About Passerum
Passerum is an AI-driven governance, risk, and compliance (GRC) platform designed to help organizations understand and improve their cybersecurity and AI governance posture without requiring access to their internal systems.
The platform combines established frameworks such as National Institute of Standards and Technology (NIST) and International Organization for Standardization (ISO 27001) with adaptive AI models to deliver structured risk assessments, actionable recommendations, and continuous learning from real-world use.
Passerum was built to address a practical gap: most small and mid-sized organizations lack the resources to interpret complex security and AI governance requirements, while existing solutions often require heavy integrations or assume mature security teams. Passerum removes that barrier by delivering insight without operational friction.
Founder Background
Passerum is founded by Francisco Rincon, a cybersecurity professional with experience evaluating regulatory impacts of emerging technologies and helping businesses improve cybersecurity resilience.
In parallel, Francisco conducts research on AI Resilience in collaboration with Virginia Tech and the Carnegie Endowment for International Peace (CEIP), contributing to work that examines how organizations can build resilient AI systems across technical, organizational, and governance domains.
Built on Recognized Cybersecurity Frameworks
NIST Cybersecurity Framework (CSF)
Passerum aligns risk identification and prioritization with the NIST CSF core functions (Identify, Protect, Detect, Respond, and Recover) adapted for SMB IT environments.
Focus areas include:
-
Asset visibility
-
Vulnerability exposure
-
Risk prioritization
-
Incident readiness
NIST AI Risk Management Framework (AI RMF)
For organizations deploying AI agents or GenAI systems, Passerum incorporates principles from the NIST AI RMF to evaluate:
-
Bias exposure
-
Output reliability
-
Governance gaps
-
Accountability controls
-
Risk documentation maturity
AI audits are structured, repeatable, and focused on real-world deployment risk.
ISO 27001 & Risk-Based Controls
Passerum’s risk prioritization logic follows ISO 27001 risk-based thinking:
-
Likelihood × Impact evaluation
-
Control gap identification
-
Documentation readiness
-
Continuous improvement mindset
This ensures assessments are business-aligned, not just technically detailed.
What Passerum Does
Passerum provides:
-
- Structured cybersecurity risk assessments aligned with NIST and ISO 27001
- Identification of gaps across core risk domains: Identify, Protect, Detect, Respond, Recover
- AI bias auditing focused on real-world system interactions
- Actionable, prioritized recommendations tailored to organizational context
The platform is designed to operate without requiring integration into IT infrastructure or access to sensitive data.
Enhance Your Cybersecurity Today
Explore our comprehensive resources designed to empower your business with the latest cybersecurity insights. From insightful articles to in-depth whitepapers, Passerum provides the tools you need to safeguard your digital assets effectively.
