Atlassian bridge (Jira & Confluence)
Two-way connection to Jira (incidents, actions, CAPA) and Confluence (policy mirroring). Issues, status changes and evidence flow without a media break.
25 integrated modules — from cockpit and risk through GDPR, TPM and the EU AI Act to SBOM, CRA and ISO 9001 QMS. Each module is productive on its own.
Your CISO dashboard in 5 minutes — not 5 weeks of Excel tinkering.
All plans
Explore moduleScope, stakeholders, obligations — in one place, and auditable.
All plans
Explore moduleFrom an Excel risk register to an auditable ISMS.
Starter+
Explore moduleISO 31000 and ISO 27005 on one platform — IT and business risk together.
Starter+
Explore moduleNo action item falls through the cracks.
All plans
Explore moduleAn asset inventory auditors like — with CIA, lifecycle and dependencies.
Starter+
Explore moduleOne control set, every framework — crosswalks cover two audits.
Starter+
Explore modulePolicies people actually read — with a policy centre.
Starter+
Explore moduleExternal auditors see only what they need — securely, and only for a limited time.
Starter+
Explore moduleGDPR built into GRC — with AI for RoPA, DPIA and DPA.
Starter+
Explore moduleFrom incident to notification in hours, not days.
Starter+
Explore moduleA protected reporting portal under the HinSchG — anonymous, encrypted, provable.
Growth+
Explore moduleSpot SLA breaches before the customer does.
Professional+
Explore moduleA compliant supply chain — from assessment to questionnaire.
Growth+
Explore moduleCRA-ready from day one — SBOM import, CVE scan and dependency graph.
Enterprise
Explore moduleCyber Resilience Act — conformity documented, not interpreted.
Enterprise
Explore moduleEU AI Act deployer duties — classification and compliance in one module.
Growth+
Explore moduleISO 9001 and ISO 27001 on one platform — one audit, two certificates.
Add-on
Explore moduleModel processes, don't just describe them — BPMN linked to GRC.
Growth+
Explore moduleVisitors documented, NDA confirmed — ready for ISO 27001 Annex A.7.
Growth+
Explore moduleRequest handling without SharePoint — with workflow and an audit trail.
Starter+
Explore moduleAwareness campaigns with evidence — ISO 27001 clause 7.2 covered.
Starter+
Explore moduleBoard-ready reports in minutes — not days of manual formatting.
Starter+
Explore moduleAll evidence in one place — tenant-isolated, versioned, auditable.
All plans
Explore moduleSee what is connected — risks, assets and controls as a graph.
All plans
Explore moduleTwo-way connection to Jira (incidents, actions, CAPA) and Confluence (policy mirroring). Issues, status changes and evidence flow without a media break.
Import scan results from Greenbone / OpenVAS, Tenable Nessus and OWASP Dependency-Check. Automatic CVE/CVSS matching onto assets and controls.
Two-way sync with ServiceNow and i-doit: assets, owners and dependencies are imported automatically — deveca adds protection needs and control mapping.
Preconfigured control set for the Digital Operational Resilience Act in the financial sector.
Trust Services Criteria as a native mapping, with crosswalks to ISO 27001.
Payment Card Industry controls for payment service providers and merchants.