The platform

Be secure and compliant.

Pillar one tells you what is missing. Pillar two closes the technical half. Both write to the same evidence trail.

See what is available
Pillar 1

Risk and Compliance

Know where you stand, and what to do about it. Your profile becomes a ranked gap list, a risk register and an evidence trail that is audit-ready on demand.

Guided action plan

Five phases from scoping to audit-ready evidence, every task with an owner, a deadline and a time estimate.

Framework mapping

Live completion for ISO 27001, NIS2, CIS, DORA, GDPR and TISAX, all counting from one control set.

Business assessment and impact analysis

A structured questionnaire models what you do, what you depend on and what would hurt. Everything downstream is ranked by it.

Control library

One control set with owners and status, mapped across every framework you target. Map a control once, comply many times.

Risk register

Risks with owners, treatments and deadlines. Findings from the tooling land here automatically, and overdue treatments chase you on the home screen.

Policy library

Templates already mapped to your framework, with versions, approvers and staff acceptance tracking.

Vendor and asset registers

Your suppliers and systems in one inventory, with supply-chain risk and asset classification where your auditor looks.

Progress reports and audit packs

Every action leaves a signed record, and packs generate on demand for management or the audit room.

Pillar 2

Security Operations

Close the gaps the roadmap found. Detection, exposure and resilience: the tooling that closes the technical items on your gap list. Switch it on when you need it.

Detection and alerts

Agents stream events into the platform with alerts by severity. What escalates is what matters to your business, not what scored highest on a generic scale.

Incident tracking

Alerts that matter become incidents with owners and status, tracked next to the risks they belong to.

Exposure and cloud posture

Vulnerability findings, cloud compliance checks and patch oversight, each with a recommended fix.

Business-context triage

Findings are checked against your profile and the risks already on your register, so you hear about the ones that matter to you.

One evidence engine

Detections, findings and fixes feed the same evidence engine as the compliance work. Findings arrive prioritised, with a recommended action.

Resilience

Backups verified, not assumed. Restore tests, recovery targets and plan owners live in the platform instead of a policy folder.

Supply chain risk

Vendor assessments and supplier alerts, so a supplier's incident hits your register the same day.

Integrations

Bring the tools you trust.

Connected systems feed posture, vulnerabilities and logs automatically. Already running a SIEM, EDR, IAM, backup or training vendor you do not want to displace? We integrate it into the same gap list and the same evidence trail, so the work it already does counts.

How the pillars connect

A ranked list, and the tooling to close it.

Pillar one hands you the gap list. Some of it you close yourself: a policy, a training session, an owner. The rest is technical, and that is where most companies stall. Pillar two closes those. Same platform, no second vendor.

Model

Model the business

Sector, size, estate, tooling, deadline. Everything else is built from this. Model the business once, not once per audit.

List gaps

See what is missing

Every control you owe, checked against what you already have. Worst gaps first. Each one says what closes it.

Close it

Do the work

Policies, training and owners are yours. The technical items close with pillar two. Switch it on when the list calls for it.

Prove it

Hold the evidence

Every action leaves a signed record. Board packs and auditor packs generate on demand. Regulator notifications come drafted for you to confirm and submit.

FAQ

Common questions about the platform.

Is CloudSoul a SaaS platform or a managed service?

It is a complete SaaS platform. Continuous scanning, vulnerability and patch oversight, and evidence collection are platform features that run automatically.

What does Risk and Compliance do?

It is one of the two platform pillars: know where you stand, and what to do about it. It profiles your business and IT, runs the assessment, produces the gap list in priority order, holds the evidence and reports out. Risks, policies, controls, frameworks: all in one place.

Can I bring my existing tools (SIEM, EDR, etc.)?

Yes. If you have an incumbent SIEM, EDR, IAM, backup, or training vendor you want to keep, it feeds the same evidence engine and the same plan as everything else. Custom integrations are scoped per request.

Where does my data live?

In the EU. CloudSoul is hosted on EU-owned infrastructure, not an EU region of a US-owned provider, so there is no US Cloud Act exposure. Models are open source, on our own hardware or served by European providers, and your data is never used to train a model.

What frameworks does the platform support?

The mapping engine covers NIS2, ISO 27001, CIS, DORA, GDPR and TISAX. Once a control is mapped, it carries across frameworks, so adding ISO 27001 does not mean rebuilding your control library.

How is the platform priced?

Annual contracts with monthly billing, sized by employee band. You get the exact numbers on the first call, and a written offer within 24 hours.

Do you offer a one-off security assessment?

Yes, the Security Audit: an independent audit of your systems and posture. Automation does the collection, a vCISO validates, prioritises and writes the recommendations, and you get a ranked gap list you can use as your roadmap.

Does this still hold as we grow?

That is the point of modelling the business rather than writing it up once. Hire people, open a site, add a supplier or a new system, and you update the model instead of rewriting a folder of documents. What you show an auditor keeps describing the company you actually are.

Unified platform for cybersecurity compliance.
See what is available