Graph as your cyber controls. You can classify AI systems by risk, assign the relevant controls, and collect governance evidence continuously inside your tenant. Because these AI frameworks share Kyūdō's control crosswalk, the work you do for one contributes to the others, and your AI-governance posture stays connected to the security controls underneath it.
Kyūdō prepares you for SOC 2 (System and Organization Controls 2) by mapping the Trust Services Criteria to one control set through the Secure Controls Framework crosswalk and collecting supporting evidence continuously from Microsoft Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy inside your tenant. Each artifact carries a hash, lineage, and confidence score your auditor can verify. Kyūdō supports readiness; the SOC 2 report itself is issued by an independent auditor.
Kyūdō supports ISO 27001 readiness by mapping the standard's controls into its Secure Controls Framework crosswalk, so work done for other frameworks carries over, and by collecting evidence continuously from your Microsoft Security estate inside your own tenant. Control status, ownership, and linked evidence stay current between surveillance audits rather than being rebuilt each cycle. Certification is granted by an accredited certification body; Kyūdō keeps the evidence ready for it.
Kyūdō supports the NIST Cybersecurity Framework (CSF) by mapping its functions (Govern, Identify, Protect, Detect, Respond, Recover) to one control set through the Secure Controls Framework crosswalk. Evidence flows continuously from Microsoft Defender XDR, Sentinel, Purview, Entra ID, and Azure Policy, so your CSF posture reflects the current state of your estate. Because CSF overlaps heavily with other frameworks, the same controls and evidence also serve SOC 2, ISO 27001, and CMMC.
Architecture, sovereignty, and security
Kyūdō deploys inside your own Microsoft Azure tenant as containerized services running on Azure, provisioned through the Azure Managed Application model. The platform operates where your data already lives, so there is no cross-tenant data plane and no vendor-hosted copy of your compliance evidence. Deployment is handled with your Azure administrator during onboarding, and the application layer is maintained by Kyūdō while you retain control of the Azure subscription and the data within it.
Your compliance data lives entirely inside your own Microsoft Azure tenant and never leaves it. There is no cross-tenant data plane and no vendor-side copy of your evidence. Under the Azure Managed Application model, the provider holds standing least-privilege access scoped only to the managed resource group that runs the application, not to your compliance data or your wider tenant. In practice this means no vendor access to your compliance data, which removes the data-export exposure multi-tenant SaaS compliance tools carry.
Kyūdō's AI reasons over a typed Compliance Graph, a structured model of your controls, evidence, frameworks, and their relationships, rather than generating text over a flat database. Every AI output carries a confidence score, and results below a defined threshold are routed to a human for review before they are accepted. Each answer cites the specific source nodes it draws from, so you can trace a conclusion back to the underlying evidence. The agent runtime is Microsoft Foundry Agent Service, running inside your tenant.
Yes, because Kyūdō is built for auditor scrutiny rather than unexplained automation. Every AI-assisted conclusion cites the source nodes in the Compliance Graph it was derived from, carries a confidence score, and is sealed with a cryptographic chain of custody. Outputs below a defined confidence threshold require human disposition before they count as evidence, keeping a person in the loop for consequential decisions. An auditor can follow any artifact from the AI's statement back to the Microsoft Security signal that produced it.
Kyūdō builds evidence from core Microsoft Security signals: Microsoft Defender for threat protection, Microsoft Sentinel for security information and event management, Microsoft Purview for data governance and information protection, Microsoft Entra ID for identity and access, and Azure Policy for configuration and guardrails. These signals are read continuously inside your tenant and converted into governed control evidence. Treating Microsoft as the primary evidence source, rather than one connector among hundreds, is what lets Kyūdō produce deep, continuous proof from infrastructure you already run.
Yes. Because Kyūdō runs inside your Azure tenant, encryption keys remain under your control, and the platform supports customer-managed keys through Azure Key Vault. Data is encrypted in transit and at rest using your tenant's key management, so the provider never holds the keys to your compliance data. This is a direct consequence of the deployment model: when the application and its data live in your tenant, key custody stays with you rather than with a SaaS vendor.
