# Acuity Risk Management > Cyber GRC and risk management software — the STREAM® platform for risk, compliance, controls monitoring, vendor risk, and AI Act readiness. Acuity Risk Management is the developer of STREAM®, a Cyber GRC platform used by regulated organisations across financial services, healthcare, critical infrastructure, public sector, life sciences, and rail. STREAM® comes in two editions: STREAM® Cloud (fast-deploy, self-service for focused use cases) and STREAM® Classic (configurable enterprise platform with 100+ integrations, advanced analytics, and complex framework coverage). Vendor Management Hub extends STREAM® for third-party risk. ## Platform - [STREAM® Cyber GRC Platform](https://acuityrm.com/platform): Overview of the STREAM® platform, editions, and capabilities for cyber GRC, risk, and compliance teams. - [STREAM® Cloud](https://acuityrm.com/platform/stream-cloud): Fast-deploy SaaS edition of STREAM® for focused risk, compliance, and assurance use cases. - [STREAM® Classic](https://acuityrm.com/platform/stream-classic): Configurable enterprise edition of STREAM® for complex Cyber GRC programmes, deep integrations, and advanced analytics. - [STREAM® Cloud Launch](https://acuityrm.com/platform/stream-cloud-launch): STREAM® Cloud onboarding and fast-deployment programme. - [Compare STREAM® Editions](https://acuityrm.com/platform/compare-editions): Side-by-side capability comparison of STREAM® Cloud and STREAM® Classic. - [Vendor Management Hub](https://acuityrm.com/platform/vendor-management-hub): Third-party risk management for assessing, monitoring, and reporting on supplier cyber and compliance risk. - [Integrations](https://acuityrm.com/platform/integrations): Integration catalogue for STREAM® Classic, covering security tools, ticketing, identity, and data sources. - [Reporting](https://acuityrm.com/platform/reporting): Reporting and dashboard capabilities in STREAM® Classic for boards, regulators, and auditors. - [Risk Quantification](https://acuityrm.com/platform/risk-quantification): Cyber risk quantification in STREAM® for translating control posture into financial exposure. ## Use Cases - [Use Cases hub](https://acuityrm.com/use-cases): Index of STREAM® Cloud use cases — pick the buyer scenario that matches your team. - [Secure by Design](https://acuityrm.com/use-cases/secure-by-design): Secure by Design for UK public-sector cyber, risk, compliance, and assurance teams. - [Patient Safety & Clinical Governance](https://acuityrm.com/use-cases/patient-safety): Patient safety and clinical governance evidence for NHS trusts and clinical teams. - [Critical Service Resilience Assurance](https://acuityrm.com/use-cases/critical-service-resilience): Critical service resilience assurance for operators of essential services. - [Deviation-to-CAPA Evidence Tracking](https://acuityrm.com/use-cases/deviation-to-capa): GMP deviation-to-CAPA evidence tracking for regulated manufacturing and life sciences. - [Rail Infrastructure Safety & Engineering Assurance](https://acuityrm.com/use-cases/rail-infrastructure-assurance): Safety and engineering assurance evidence for rail infrastructure teams. - [AI Governance & EU AI Act Readiness](https://acuityrm.com/use-cases/ai-governance): AI inventory, classification, obligations, evidence and assurance for AI governance, risk, compliance, privacy, legal, procurement and technology-risk teams. - [Medical Device Product Compliance & Design Assurance](https://acuityrm.com/use-cases/medical-device-compliance): Connect product requirements, risks, controls, V&V evidence, design reviews, CAPA and post-market signals for medical device quality, regulatory and design assurance teams. - [Defence Contractor Cyber GRC & Operational Security Assurance](https://acuityrm.com/use-cases/defence-cyber-assurance): Connect cyber obligations, controls, evidence, risks, exceptions and customer assurance updates for defence contractors and public-sector suppliers. - [Regulatory Readiness & Evidence Assurance](https://acuityrm.com/use-cases/regulatory-readiness): Connect recurring regulatory, contractual and customer requirements with owners, actions, evidence, reviews and assurance outputs for risk, compliance, audit and supplier assurance teams. - [Supplier Assurance for Critical Aerospace & Defence Supply Chains](https://acuityrm.com/use-cases/supplier-assurance): Connect suppliers, obligations, evidence, findings, actions, supplier changes, exceptions and assurance decisions for aerospace and defence supplier assurance, quality, cyber, programme and procurement teams. ## Solutions - [Cyber GRC](https://acuityrm.com/solutions/cyber-grc): Cyber governance, risk, and compliance solution overview. - [Continuous Compliance Automation](https://acuityrm.com/solutions/continuous-compliance-automation): Automating compliance evidence and reporting across multiple frameworks. - [Continuous Control Monitoring](https://acuityrm.com/solutions/continuous-control-monitoring): Continuous monitoring of control health and residual risk. - [Cyber Risk Quantification](https://acuityrm.com/solutions/cyber-risk-quantification): Quantifying cyber risk in financial and business terms for boards and CFOs. - [Third-Party Risk Management](https://acuityrm.com/solutions/third-party-risk-management): Supplier and vendor risk assessment, monitoring, and reporting. - [Frameworks](https://acuityrm.com/solutions/frameworks): Supported control and risk frameworks across security, privacy, AI, and sector regulations. - [ISO 