The complete AI-powered GRC platform for SMEs

Compliance, Risk, Privacy & Security.
One intelligent platform.

Run assessments across 9 frameworks. Manage controls, policies, risks, vendors, assets, incidents and DPIAs from one place. Let AI draft your policies, judge your evidence, find your gaps, and keep you audit-ready.

No credit card  ·  ~15 min first assessment  ·  Cancel anytime

9
Frameworks
18+
GRC modules
5
AI features
259
Questions
<15
Minutes to first score
9 Frameworks

Every Framework Your Business Needs

The full GRC platform

Everything you need. Nothing you don't.

Eighteen integrated modules covering compliance assessments, governance, risk, privacy, third-party management, incidents, security hardening and audit reporting.

Assessments

9 frameworks, AI scoring per category, spider graphs, target maturity overlay.

Control Library

Cross-framework controls with status, evidence and assessment auto-linking.

Policy Manager

Versioned policies, control mappings, employee acknowledgments. AI drafter.

Risk Register

5×5 grid + FAIR-lite quantitative loss expectancy + treatment plans.

Asset Register

Inventory with criticality, classification, ownership and control links.

Vendor Risk (TPRM)

Lite + Standard questionnaires. Auto-generates risks from poor scores.

Incident Management

Auto 72h GDPR / 24h NIS2 / 4h DORA deadlines. AI drafts the regulator notification.

Network Scanner

NMAP scans with AI analysis of open ports and vulnerabilities.

ROPA Register

GDPR Art. 30 records of processing activities. Regulator-ready CSV export.

DPIA Workflow

GDPR Art. 35 6-step wizard with auto Art. 36 prior-consultation trigger.

Compliance Calendar

Unified view of audits, reviews, evidence expiries, contract renewals and deadlines.

Pen Test Repository

Structured engagement records with findings, retest schedule, risk linkage.

Remediation Tracker

Kanban board with effort/impact priorities, assignment and due dates.

Audit Log + Activity Feed

Tamper-evident trail with PII pseudonymisation, comments, @mentions.

Team & Auditor Mode

Org accounts, roles, time-boxed read-only auditor access, comments.

Security Hardening

Forced MFA, login anomaly detection, trusted devices, tenant policy.

Bulk CSV Import/Export

Risks, assets, vendors. Preview + validate + confirm. No 200-row hand entry.

Customisable Dashboard

Drag, collapse, reorder. Compliance snapshot, trends, benchmarks, calendar widget.

AI Capabilities

Five AI features. One unified credit pool.

Built into the platform. Generous monthly allowances on every paid tier — no surprise overage bills, no margin death-spiral.

AI Assessment Scoring

Each category individually analysed by our AI with full business context. 2-3 paragraphs per category. Free, bundled into every assessment.

AI Policy Generator

Pick a policy type, scope, and framework. Our AI drafts a tailored policy you can review, edit and save as a versioned draft.

AI Evidence Analyser

Upload a file, get a verdict — satisfies / partial / does not satisfy — plus confidence score and gap analysis. Vision for screenshots.

AI Cross-Framework Gap Analysis

Picked NIST CSF? Want to know how close you are to ISO 27001 or SOC 2? Coverage % + gap list with priority and effort.

AI Incident Drafter

Triggered an Art. 33 / NIS2 incident? Our AI drafts your regulator notification using the incident data and the right legal template.

AI Risk Auto-Generation

Low-scoring assessment categories and poor-scoring vendors automatically generate risk register entries with appropriate likelihood + impact.

Privacy & GDPR

Native GDPR workflows. None of your competitors ship them.

Article 30 records of processing activities and Article 35 data protection impact assessments — built in, regulator-grade, with the EDPB-template rigour your DPO actually wants.

ROPA Register Art. 30
Records of Processing Activities
  • Full Art. 30(1) controller field set
  • Art. 6 legal basis + Art. 9 special category dropdowns
  • Children's data flag (Art. 8)
  • Third-country transfer builder (SCCs / BCRs / adequacy)
  • Linked to your Asset and Vendor registers
  • Regulator-ready CSV export
DPIA Workflow Art. 35
Data Protection Impact Assessment
  • 6-step EDPB-template wizard
  • Inline risk + mitigation builders
  • Auto Art. 36 trigger when residual risk is high
  • DPO sign-off; signed-off DPIAs are immutable
  • Version supersede flow when processing changes
  • Linked to ROPA records for traceability
Risk management

Beyond the 5×5 grid.

Quantitative loss expectancy. Formal acceptance workflow with separation of duties. Treatment plans with budget tracking. Vendor-inherited risks. Everything you'd expect from an enterprise GRC tool — at SME prices.

FAIR-lite Quantitative

Single Loss Expectancy × Annual Rate of Occurrence = Annualized Loss Expectancy in real money. Roll up across the tenant for a board-ready exposure number.

Acceptance Workflow

Formal request → admin/DPO sign-off → optional expiry → auto-reopen on expiry. Separation of duties: requesters can never self-approve.

Treatment Plans + Budget

Multiple plans per risk. Estimated vs actual cost with auto variance. Milestones with their own status. Portfolio rollup of total spend across the tenant.

Vendor-Inherited Risks

When a vendor scores poorly on TPRM, the platform auto-generates an inherited risk in your register, linked back to the vendor and its assessment.

Security hardening

Your platform shouldn't be a weak link.

