ShieldIQ Sign in

Help & user guide

Everything ShieldIQ does, and how to get value from it fast. Jump to a section, or start with the four-step quick start below.

Quick start — from zero to a compliance picture in ~15 minutes

  1. 1Run an assessment — pick a framework and answer to your current practice.
  2. 2Read your results — AI scores, radar and prioritised fixes per category.
  3. 3Generate actions & risks — turn gaps into a tracked remediation plan.
  4. 4Build your GRC — controls, policies, assets, vendors, evidence.

Getting started

ShieldIQ turns a framework questionnaire into a live GRC programme. The typical flow is assess → understand → remediate → maintain. Use the sidebar to move between modules; press ⌘K (or Ctrl K) anywhere to jump to any page or run a quick action.

  • • The Dashboard is your posture at a glance — overall score, GRC counts, trends and due items. The same overall score rides in the top bar as an always-visible posture meter.
  • • Everything is multi-tenant and role-aware; invite your team and set workspace security policy from Admin.
  • • You must verify your email before signing in — check your inbox after registering, or use the resend link on the login page.
  • • Your plan sets which frameworks and limits you get — see Plans & billing.

Assessments

Assessments are the engine. Choose a framework, answer maturity questions, and Claude produces per-category scores, narrative analysis and prioritised suggestions.

  • Pick a framework on New assessment. Locked frameworks show an Upgrade button — higher plans unlock more.
  • Answering — questions are grouped by domain; some are conditional (appear based on earlier answers). Your progress autosaves server-side, so you can resume on any device.
  • Results — an overall score, a per-function radar, and expandable categories with AI analysis + improvement steps. Re-take any time to track progress over quarters.

Dashboard

The Dashboard aggregates your whole programme: overall compliance, score by function, GRC summary cards (risks, controls, policies, actions), risk severity, framework coverage and score trends. An onboarding checklist guides first-time setup.

Risk register

Track risks with likelihood × impact scoring on a colour-coded 5×5 matrix whose cells deep-link to the filtered register.

  • Treatment plans — attach structured plans with budgets, target dates and milestones; a progress bar tracks completion.
  • Formal acceptance — when you accept a risk, raise an acceptance request with justification, business case and evidence; an admin (never the requester) signs it off. Revoking reopens the risk.
  • Auto-generation — low-scoring assessment categories and material FRIA harms can create risks automatically; vendor rejections raise a linked third-party risk.
Open the risk register →

Controls & mapping

The control library tracks implementation status across your frameworks.

  • Framework mappings — map each control to the framework categories it satisfies (feeds compliance coverage).
  • AI gap analysis — pick a source and target framework and Claude estimates your readiness, strong areas and prioritised gaps.
  • Cross-framework Mapping — see how a control or requirement in one framework corresponds to others, so work done for one standard counts toward the rest.
  • • Generate remediation actions straight from unimplemented controls.
Open controls →

Policies

Author, version and track acknowledgment of your policies (markdown, rendered to clean HTML).

  • Template gallery — adopt a ready-made policy as an editable draft.
  • AI generator — describe scope + requirements and Claude drafts a tailored policy you can review and save.
  • Versioning & acknowledgment — edits create a new version automatically; staff acknowledge and you track who has.
Open policies →

Remediation actions

A kanban board (To do → In progress → Done) for remediation. Drag cards or use the no-JS controls; completing an action updates its linked control and risk automatically. One-click generate from open risks, unimplemented controls, or assessment gaps.

Open actions →

Assets

Maintain an asset inventory with type, data classification and criticality. Assets link to risks and vendors so impact ratings stay grounded in what actually matters.

Open assets →

Vendors (TPRM)

Third-party risk management: register vendors with criticality, data access and DPA status.

  • Send questionnaires — start an assessment from a template and send the vendor a secure token link to self-assess.
  • Review → auto-risk — record your decision; a rejection or conditional pass can raise a linked third-party risk.
  • Trust network — search vendors already assessed across ShieldIQ and import their profile.
Open vendors →

Incidents

Log and manage security incidents with a timeline, playbooks and regulatory deadline countdowns (NIS2 / GDPR / DORA). AI can draft breach notifications; export a regulator-ready pack.

Open incidents →

Evidence

A central evidence library — upload documents (virus-scanned, validated) and attach them to controls, risks and audits. Expiry tracking flags evidence that needs refreshing.

Open evidence →

Business continuity & pen testing

  • BCDR — log business-continuity and disaster-recovery exercises with type, outcome and auto-generated reference; upcoming and overdue re-tests are highlighted so nothing lapses.
  • Pen tests — a penetration-test repository tracking findings by severity (critical / high / medium / low), open critical+high counts, status workflow and retest-due dates.

GDPR, AI & CRA — ROPA / DPIA / FRIA

  • ROPA — records of processing activities (Art. 30) with legal basis and special-category flags.
  • DPIA — data protection impact assessments with DPO sign-off, the Art. 36 prior-consultation gate for high residual risk, versioning and scheduled reviews.
  • FRIA — fundamental-rights impact assessments for AI systems (EU AI Act Art. 27), generate-risks from identified harms, and sign-off.
  • AI systems — an inventory of the AI you build or use, with risk classification, feeding your FRIAs.
  • CRA reports — EU Cyber Resilience Act tracking with the 24-hour / 72-hour / 14-day notification stages for products with digital elements.

Scanner & threat intel

  • Scanner — run network/vulnerability scans (quick, standard, deep by plan); results poll in live and feed your risk picture.
  • Threat intel — live CISA KEV (with EPSS), ransomware activity and security news, plus the regulatory horizon and recent enforcement.

Calendar & activity

  • Calendar — a month view of everything with a date: reassessment cadences, policy and DPIA reviews, evidence expiry, incident and CRA deadlines and re-tests. Use it to stay ahead of what's due.
  • Activity — a day-grouped feed of everything that has happened across your workspace, so you can see recent changes and who made them at a glance.

Certificates & scheduling

  • Certificates — generate a shareable compliance certificate from a qualifying assessment; anyone can verify it via its public code.
  • Schedule reassessment cadences and set per-category maturity targets to measure against.

Reports & exports

Every results page has a print-perfect report (browser → Save as PDF) and CSV export (by plan). Higher tiers add an auditor export pack and emailed reports.

Team, roles & admin

Invite colleagues, assign roles and track seat usage from Admin (workspace owners and admins only).

  • Roles — admins manage the workspace; members do the day-to-day; the auditor role gives read-only access for external reviewers.
  • Security policy — enforce MFA across the workspace (with a grace period), set a minimum password length and a session-timeout, so your standards apply to everyone.
  • Audit trail — a detailed log of who did what, when, to which record, with the outcome and source IP — useful for evidence and investigations.
  • Usage meters show seats and per-module counts against your plan.

Account & security

Manage your profile and password, and turn on multi-factor authentication (scan the QR with any authenticator app) from Account. You can review trusted devices and disable MFA with your password.

  • Email verification is required before any account can be used — this protects against someone signing up with an address that isn't theirs.
  • Recent sign-ins lists your logins with a risk rating (device, location, impossible travel, time-of-day and IP reputation). Your workspace admin sets the weighting, alert threshold and notifications under Admin → Security policy.
  • • Changing your password signs you out everywhere; password-reset links are single-use and expire after an hour.

Plans & billing

Compare tiers, see exactly what each includes, and upgrade instantly — payment and invoicing are handled securely by Stripe. Change or cancel any time from the customer portal.

View plans →

Support

Still stuck? Email info@shieldiqcyber.com — response times depend on your plan. Business and Enterprise plans include priority support and onboarding sessions.