Features
One system for the entire ISMS.
Registers, assessment, evidence, data protection and audit interlock - no switching between tools, no duplicate maintenance. The modules below are grouped the way the product itself is.
Daily operations
What the people who carry the ISMS see when they log in.
Control desk
Every obligation that is yours, across all modules, most urgent first - instead of hunting through registers to find what is due.
Digital colleague and hints
Ask questions about your own records and let them be swept for gaps. Every hint names the rule behind it and can be promoted to a finding or a task.
Tasks and checklists
Recurring obligations as a checklist, owners and deadlines included, with a complete-then-approve trail. Nothing falls through the cracks.
Notifications
Deadlines, approvals and changes reach the people responsible - in the system and as an email digest whose wording you control.
Registers
The inventory of your ISMS in one place - linked, versioned and analysable.
Risk register
Capture, assess and treat risks - with a traceable history, links to assets and controls, and an approval step separated from the author.
Asset register
Inventory information assets, classify them and assign owners. Protection needs inherit down the dependencies.
Applications and shadow IT
The inventory of what is actually in use, with an owner and an explicit approval decision per application.
Vendor register
Document service providers and their criticality - including contract, data categories, review cycles and review status.
Incidents and playbooks
Record incidents in a structured way and apply a reusable playbook that materialises the response as tracked tasks.
Threats and vulnerabilities
The BSI catalogue of elementary threats plus your own weakness catalogue, both linkable to the risks they drive.
Sites
Head office, data centre or plant as a scoping dimension - so a register can be read per location, not only per company.
Governance and metrics
The management-system half of ISO 27001, not just the control list.
Security objectives
Objectives per clause 6.2 with the measurement that decides whether they were met.
Management reviews
Reviews with their inputs and decisions, carrying open actions forward from the previous one instead of restarting.
KPI and maturity dashboards
Metrics and maturity levels per COBIT, by framework, unit and period, with the measurement history behind each figure.
Assessment campaigns
A dated pass you can freeze. Closing one locks every control status, so the next campaign shows the change rather than a fresh guess.
Governance cockpit
Review health across every register: what has never been reviewed, and what is overdue.
Implementation and evidence
From the applicability decision to the document an auditor accepts.
Gap assessment
Guided, control by control, in plain language - with a maturity level per COBIT and a trail of who assessed what, when.
Statement of Applicability
Generated from your applicability decisions and their justifications, not maintained as a second document. Exports as CSV.
Controls, cross-mapping and building blocks
One control set carries every framework. Describe a practice once as a building block and link it to all the controls it satisfies.
Documents with real-time collaboration
Write, approve and version policies together. Every approval is retained as evidence; export as PDF or DOCX.
BPMN process designer
Model the workflows that belong to a policy - in the open BPMN standard, linked to the policies, controls and assets they touch.
Exceptions
Time-boxed deviations with owner, approver and expiry, so a temporary exception cannot quietly become permanent.
Evidence
Artefacts with review and staleness dates, linked to the controls they prove - so you see what has gone stale before an auditor does.
Business continuity
Critical processes with RTO and RPO and their dependencies, connected to the assets and vendors they run on.
Data protection
The GDPR duties that sit next to the ISMS, in the same system rather than a separate tool.
Records of processing, Art. 30
The ROPA with purposes, legal bases, recipients and retention - linked to the assets and vendors it describes. Exports as CSV.
Data subject requests
Requests under Art. 15 to 22 with their one-month deadline, their owner and the record of what you answered.
Breach register
Art. 33 notifications with their own 72-hour clock, and the assessment that decides whether a notification is owed at all.
Data inventory
Where personal data actually sits and where it flows, as an inventory you can hand to a supervisory authority.
AI system register
The AI systems you build or use, with your role per system, its risk class and the Art. 14 and Art. 50 narrative fields.
Audit and trust
What you hand over when someone asks you to prove it.
Audit preparation
Walk the auditor's checkpoints, record each result and convert a failed one into a tracked task without leaving the audit.
Evidence requests
A thread per request between auditor and team, with the linked evidence and the comments attached to it.
Evidence packages
A control-to-evidence coverage map, and the closed ZIP package an auditor or a customer receives - the evidence, not your login.
Findings and remediation plan
Findings from any source in one register with owner, due date and remediation status - the plan of action an assessor expects.
Trust center
Share selected evidence in a controlled way - tiered, behind an NDA gate and with traceable access per prospect.
Questionnaires, both directions
Answer a customer's security questionnaire from live data, and send your own to service providers who reply without an account.
Organisation, access and integration
Who may see what, and how the platform fits your landscape instead of becoming another island.
Org chart and group ISMS
Divisions, departments and teams with their leads - and above them the group view that rolls subsidiaries up to the holding.
Roles and access matrix
Fine-grained permissions across five roles, shown as a matrix so you can answer who may do what without reading configuration.
Access requests and recertification
Request, approve and fulfil access with a joiner-mover-leaver trail, and recertify it in campaigns whose items freeze at review start.
Acknowledgments and training
Who has read which policy and completed which training - the evidence clause A.6.3 and NIS2 Art. 20 both ask for.
Record visibility
Optional need-to-know filtering that narrows rows by org unit or site membership, off by default and auditable when on.
SSO, SCIM and passkeys
Sign in through your identity management with access provisioned and revoked automatically. Passkeys and two-factor come as standard.
Open interfaces
A read-only REST API and MCP interface for your own analyses, signed webhooks per event, and CSV import and export for every register.
OSCAL and your own frameworks
Export catalogues, profiles and assessment results as OSCAL, import mappings, and author frameworks of your own alongside the built-in ones.
Self-hosting and licence
Runs on your own server or in your own Docker environment. Activation is a pasted key; an expired licence turns the system read-only, never off.