Security compliance and operations for software companies.
ISO 27001, NIS2 and GDPR mapped to one control set. Customer security questionnaires answered from the same record. Technical gaps closed in the same platform.
One control set for every requirement.
The tools a software company needs to answer enterprise buyers, auditors and regulators from one record.
Map a control once, satisfy every framework.
Live completion for ISO 27001, NIS2 and GDPR from one control set, so the customer who asks for ISO and the customer who asks for NIS2 are answered by the same work.
Read the answers instead of writing them.
Every control carries its owner, status and evidence, so the next customer questionnaire or auditor pack is generated rather than assembled the week before.
Repos, cloud accounts and suppliers, listed.
The inventory most software companies know but have never written down, in the same place the auditor looks and the supplier register your customers ask for.
Find it before your customer scanner does.
Vulnerability findings, cloud configuration checks and patch oversight across your accounts, each with a recommended fix and each becoming evidence.
Logs nobody reads become alerts that matter.
Agents stream events into one place, and what escalates is what matters to the product you ship, not what scored highest on a generic scale.
Sovereign by design.
Hosted on EU-owned infrastructure with European data residency. The models we run are open source, on our own hardware or served by European providers. Your data is never used to train a model.
The frameworks software companies are asked for.
ISO 27001
The certification enterprise buyers and the public sector ask for before they sign. Controls, statement of applicability and evidence held in the platform.
NIS2
Reaches software companies directly where they are named, and through customer contracts everywhere else. The ten risk measures mapped to the same control set.
GDPR
Applies wherever your platform holds personal data on behalf of your customers. Mapped to the same controls, evidenced once.
Start with the audit.
Fixed scope, priced by company size.
Security Audit
An independent vCISO Security Audit returns a ranked gap list against every framework in scope. The starting roadmap, and the document you show a customer.
Platform
GRC and Security Operations, switched on from day one. Annual contract, monthly billing, priced by employee band.
vCISO
A named security lead where a contract requires one. Scoping, risk decisions, audit-facing guidance, management reporting.