100% Made in Germany
Built in Germany, hosted in the EU. German data residency — vendor and subprocessor review against documented sovereignty criteria.
deveca brings risk management, ISO 27001, ISO 27701, TISAX, NIS2, BSI IT-Grundschutz, the GDPR and the German Whistleblower Protection Act together on one multi-tenant platform — audit-ready, integrated and without Excel chaos.
Try free for 6 weeks
No contract, no credit card. Afterwards a permanent Free plan with Micro-ISMS.
6 weeks freeNo contractNo credit cardReady in 5 minutes

Frameworks · fully integrated
Six promises we keep in a measurable way — not only on marketing slides.
Built in Germany, hosted in the EU. German data residency — vendor and subprocessor review against documented sovereignty criteria.
Every tenant gets its own schemas and keys. Encryption at rest and in transit, granular RBAC, complete audit logs.
TISAX without ISO — or together: modules combine freely. You pay only for what you need.
Push policies into Microsoft 365, collect read acknowledgements and send news to the right audiences.
An AI assistant in every workflow: evidence check, crosswalk gaps, RoPA/DPIA drafts and 6 agentic AI agents — not bolted on afterwards.
A complete whistleblowing portal with anonymous communication, a case file, deadline control and action tracking.
From cockpit and risk through GDPR, TPM and the EU AI Act to SBOM and CRA — freely combinable, audit-ready and tenant-isolated.
100% Made in Germany, hosted in the EU. German data residency: vendor and subprocessor review against documented sovereignty criteria — transparent for audits and procurement.
Sovereignty guarantee
Made in Germany · Hosted in the EU
Full security documentation
Security and privacy5-Why, Ishikawa, fault-tree analysis, timeline analysis and configurable methods — inside every incident, not in a separate spreadsheet.
Publish policies, instructions and news into the right SharePoint libraries in one click. Read acknowledgements, versioning and automatic reminders included.
Anonymous whistleblowing portal with a two-way mailbox, encrypted attachments, investigation steps and automatic deadline monitoring (7-day acknowledgement, 3-month feedback).
Go to the HinSchG moduleAggregates 20+ relationships — assets, risks, controls, suppliers, sites. Filter by protection need or owner and drill into every element. It looks like a map and serves as audit evidence.
Explore the graphTransparency instead of vapourware. These modules are in active development and roll out as they are ready.
Two-way connection to Jira (incidents, actions, CAPA) and Confluence (policy mirroring). Issues, status changes and evidence flow without a media break.
Import scan results from Greenbone / OpenVAS, Tenable Nessus and OWASP Dependency-Check. Automatic CVE/CVSS matching onto assets and controls.
Two-way sync with ServiceNow and i-doit: assets, owners and dependencies are imported automatically — deveca adds protection needs and control mapping.
Preconfigured control set for the Digital Operational Resilience Act in the financial sector.
Trust Services Criteria as a native mapping, with crosswalks to ISO 27001.
Payment Card Industry controls for payment service providers and merchants.
Try it free for 6 weeks, then stay on Free with Micro-ISMS. No call, no credit card. Enterprise and a guided rollout still get a live demo.