Kyūdō is secured by the same Microsoft-native controls it helps you govern. It runs as least-privilege containerized services on Azure Kubernetes Service inside your tenant, isolated to a managed resource group, with identity through Microsoft Entra ID and monitoring through your own Defender and Sentinel. KMicro Tech builds and maintains Kyūdō as a Microsoft Solutions Partner for Security and MISA member. Because there is no central multi-tenant store of customer evidence, there is no shared pool of compliance data to breach.
Yes. Microsoft Defender XDR (extended detection and response) is one of Kyūdō's primary evidence sources. Kyūdō reads Defender signals continuously inside your Azure tenant and converts them into governed control evidence, with a hash, lineage, and confidence score recorded per artifact. Because controls are mapped once through the Secure Controls Framework crosswalk, a single Defender signal can support the equivalent requirement in every framework you have activated.
Yes. Kyūdō uses Microsoft Sentinel, Microsoft's cloud-native security information and event management (SIEM) service, as a continuous evidence source. Sentinel logs and analytics are read inside your tenant and converted into audit-ready control evidence, with a hash, lineage, and confidence score per artifact. Monitoring, logging, and incident-response controls get live proof drawn from telemetry you already collect, instead of screenshots assembled before an audit.
Yes. Kyūdō converts Microsoft Purview signals into control evidence for data governance, classification, and information-protection requirements. Purview is read continuously inside your Azure tenant, and each resulting artifact carries a hash, lineage, and confidence score. Frameworks with strong data-handling obligations, such as HIPAA, GDPR, and ISO 27001, draw much of their evidence from exactly these signals, mapped once through the Secure Controls Framework crosswalk.
Yes. Microsoft Entra ID, Microsoft's identity and access management service, is a core Kyūdō evidence source. Access reviews, conditional access policies, and authentication settings are read continuously inside your tenant and converted into governed evidence for identity and access-control requirements across every activated framework. Kyūdō also uses Entra ID for its own authentication and role-based access, so the platform is governed by the same identity controls it reports on.
How Kyūdō compares
Most established GRC platforms share the same architecture: multi-tenant SaaS that connects to hundreds of integrations and gives cloud-native teams a fast, well-understood path to a first SOC 2 or ISO 27001. That model works well when speed to a first certificate is the priority, and auditors know these tools, so the path is familiar on both sides. Kyūdō is built differently on purpose. It deploys inside your own Azure tenant with no cross-tenant data plane, so your compliance evidence never leaves your environment. Rather than treating Microsoft as one connector among hundreds, it converts Defender, Sentinel, Purview, Entra ID, and Azure Policy signals directly into governed evidence, then extends coverage to AWS, Google Cloud, Oracle, and other platforms you run. That evidence is grounded in a typed Compliance Graph with confidence scoring, source citations, and a cryptographic chain of custody, and AI governance lives in the same platform rather than a separate tool. The choice usually comes down to what's driving the decision. If you want the quickest managed path to a first certificate across many SaaS connectors, the incumbent platforms do that well. If data sovereignty, residency, a Microsoft-centric estate, or audit-grade evidence you can defend line by line is central to your requirements, that's where Kyūdō is the precise fit.
The structural difference is where your data lives. Most SaaS compliance-automation tools are multi-tenant: your evidence is collected into the vendor's environment, and pricing typically scales with users and the number of frameworks. Kyūdō deploys inside your own Azure tenant, so compliance data never leaves it, treats your Microsoft Security estate as the primary evidence source, and includes all modules (GRC, vendor risk, risk, AI governance, policy, and the Trust Center) with no per-seat or per-framework charge. It suits regulated, sovereignty-bound, Microsoft-centric organizations rather than teams wanting the lightest-weight managed SaaS.
Kyūdō replaces spreadsheets with a continuously governed system of record. Spreadsheets capture compliance at a single moment, drift immediately, and carry no provenance, so every audit becomes a reconstruction effort. Kyūdō collects evidence continuously from your Microsoft Security signals inside your tenant, maps one control set across 80+ frameworks, and seals each artifact with a cryptographic chain of custody. Instead of rebuilding a workbook before every assessment, your posture stays current and traceable, and proof is available the moment it is requested.
