Skip to content
deveca GRC
100% Made in Germany · Hosted in the EU

Security with substance.
GRC, ISMS and risk — finally modern.

deveca brings risk management, ISO 27001, ISO 27701, TISAX, NIS2, BSI IT-Grundschutz, the GDPR and the German Whistleblower Protection Act together on one multi-tenant platform — audit-ready, integrated and without Excel chaos.

Try free for 6 weeks

No contract, no credit card. Afterwards a permanent Free plan with Micro-ISMS.

6 weeks freeNo contractNo credit cardReady in 5 minutes

grc.deveca.app
deveca GRC dashboard – risks, compliance score and incident feed
One place for risks, actions, audits, assets and evidence — tidy, audit-ready, calm.

Frameworks · fully integrated

ISO 27001
ISO 9001
ISO 27701
TISAX
NIS2
BSI IT-Grundschutz
GDPR
EU AI Act
HinSchG
Cyber Resilience Act
DORA
SOC 2
PCI DSS
HIPAA
ISO 27001
ISO 9001
ISO 27701
TISAX
NIS2
BSI IT-Grundschutz
GDPR
EU AI Act
HinSchG
Cyber Resilience Act
DORA
SOC 2
PCI DSS
HIPAA
Why deveca

A platform built for people who actually do GRC.

Six promises we keep in a measurable way — not only on marketing slides.

100% Made in Germany

Built in Germany, hosted in the EU. German data residency — vendor and subprocessor review against documented sovereignty criteria.

Tenant-isolated · security by design

Every tenant gets its own schemas and keys. Encryption at rest and in transit, granular RBAC, complete audit logs.

Framework-independent

TISAX without ISO — or together: modules combine freely. You pay only for what you need.

SharePoint distribution

Push policies into Microsoft 365, collect read acknowledgements and send news to the right audiences.

AI-native GRC

An AI assistant in every workflow: evidence check, crosswalk gaps, RoPA/DPIA drafts and 6 agentic AI agents — not bolted on afterwards.

Whistleblowing, done properly

A complete whistleblowing portal with anonymous communication, a case file, deadline control and action tracking.

Sovereign IT

German data. German servers. German responsibility.

100% Made in Germany, hosted in the EU. German data residency: vendor and subprocessor review against documented sovereignty criteria — transparent for audits and procurement.

  • Hosting in Nuremberg · ISO 27001 certified data centre
  • Backup data centre in Falkenstein · geographically separate
  • German data residency · hosted in the EU
  • Full DPA under Art. 28 GDPR
  • Vendor and subprocessor review against sovereignty criteria
  • TOMs aligned with BSI IT-Grundschutz (technical and organisational)

Sovereignty guarantee

Made in Germany · Hosted in the EU

Primary site
Nuremberg
Backup site
Falkenstein
Data residency
Germany
AI inference
EU-private
Encryption
AES-256 / TLS 1.3
Processing
DPA included

Full security documentation

Security and privacy
Highlights

Four capabilities you will miss everywhere else.

Root-cause analysis people actually use

5-Why, Ishikawa, fault-tree analysis, timeline analysis and configurable methods — inside every incident, not in a separate spreadsheet.

5-WhyIshikawaFault tree (FTA)TimelineCustom methodsLessons learned

ISMS into SharePoint automatically — including news

Publish policies, instructions and news into the right SharePoint libraries in one click. Read acknowledgements, versioning and automatic reminders included.

  1. 1Create and approve the policy in deveca
  2. 2deveca syncs it to SharePoint, including permissions
  3. 3News post to site, department or function
  4. 4Read acknowledgement and reminder requested automatically

HinSchG portal with a real case file

Anonymous whistleblowing portal with a two-way mailbox, encrypted attachments, investigation steps and automatic deadline monitoring (7-day acknowledgement, 3-month feedback).

Go to the HinSchG module

Force-directed graph: what is actually connected?

Aggregates 20+ relationships — assets, risks, controls, suppliers, sites. Filter by protection need or owner and drill into every element. It looks like a map and serves as audit evidence.

Explore the graph
Roadmap

What comes next.

Transparency instead of vapourware. These modules are in active development and roll out as they are ready.

In planning

Atlassian bridge (Jira & Confluence)

Two-way connection to Jira (incidents, actions, CAPA) and Confluence (policy mirroring). Issues, status changes and evidence flow without a media break.

In planning

Vulnerability connectors (Greenbone, OpenVAS, Nessus)

Import scan results from Greenbone / OpenVAS, Tenable Nessus and OWASP Dependency-Check. Automatic CVE/CVSS matching onto assets and controls.

Research

CMDB sync (ServiceNow, i-doit)

Two-way sync with ServiceNow and i-doit: assets, owners and dependencies are imported automatically — deveca adds protection needs and control mapping.

Coming soon

DORA framework

Preconfigured control set for the Digital Operational Resilience Act in the financial sector.

Coming soon

SOC 2 Type II framework

Trust Services Criteria as a native mapping, with crosswalks to ISO 27001.

Coming soon

PCI DSS v4 framework

Payment Card Industry controls for payment service providers and merchants.

Ready for GRC that feels good to use?

Try it free for 6 weeks, then stay on Free with Micro-ISMS. No call, no credit card. Enterprise and a guided rollout still get a live demo.