Tenant-configurable security policy, login anomaly detection, trusted devices, and a structured pen test repository. Built with the rigour you'd want from a tool managing your compliance evidence.

Login Anomaly Detection
5-factor risk scoring on every sign-in
  • New country detected (+30)
  • New device fingerprint (+15)
  • Impossible travel (+50, distance vs time)
  • Unusual hour vs your history (+10)
  • Known-bad IP (+20)

High-risk sign-ins fire an email alert. Trusted devices skip the new-device flag. Geolocation cached.

Tenant Security Policy
Admin-controlled, applied org-wide
  • Force MFA org-wide with grace period
  • Idle session timeout + absolute max
  • Password length floor + complexity
  • Anomaly alert email opt-in
  • Step-up MFA on high-risk sign-ins

Plus structured pen test report repository with engagement metadata, severity-bucketed findings, retest scheduling and risk linkage.

What you get

Outputs your auditor will actually accept.

One platform. Nine frameworks. Zero spreadsheets.

AI-Powered Risk Scoring

Each category scored 0-100% by our AI with full understanding of your specific business context. Not a generic checklist — a personalised compliance analysis.

73%
Boardroom-Ready Reports

Spider graphs, risk heatmaps, executive summaries, and branded PDF reports. Present to the board with confidence — everything's already formatted.

PDF CSV Email
Prioritised Recommendations

Every suggestion rated by effort and impact. Know exactly what to fix first. No more guessing where to invest your security budget.

Low Effort High Impact Fix First
Network Vulnerability Scanner

Scan any IP or domain with AI. AI analyses open ports, services, and vulnerabilities, then tells you exactly what to fix.

Quick Standard Deep
Outputs

See Exactly What You'll Get

  • Overall compliance score per framework
  • Spider graph with target maturity overlay
  • Red/amber/green risk heatmap
  • Category-level AI analysis (2-3 paragraphs each)
  • Prioritised actions with effort/impact ratings
  • Benchmark vs other organisations
  • Branded PDF report for the board
  • Network vulnerability scan with AI findings
  • Remediation tracker (Kanban board)
  • Compliance certificates & embeddable badges
  • Cross-framework gap analysis
73%
NIST CSF
68%
NIS2
81%
GDPR
76%
ISO 27001
Top action: Enable MFA on all critical systems Low Effort / High Impact
Simple Process

Four Steps to Compliance Clarity

1
Choose Framework

Pick from 9 frameworks: NIST CSF 2.0, NIS2, GDPR, ISO 27001, DORA, SOC 2, Cyber Essentials, EU AI Act, PCI DSS.

2
Answer 25-30 Questions

Practical, jargon-free questions. Auto-saves as you go. Takes ~15 minutes.

3
AI Analyses Every Answer

Each category assessed individually. Watch real-time progress as AI works through your responses.

4
Get Your Report

Scores, graphs, heatmap, prioritised actions. Download PDF, export CSV, email to stakeholders.

Platform Features

Built for Compliance Teams Who Mean Business

Target Maturity Levels
Set goals per category, visualise on spider graph
Risk Heatmap
Instant visual of strengths & weaknesses
Benchmark Comparison
Your scores vs platform average
Team Collaboration
Org accounts, shared assessments, role-based access
Evidence Upload
Attach policies, screenshots, certificates
Scheduled Reassessments
Set reminders, track compliance over time
Network Scanner
NMAP scans with AI vulnerability analysis
Remediation Tracker
Kanban board for compliance improvement tasks
Compliance Certificates
Verified badges for your website
Cross-Framework Mapping
See overlap between frameworks you've assessed
Expert Support CTA
WhatsApp links on low-scoring categories
Pricing

Simple, transparent pricing.

Start free. Upgrade only when you need more. Save ~17% on annual billing.

Monthly Annual −17%
Starter
€0

free forever


  • NIST CSF 2.0 only
  • 1 assessment/quarter
  • Watermarked PDF reports
  • Spider graph + heatmap
  • 1 user
Individual
€79

per month


Everything in Starter, plus:
  • 3 frameworks of choice
  • Risk register — up to 25 risks
  • Incident management + 5 AI drafts/mo
  • 10 AI credits/month
  • Email support (48h)
Most popular
Professional
€169

per month


Everything in Individual, plus:
  • 5 frameworks ↑ from 3
  • 150 risks in the register ↑ from 25
  • Asset register — up to 100 assets NEW
  • ROPA Art. 30 + Calendar + Comments
  • FAIR-lite + AI Policy Generator
  • 50 AI credits · 5 seats ↑ from 10
Business
€399

per month


Everything in Professional, plus:
  • All 9 frameworks ↑ from 5
  • 1,000 risks + 1,000 assets ↑ from 150 / 100
  • DPIA workflow (Art. 35) NEW
  • TPRM + Auditor mode + Bulk import
  • Treatment plans + Audit ZIP
  • 200 AI credits · 15 seats ↑ from 50
Enterprise
€1,099+

per month


Everything in Business, plus:
  • Unlimited risks, assets, policies
  • Custom frameworks
  • SSO/SAML + SCIM provisioning
  • Data residency options
  • Unlimited seats, orgs, AI credits
  • Dedicated CSM, 4h SLA

All paid plans available with annual billing — pay for 10 months, get 12 (~17% discount). Charity, education and early-adopter discounts available.

Ready to Know Where You Stand?

Free to start. No credit card. Your first assessment takes under 15 minutes.