Help & user guide
Everything ShieldIQ does, and how to get value from it fast. Jump to a section, or start with the four-step quick start below.
Quick start — from zero to a compliance picture in ~15 minutes
- 1Run an assessment — pick a framework and answer to your current practice.
- 2Read your results — AI scores, radar and prioritised fixes per category.
- 3Generate actions & risks — turn gaps into a tracked remediation plan.
- 4Build your GRC — controls, policies, assets, vendors, evidence.
Getting started
ShieldIQ turns a framework questionnaire into a live GRC programme. The typical flow is assess → understand → remediate → maintain. Use the sidebar to move between modules; press ⌘K (or Ctrl K) anywhere to jump to any page or run a quick action.
- • The Dashboard is your posture at a glance — overall score, GRC counts, trends and due items. The same overall score rides in the top bar as an always-visible posture meter.
- • Everything is multi-tenant and role-aware; invite your team and set workspace security policy from Admin.
- • You must verify your email before signing in — check your inbox after registering, or use the resend link on the login page.
- • Your plan sets which frameworks and limits you get — see Plans & billing.
Assessments
Assessments are the engine. Choose a framework, answer maturity questions, and Claude produces per-category scores, narrative analysis and prioritised suggestions.
- • Pick a framework on New assessment. Locked frameworks show an Upgrade button — higher plans unlock more.
- • Answering — questions are grouped by domain; some are conditional (appear based on earlier answers). Your progress autosaves server-side, so you can resume on any device.
- • Results — an overall score, a per-function radar, and expandable categories with AI analysis + improvement steps. Re-take any time to track progress over quarters.
Dashboard
The Dashboard aggregates your whole programme: overall compliance, score by function, GRC summary cards (risks, controls, policies, actions), risk severity, framework coverage and score trends. An onboarding checklist guides first-time setup.
Risk register
Track risks with likelihood × impact scoring on a colour-coded 5×5 matrix whose cells deep-link to the filtered register.
- • Treatment plans — attach structured plans with budgets, target dates and milestones; a progress bar tracks completion.
- • Formal acceptance — when you accept a risk, raise an acceptance request with justification, business case and evidence; an admin (never the requester) signs it off. Revoking reopens the risk.
- • Auto-generation — low-scoring assessment categories and material FRIA harms can create risks automatically; vendor rejections raise a linked third-party risk.
Controls & mapping
The control library tracks implementation status across your frameworks.
- • Framework mappings — map each control to the framework categories it satisfies (feeds compliance coverage).
- • AI gap analysis — pick a source and target framework and Claude estimates your readiness, strong areas and prioritised gaps.
- • Cross-framework Mapping — see how a control or requirement in one framework corresponds to others, so work done for one standard counts toward the rest.
- • Generate remediation actions straight from unimplemented controls.
Policies
Author, version and track acknowledgment of your policies (markdown, rendered to clean HTML).
- • Template gallery — adopt a ready-made policy as an editable draft.
- • AI generator — describe scope + requirements and Claude drafts a tailored policy you can review and save.
- • Versioning & acknowledgment — edits create a new version automatically; staff acknowledge and you track who has.
Remediation actions
A kanban board (To do → In progress → Done) for remediation. Drag cards or use the no-JS controls; completing an action updates its linked control and risk automatically. One-click generate from open risks, unimplemented controls, or assessment gaps.
Open actions →Assets
Maintain an asset inventory with type, data classification and criticality. Assets link to risks and vendors so impact ratings stay grounded in what actually matters.
Open assets →Vendors (TPRM)
Third-party risk management: register vendors with criticality, data access and DPA status.
- • Send questionnaires — start an assessment from a template and send the vendor a secure token link to self-assess.
- • Review → auto-risk — record your decision; a rejection or conditional pass can raise a linked third-party risk.
- • Trust network — search vendors already assessed across ShieldIQ and import their profile.
Incidents
Log and manage security incidents with a timeline, playbooks and regulatory deadline countdowns (NIS2 / GDPR / DORA). AI can draft breach notifications; export a regulator-ready pack.
Open incidents →Evidence
A central evidence library — upload documents (virus-scanned, validated) and attach them to controls, risks and audits. Expiry tracking flags evidence that needs refreshing.
Open evidence →Business continuity & pen testing
- • BCDR — log business-continuity and disaster-recovery exercises with type, outcome and auto-generated reference; upcoming and overdue re-tests are highlighted so nothing lapses.
- • Pen tests — a penetration-test repository tracking findings by severity (critical / high / medium / low), open critical+high counts, status workflow and retest-due dates.
GDPR, AI & CRA — ROPA / DPIA / FRIA
- • ROPA — records of processing activities (Art. 30) with legal basis and special-category flags.
- • DPIA — data protection impact assessments with DPO sign-off, the Art. 36 prior-consultation gate for high residual risk, versioning and scheduled reviews.
- • FRIA — fundamental-rights impact assessments for AI systems (EU AI Act Art. 27), generate-risks from identified harms, and sign-off.
- • AI systems — an inventory of the AI you build or use, with risk classification, feeding your FRIAs.
- • CRA reports — EU Cyber Resilience Act tracking with the 24-hour / 72-hour / 14-day notification stages for products with digital elements.
Scanner & threat intel
- • Scanner — run network/vulnerability scans (quick, standard, deep by plan); results poll in live and feed your risk picture.
- • Threat intel — live CISA KEV (with EPSS), ransomware activity and security news, plus the regulatory horizon and recent enforcement.
Calendar & activity
- • Calendar — a month view of everything with a date: reassessment cadences, policy and DPIA reviews, evidence expiry, incident and CRA deadlines and re-tests. Use it to stay ahead of what's due.
- • Activity — a day-grouped feed of everything that has happened across your workspace, so you can see recent changes and who made them at a glance.
Certificates & scheduling
- • Certificates — generate a shareable compliance certificate from a qualifying assessment; anyone can verify it via its public code.
- • Schedule reassessment cadences and set per-category maturity targets to measure against.
Reports & exports
Every results page has a print-perfect report (browser → Save as PDF) and CSV export (by plan). Higher tiers add an auditor export pack and emailed reports.
Team, roles & admin
Invite colleagues, assign roles and track seat usage from Admin (workspace owners and admins only).
- • Roles — admins manage the workspace; members do the day-to-day; the auditor role gives read-only access for external reviewers.
- • Security policy — enforce MFA across the workspace (with a grace period), set a minimum password length and a session-timeout, so your standards apply to everyone.
- • Audit trail — a detailed log of who did what, when, to which record, with the outcome and source IP — useful for evidence and investigations.
- • Usage meters show seats and per-module counts against your plan.
Account & security
Manage your profile and password, and turn on multi-factor authentication (scan the QR with any authenticator app) from Account. You can review trusted devices and disable MFA with your password.
- • Email verification is required before any account can be used — this protects against someone signing up with an address that isn't theirs.
- • Recent sign-ins lists your logins with a risk rating (device, location, impossible travel, time-of-day and IP reputation). Your workspace admin sets the weighting, alert threshold and notifications under Admin → Security policy.
- • Changing your password signs you out everywhere; password-reset links are single-use and expire after an hour.
Plans & billing
Compare tiers, see exactly what each includes, and upgrade instantly — payment and invoicing are handled securely by Stripe. Change or cancel any time from the customer portal.
View plans →Support
Still stuck? Email info@shieldiqcyber.com — response times depend on your plan. Business and Enterprise plans include priority support and onboarding sessions.