A whole GRC programme, in one application

Every module shares the same controls library, the same owners and the same calendar, so work done in one place shows up everywhere it counts. Every feature is in every plan, and in the free trial.

Frameworks and compliance

Standards turned into work you can finish

Adopt the security standards, privacy laws and sector regulations that apply to you. Their requirements map onto one shared controls library, so a control implemented once counts for every framework that needs it.

  • A framework-to-project-plan generator, with implementation guidance for each control
  • Audit readiness per framework, weighted by criticality, with its blockers and trend
  • Continuous control checks that test collected evidence and raise or close findings
  • A regulations register that tracks changes to the rules you follow
Evidence and audits

Evidence that is collected, current and easy to hand over

Upload evidence or collect it on a schedule from cloud, source-control and identity providers, and map it automatically to every control it satisfies. When an audit comes, sample controls, write findings in workpapers and export a bundle for the external auditor.

  • Evidence freshness: what is about to go stale, and who has to renew it
  • Audit windows, certifications and governance ceremonies on one calendar
  • Findings, exceptions and risks on one severity scale
Risk and governance

Risk management that leads to decisions

Score risks before and after controls, set an appetite for each category, and require two approvers to accept anything above it. Key risk indicators keep their history and alert on breaches; business objectives show how well their risks are covered.

  • Heat maps, treatment plans and risk owners with dated actions
  • A key risk indicator library to start from
  • Policies with templates, versions and a review and approval workflow
  • Separation of duties on every approval, and toxic permission combinations reported
Third parties

Vendor risk with the reasoning shown

Tier vendors automatically and see why. Send assessment questionnaires by link or email; vendors answer without an account. Criticality comes from the business processes and recovery objectives that depend on each vendor.

  • Trust and exposure scores fed by profiles and assessments
  • Concentration and single points of failure
  • Contract renewals, terms-of-service reviews and offboarding checklists
Assets, vulnerabilities and exposure

From inventory to remediation

An inventory of software and systems linked to the vendors behind them, a vulnerability register fed by public vulnerability data and scanner exports, and remediation deadlines ranked by known exploitation and exploit probability.

  • Imports of common vulnerability-scanner export formats
  • External attack-surface discovery from certificate transparency for your verified domains
  • Certificate expiry watch, data classification and threat models traced to controls
Incidents and resilience

Ready before something goes wrong

Log incidents, assign them through an on-call rota, and see which notification obligations they trigger, where, and how long you have. Business impact analysis, continuity, recovery and response plans keep phased, role-tagged steps and recurring reviews.

  • A live countdown to each regulatory notification deadline, with escalation
  • Corrective actions and structured post-incident reviews
  • Incidents linked to the risks they realised
Privacy and AI governance

The newest obligations, covered

A record of processing activities with lawful bases and transfer safeguards, impact-assessment screening and sign-off, and data-subject requests. A register of AI systems and agents classifies each one under the EU AI Act and lists the obligations it triggers.

  • Where restricted data flows, from the systems that hold it
  • AI impact assessments, scheduled evaluations and kill-switch tests
  • Detection of AI in use that nobody registered
Also included

The rest of the programme

Identity and access

Access reviews where "revoke" removes the access, time-limited group membership, just-in-time requests and recorded break-glass sessions.

People

Security-awareness and AI-literacy training with completion evidence, phishing-simulation records with refreshers, and a privacy-respecting human-risk score.

Reporting

Executive dashboards, a composite posture score, configurable alerts and a board pack in your branding that can be emailed every month.

My Work and the calendar

Every module produces owned, dated actions: each person sees theirs in one queue, and the whole programme shares one calendar.

AI assistant

Optional. A read-only assistant answers questions from your own records, and drafts suggestions that a person accepts. It uses the AI provider and model you choose.

Integration

A REST API with scoped keys, single sign-on with SAML and role mapping, SCIM provisioning, and imports and exports in common formats.

Several organisations

Subsidiaries, business units or clients in one installation, strictly separated, with parent organisations able to see their children.

14 languages

The interface in English, French, German, Spanish, Portuguese, Italian, Dutch, Danish, Swedish, Norwegian, Finnish, Polish, Greek and Japanese, with local dates and numbers.

Backups and restores

Scheduled backups of the encrypted database and the evidence, and a trash bin that restores anything deleted by mistake.

Try every feature for 30 days

Install it on a test server and see the whole programme working, with no account and no card.