Kyūdō complements consultants rather than replacing the judgment they bring. Consultants are valuable for interpreting requirements and advising on strategy, but using them to manually gather evidence is slow, point-in-time, and expensive to repeat each cycle. Kyūdō automates the continuous collection, mapping, and provenance of evidence inside your tenant, so consultant time shifts from assembling screenshots to higher-value advisory work. The result is lower recurring effort and an always-current evidence base your advisors and auditors can both rely on.
Getting started
You start with a free assessment, then a short architecture briefing. The assessment reviews your current frameworks, Microsoft estate, and compliance gaps; the architecture briefing is a 30-minute walkthrough for security leaders covering how Kyūdō deploys in your Azure tenant. From there, a controls workshop maps your specific frameworks, and deployment is scheduled with your Azure administrator. You can begin from the contact or demo request on this site. No data leaves your tenant at any point in the process.
The free assessment is a no-cost review of your current compliance posture. It looks at the frameworks you need, your Microsoft Security estate (Defender, Sentinel, Purview, Entra ID), and where evidence is currently manual or missing, then shows how Kyūdō would map and automate it inside your tenant. It is designed to give security and GRC leaders a concrete picture of coverage and effort before any deployment commitment, not a generic feature demo.
The architecture briefing is a 30-minute walkthrough for security leaders and architects. It covers how Kyūdō deploys as containerized services inside your Azure tenant, how the Managed Application access model works, where data resides, and how Microsoft Security signals become governed evidence. The goal is to answer the sovereignty, data-residency, and integration questions procurement and security teams raise early, so you can evaluate the deployment model before committing time to a full controls workshop.
The controls workshop is a 90-minute working session for GRC, audit, and compliance teams. Together you map your specific frameworks to a single control set using Kyūdō's Secure Controls Framework crosswalk, identify which Microsoft Security signals supply evidence for each control, and surface overlaps where one control satisfies several frameworks at once. You leave with a concrete control-to-evidence map for your environment, which becomes the backbone of your continuous-readiness program in Kyūdō.
The trust packet is a procurement-ready set of materials for vendor risk and security review. It documents Kyūdō's architecture, the in-tenant deployment and access model, how data residency and chain of custody work, and the Microsoft credentials behind the platform. It is meant to answer the questions a customer's third-party risk team asks during evaluation, so security and procurement reviewers can assess Kyūdō without a lengthy back-and-forth. You can request it through the Trust Center or a contact request.
Deployment timelines depend on your Azure environment and the number of frameworks in scope, so the exact duration is confirmed during the architecture briefing. Because Kyūdō installs as containerized services through the Azure Managed Application model rather than a lengthy custom integration, provisioning the platform in your tenant is fast; the larger variable is mapping controls and connecting evidence sources, which the controls workshop scopes. Kyūdō provides a timeline for your specific environment before you commit.
Onboarding follows a clear sequence. First, a free assessment scopes your frameworks and Microsoft estate. Second, an architecture briefing confirms the deployment and data-residency model. Third, Kyūdō is provisioned into your Azure tenant with your administrator. Fourth, a controls workshop maps your frameworks to one control set and connects Microsoft Security signals as evidence. Finally, continuous collection begins and your Trust Center and reporting go live. Throughout, your compliance data stays inside your tenant.
The Founder's Program is Kyūdō's design-partner stage, where early customers help shape the platform while standing up continuous readiness in their own tenant. Design partners get direct access to the founder and product team, influence over the roadmap, and hands-on support deploying Kyūdō against their specific frameworks and Microsoft estate. It suits regulated, Microsoft-centric organizations that want to be early and close to the people building the product.
After deployment, Kyūdō maintains the application layer running in your tenant while you retain control of the Azure subscription and your data. Support covers platform updates, framework and crosswalk additions as regulations change, and help connecting new Microsoft Security signals or evidence sources. Because the platform runs continuously rather than only at audit time, support is oriented around keeping your posture current year-round, not just preparing for a single assessment.
Kyūdō is built to deploy through the Azure Managed Application model, the same mechanism used for Azure Marketplace managed applications, so it installs natively into your tenant. Public Azure Marketplace listing status and timing are confirmed directly with the Kyūdō team, since availability is rolling out. If Marketplace transactability matters for your procurement, ask during the architecture briefing.
