PV
PilotVantage

Modules

Each module covers one part of your compliance programme. Here's what everything does and where to start.

Risk Register

Record and score risks by department, escalate to the organisation register and track treatment against your risk appetite.

Multi-Entity Management

Run several companies, regions or business units side by side — roll departmental risks up to business-unit and board level, with delegated admin.

Incidents

Log security incidents and drive them through a clear lifecycle — triage, investigate, contain, resolve and close — with a full timeline.

Controls

Track implementation across 14 built-in frameworks — ISO 27001, SOC 2, GDPR, HIPAA, DORA, NIS2 and more — plus custom frameworks, with a Statement of Applicability.

Audits

Plan internal audits, record findings and drive corrective actions to closure — so you walk into certification audits with evidence ready.

Third Parties

Keep a register of your suppliers and vendors, tier them by risk, track contracts and DPAs, and send security questionnaires for due diligence.

Questionnaires

Send security assessments to vendors, collect their answers through a secure public link — no account needed — and auto-score their security posture.

Trust Centre

Publish a public trust page that shows customers your live security posture — compliance stats, security documents with tiered access, FAQs and sub-processors.

Policies & Documents

Draft, approve and version your policy library, then collect staff acknowledgements with a shareable link — evidence auditors ask to see.

Evidence

Keep a central, audit-ready evidence store and link each item to the controls, risks, incidents and vendors it supports.

Actions

Turn findings, risks and reviews into assigned tasks with owners, priorities and due dates, and track every action through to completion.

Asset Register

Maintain an inventory of your information assets, classify them by sensitivity and assign owners — a core requirement of ISO 27001 and most frameworks.

Access Reviews

Run periodic user access reviews so the right people have the right access to the right systems — and keep the records auditors ask for.

Training & Awareness

Assign security awareness training, set deadlines, track completion across your whole team and evidence it for certification and audits.

Reports

Generate executive board packs and certification-ready PDF reports in one click, pulling live data from every module of your programme.

Which module should I use first?
Most teams start with the Risk Register and Policies, then bring in Controls and Evidence as they build towards certification.