Inside the app

See exactly where you stand

High level views power the daily workflow: mapped citations across every framework, live posture metrics per domain, a guided project plan, a Policy Templates downloads centre with 238 policy and templates, and a controls library mapping every obligation to evidence. Audit, Risk, Asset, Exception, Supplier and Issue management all available out of the box and connected dynamically to your Framework obligations.

01

Mapped Citations

One list across NIST SP 800-53, NIST CSF 2.0, ISO/IEC 27001, GDPR, NIS2, WCAG 2.2 and the EU AI Act. Filter by framework, status or domain — 238 documents, mandatory vs desirable, fully searchable.

Mapped citations across every framework
02

Compliance metrics

Real-time posture per domain and per framework: Governance, Risk, Asset Management, Access Control, Incident Response and more. Non-compliant items surface immediately so remediation is targeted, not guessed.

Executive dashboard with risk posture, workflow trail and project completion
03

Guided project plan

A PMP-aligned ISMS implementation plan that takes a complete novice to a fully operational ISMS, ready for external audit. 73 tasks across 7 phases, with framework filters and live progress tracking.

Guided PMP-aligned project plan with Initiation and Planning phases
04

Document templates

238 policy, procedure and register templates ready to download — every one mapped to the underlying ISO, NIST, GDPR, NIS2, WCAG and EU AI Act controls so auditors can trace evidence in seconds.

Policy templates organised by domain
05

Controls library

202 controls mapped to 33 control objectives with 324 preloaded and connected control tests out of the box. Each control links to its policies, evidence, owner, test method and residual risk — one source of truth for audit.

Controls register grouped by objective
Pre-baked control tests with framework, method, frequency and rating
More inside

Everything you'll need to run an Information Security Management System and more

A glance at the operational surfaces that sit behind the five core views — every register, every feed and every report rendered exactly as your team will see it.

Risk register

Risk register

Inherent vs residual scoring, treatments and ownership.

Issues & CAPA hub

Issues & CAPA hub

Unified queue for findings, non-conformities and corrective actions.

Exceptions register

Exceptions register

Approved deviations with mandatory expiry and compensating control.

Registers

Registers

Live registers — owned, on cadence and linked to controls, tests and evidence.

Watchers

Watchers

Curated regulatory, vulnerability, threat and AppSec feeds in one place.

Departments, roles, people & locations

Departments, roles, people & locations

Named individuals mapped to departments, role levels and responsibilities.

Audit-readiness reports

Audit-readiness reports

Branded PDF assurance reports per framework, ready to download.

Generate report

Generate report

Pick sections and registers — filename and scope previewed before export.

Assurance report sample

Assurance report sample

Executive summary, dashboard, operating chain and obligations — auditor-ready.

Sample templates

See what's inside a template

Every template ships fully drafted — purpose, scope, architecture, requirements, references and framework mappings — not a blank shell. Watermarked samples below show the level of detail you get in every .docx.

DNS Security Procedure
POL-NET-007

DNS Security Procedure

Covers internal DNS architecture, DNSSEC, DNS-over-TLS and DNS-over-HTTPS controls. Mapped to ISO/IEC 27001:2022 A.8.20, NIST SP 800-53 SC-20/21/22, and the relevant RFCs.

Remote Access Policy
POL-AC-007

Remote Access Policy

Zero Trust Network Access architecture, legacy VPN controls, device requirements, MFA and third-party access. Mapped to ISO 27001 A.6.7, NIST SP 800-207, NIST CSF 2.0 PR.AA-05 and NIS2 Art. 21(2)(j).

Samples shown are watermarked previews. Unlocked templates are delivered as fully editable .docx files.

Templates

Templates that unlock quickly when you license a domain

Information Security Policy
ISO 27001 A.5 · NIST PR.AT
.docx
Statement of Applicability (SoA)
ISO 27001 6.1.3
.docx
Record of Processing Activities
GDPR Art. 30
.docx
Data Protection Impact Assessment
GDPR Art. 35
.docx
AI System Risk & Conformity Assessment
EU AI Act Art. 9 / Annex IV
.docx
Incident Response Plan & Runbooks
NIST IR · NIS2 Art. 21
.docx
Business Continuity & DR Plan
ISO 22301 · NIST CP
.docx
Access Control & Joiner/Mover/Leaver
ISO A.5.15 · NIST AC
.docx
Supplier & Third-Party Risk Register
ISO A.5.19 · NIS2 Art. 21(2)(d)
.docx
WCAG 2.2 Accessibility Conformance
EN 301 549 · WCAG 2.2 AA
.docx
Required registers

Maintain the registers auditors expect to see

Risk Register
ISO 27001 A.5.12 · NIST RM-1 · NIS2 Art. 21
.docx
Asset Register
ISO 27001 A.5.9 · NIST ID.AM
.docx
Control Register
ISO 27001 Annex A · NIST SP 800-53
.docx
Incident Register
NIS2 Art. 23 · GDPR Art. 33 · NIST IR-4
.docx
Data Processing Register
GDPR Art. 30 · EU AI Act Art. 53
.docx
Supplier & Third-Party Register
ISO 27001 A.5.19 · NIS2 Art. 21(2)(d)
.docx
AI System Register
EU AI Act Art. 53 · ISO 42001
.docx
Accessibility Conformance Register
WCAG 2.2 · EN 301 549
.docx
Evidence register

One place for every artefact

Centralised evidence store
Every control, policy and register linked to supporting evidence. Screenshots, config exports, training records and penetration-test reports are linked and indexed by framework, owner and due date.
Audit trail
Control version history and reviewer sign-off are captured automatically. When an auditor asks 'show me the evidence for control A.5.1', you open one view, not ten folders.
Gap-to-evidence mapping
The app flags which controls still lack evidence and who is responsible. No more last-minute hunts before an assessment.
Export bundles
Generate an export evidence pack scoped to a single framework, a project phase, or an entire domain. Ready for external auditors, clients or regulators.
How it works

From install to audit-ready, in four steps

01
Log in and start
Pick the frameworks in scope. Start building out your specific registers using preloaded details.
02
Scope & baseline
Pick the frameworks in scope. The app generates a tailored project plan.
03
Work the plan
Download, edit and save policies. Implement controls and track evidence readiness — all tracked inside the app.
04
Report & defend
Export your progress and data, create an audit-ready evidence bundle on demand.
Licensing model

Three ways to license — Templates, App, or both with SIEM

Pick one or stack them. Every box below can be enabled immediately from your account after sign-up — no sales calls, no consultancy gating.

Templates only
€199per domain

Buy individual policy template domains or the full 238-template bundle. Download as .docx, mapped to ISO, NIST, GDPR, NIS2, WCAG and the EU AI Act. No platform subscription required.

App only
€49per user / month

Full platform access — mapped citations, posture dashboard, project plan, registers, audits and reports. One Business Unit included; add more on demand. Card-required 14-day free trial.

SIEM add-on
€49per month

Stream the immutable audit log to Splunk, Datadog, Elastic or any HTTPS SIEM in near real-time. Stacks on top of any App subscription.