Skip to main content

About ScopeWise

A Statement of Work or RFP is usually reviewed once, quickly, by someone who is not a lawyer, under time pressure to get a deal moving. Vague scope language, missing liability caps, and undefined acceptance criteria slip through -- and become expensive months later, once a project is already underway.

ScopeWise exists to catch that risk before signature, not manage it after. It started as a pre-signature review of SOWs and RFPs -- not a contract-lifecycle-management tool, and not a tool for drafting or responding to an RFP. Just: is this document safe to sign, and if not, exactly where is the risk.

The name stuck because the same question kept coming up in two other assessments consultancies deliver by hand. "Scope" is what is in and out of a contract; it is also what is in and out of a detection estate (which ATT&CK techniques your SIEM rules cover, and which are out of scope for your platforms) and of a codebase (which files a security scan read, and which findings an attacker can chain). ScopeWise now covers all three: SOW & RFP Review, MITRE ATT&CK Coverage and Code Security Review. In each one the numbers are computed by code, every finding quotes its evidence, and a model is used only where judgment is honest.

ScopeWise is built by a small team and is in early access -- if you're evaluating it for your organization, we'd like to hear from you.