27001](https://acuityrm.com/solutions/iso-27001): ISO 27001 ISMS implementation, certification, and continuous compliance. - [ISO 42001](https://acuityrm.com/solutions/iso-42001): ISO 42001 AI management system for organisations governing AI risk. - [DORA](https://acuityrm.com/solutions/dora): Digital Operational Resilience Act compliance for EU financial services. - [NIS2](https://acuityrm.com/solutions/nis2): NIS2 Directive compliance for operators of essential and important services in the EU. ## Resources - [EU AI Act Guide](https://acuityrm.com/resources/eu-ai-act): Practical guide to EU AI Act scope, high-risk systems, role-based obligations, and audit-ready evidence. - [Resources hub](https://acuityrm.com/about/resources): Index of white papers, case studies, webinars, and guides. - [White Papers](https://acuityrm.com/about/white-papers): Long-form guides on cyber GRC, ISO 27001, AI risk, supply chain, and operational resilience. - [Case Studies](https://acuityrm.com/about/case-studies): Customer stories from financial services, manufacturing, public sector, and e-commerce. - [Blog](https://acuityrm.com/about/blog): Articles on cyber GRC, EU AI Act, ISO 27001, NIS2, DORA, vendor risk, and continuous compliance. - [News](https://acuityrm.com/about/news): Company news, press releases, and leadership announcements. - [Webinars](https://acuityrm.com/about/webinars): On-demand and upcoming webinars on cyber GRC topics. - [Investor Presentations](https://acuityrm.com/resources/investor-presentations): Library of investor presentations, trading updates, and interviews. - [Assurance Insights](https://acuityrm.com/resources/assurance-insights): Library of public-case and synthetic assurance insights showing how evidence, ownership, review and follow-through gaps become assurance problems — and how STREAM® Cloud supports the chain. - [The Coupang Privacy Fine: What It Shows About Privileged Access Assurance](https://acuityrm.com/resources/assurance-insights/coupang-privacy-fine-privileged-access-assurance): Public case insight on the Coupang privacy enforcement action and what it shows about privileged access, leaver access, privileged credentials, evidence readiness and leadership assurance. - [The Approved Supplier That Was No Longer Assured](https://acuityrm.com/resources/assurance-insights/approved-supplier-no-longer-assured): Synthetic supplier assurance scenario showing how stale evidence, unresolved actions and supplier changes can weaken decision-ready assurance. - [The Vendor AI System No One Classified](https://acuityrm.com/resources/assurance-insights/vendor-ai-system-no-one-classified): Synthetic AI governance scenario showing how a live vendor AI system can lack classification, ownership, evidence and review status. - [The Closed Action That Wasn’t Closed](https://acuityrm.com/resources/assurance-insights/closed-action-that-wasnt-closed): Synthetic patient safety scenario showing how an action can be marked complete without evidence that change has been embedded. - [The Board Declaration Was Ready, But the Evidence Was Not](https://acuityrm.com/resources/assurance-insights/board-declaration-ready-evidence-was-not): Synthetic regulatory readiness scenario showing how assurance statements can outpace current, reviewed and traceable evidence. ## Tools - [Cyber GRC Velocity Assessment](https://acuityrm.com/cyber-grc-velocity-assessment): 12-question diagnostic of cyber GRC maturity with a personalised roadmap. - [Which STREAM® Edition Quiz](https://acuityrm.com/which-stream-edition-is-right-for-you): Short assessment to recommend STREAM® Cloud or STREAM® Classic. - [Cyber GRC Quiz](https://acuityrm.com/cyber-grc-quiz): Quick quiz on cyber GRC fundamentals. - [ROI Calculator](https://acuityrm.com/roi-calculator): Estimate ROI from consolidating cyber GRC tooling on STREAM®. ## Company - [Homepage](https://acuityrm.com/): Acuity Risk Management — STREAM® Cyber GRC platform overview and starting points. - [Company](https://acuityrm.com/about/company): About Acuity Risk Management, leadership, and mission. - [Contact](https://acuityrm.com/contact/us): Contact Acuity Risk Management. - [Request a Demo](https://acuityrm.com/contact/request-demo): Book a STREAM® demonstration with the Acuity team. ## Optional - [White paper: Securing the Supply Chain](https://acuityrm.com/about/white-papers/securing-supply-chain): Third-party risk management guide. - [White paper: AI Risk Management](https://acuityrm.com/about/white-papers/ai-risk-management): Practical AI risk management for regulated organisations. - [White paper: Operational Resilience](https://acuityrm.com/about/white-papers/operational-resilience): Operational resilience playbook. - [White paper: ISO 27001 Demystified](https://acuityrm.com/about/white-papers/iso-27001-demystified): Practical guide to ISO 27001 certification. - [Case study: ATPI](https://acuityrm.com/about/case-studies/atpi) - [Case study: Carl Zeiss](https://acuityrm.com/about/case-studies/carl-zeiss) - [Case study: Midland States Bank](https://acuityrm.com/about/case-studies/midland-states-bank) - [Case study: European Data Hub](https://acuityrm.com/about/case-studies/european-data-hub) - [Case study: Moonpig](https://acuityrm.com/about/case-studies/moonpig) - [Case study: B2C E-commerce](https://acuityrm.com/about/case-studies/b2c-ecommerce-company) - [Privacy Policy](https://acuityrm.com/privacy-policy) - [Cookie Policy](https://acuityrm.com/cookie-policy) - [Terms of Service](https://acuityrm.com/terms-of-service)