Modules
Each module covers one part of your compliance programme. Here's what everything does and where to start.
Record and score risks by department, escalate to the organisation register and track treatment against your risk appetite.
Run several companies, regions or business units side by side — roll departmental risks up to business-unit and board level, with delegated admin.
Log security incidents and drive them through a clear lifecycle — triage, investigate, contain, resolve and close — with a full timeline.
Track implementation across 14 built-in frameworks — ISO 27001, SOC 2, GDPR, HIPAA, DORA, NIS2 and more — plus custom frameworks, with a Statement of Applicability.
Plan internal audits, record findings and drive corrective actions to closure — so you walk into certification audits with evidence ready.
Keep a register of your suppliers and vendors, tier them by risk, track contracts and DPAs, and send security questionnaires for due diligence.
Send security assessments to vendors, collect their answers through a secure public link — no account needed — and auto-score their security posture.
Publish a public trust page that shows customers your live security posture — compliance stats, security documents with tiered access, FAQs and sub-processors.
Draft, approve and version your policy library, then collect staff acknowledgements with a shareable link — evidence auditors ask to see.
Keep a central, audit-ready evidence store and link each item to the controls, risks, incidents and vendors it supports.
Turn findings, risks and reviews into assigned tasks with owners, priorities and due dates, and track every action through to completion.
Maintain an inventory of your information assets, classify them by sensitivity and assign owners — a core requirement of ISO 27001 and most frameworks.
Run periodic user access reviews so the right people have the right access to the right systems — and keep the records auditors ask for.
Assign security awareness training, set deadlines, track completion across your whole team and evidence it for certification and audits.
Generate executive board packs and certification-ready PDF reports in one click, pulling live data from every module of your programme.