Pricing and commercial model
Kyūdō uses a simple, all-inclusive commercial model. Every module (GRC, evidence, third-party and vendor risk, risk management, AI governance, policy, and the Trust Center) is included together rather than sold as separate SKUs or gated behind higher tiers. Pricing does not depend on the number of users, and there is no per-framework charge or cap on how many of the 80+ supported frameworks you activate. For figures matched to your deployment scope, contact the Kyūdō team.
All modules are included. GRC and controls, evidence automation, third-party and vendor risk management, enterprise risk management, AI governance, policy management, and the Trust Center come together in one platform, not as add-ons or premium tiers. This is deliberate: because everything runs on one Compliance Graph, separating capabilities into SKUs would break the shared context that makes the platform work. You get the full system from the start.
No. Kyūdō does not charge per user or per seat, so adding people to the platform does not increase the price. Your entire compliance, security, audit, and risk team can use Kyūdō, along with stakeholders who only need reporting or Trust Center access, without seat-based cost. This reflects the platform's purpose: compliance is an organization-wide responsibility, and pricing that penalized participation would work against continuous, shared readiness.
No. Kyūdō does not charge per framework and does not cap how many you can use. You can activate as many of the 80+ supported frameworks as you need at no additional per-framework cost. This follows directly from the architecture: controls are defined once and mapped across frameworks through the Secure Controls Framework crosswalk, so adding a framework reuses existing controls and evidence rather than creating separate work to bill for.
Kyūdō's model is structurally different from compliance tools that charge per seat and per framework. Where those models raise the price as you add users or turn on more frameworks, Kyūdō includes all modules and all activated frameworks under one charge, with no per-seat fee. The difference comes from architecture: one control set mapped across frameworks via the Secure Controls Framework crosswalk means more frameworks reuse the same work, so charging incrementally for them would contradict how the platform operates.
Because Kyūdō deploys through the Azure Managed Application model inside your tenant, it is designed to align with Azure-native procurement. Whether Kyūdō billing can count toward your Microsoft Azure Consumption Commitment (MACC) depends on the listing and contract path, which the Kyūdō team confirms directly. If MACC drawdown matters to your procurement, raise it during the architecture briefing so the right purchasing route is set up.
Kyūdō is delivered as an annual engagement, reflecting that customer-hosted deployment provisions dedicated infrastructure in your Azure tenant and that compliance is a continuous, year-round program rather than a one-time project. Specific contract terms and minimums are confirmed with the Kyūdō team for your scope, and your controls and evidence remain inside your tenant throughout.
Yes. Kyūdō's Enterprise tier includes a white-label option for MSSPs (managed security service providers) and partners who deliver GRC services to their clients. Each client deployment keeps the standard architecture: the platform runs inside the client's own Azure tenant, so client compliance data stays in the client's environment rather than pooling with the service provider. Partners interested in the white-label model should contact the Kyūdō team to discuss scope and setup.
Trust and proof
You can review several concrete proof points before committing. These include Kyūdō's reference architecture showing exactly how it deploys in your Azure tenant, sample rendered evidence snapshots that demonstrate the chain-of-custody and provenance format, the Trust Center, and a free assessment of your own environment. Because Kyūdō is at the design-partner stage, it leads with architecture and verifiable mechanism rather than customer logos, so you can judge fit on how the platform actually works.
Kyūdō is built by a Microsoft Solutions Partner for Security and a member of the Microsoft Intelligent Security Association (MISA), the partner ecosystem Microsoft maintains for vetted security solutions. The platform is built on Microsoft-native services, including Microsoft Foundry Agent Service as its agent runtime and Microsoft Security signals as its evidence source, and is being registered for Microsoft co-sell. These credentials reflect that Kyūdō is designed around the Microsoft security stack rather than bolted onto it.
Kyūdō applies its own platform to its own posture, governing its controls, evidence, and AI systems the same way it does for customers. It runs on least-privilege, Microsoft-native infrastructure and uses continuous evidence collection internally, so its compliance state stays current rather than assembled for review. Because the architecture keeps each customer's evidence inside that customer's tenant, there is no central store of customer compliance data for Kyūdō to secure on their behalf, which reduces the shared risk surface.
