Skip to content
deveca GRC
Modules · platform overview

One platform. Everything included.

25 integrated modules — from cockpit and risk through GDPR, TPM and the EU AI Act to SBOM, CRA and ISO 9001 QMS. Each module is productive on its own.

Available now

Ready today

Available now

Cockpit & overview

Your CISO dashboard in 5 minutes — not 5 weeks of Excel tinkering.

All plans

Explore module
Available now

Organisation & scope

Scope, stakeholders, obligations — in one place, and auditable.

All plans

Explore module
Available now

IT risk management (ISO 27005)

From an Excel risk register to an auditable ISMS.

Starter+

Explore module
Available now

Enterprise risk management (ISO 31000)

ISO 31000 and ISO 27005 on one platform — IT and business risk together.

Starter+

Explore module
Available now

Action management

No action item falls through the cracks.

All plans

Explore module
Available now

Asset management

An asset inventory auditors like — with CIA, lifecycle and dependencies.

Starter+

Explore module
Available now

Control framework & compliance

One control set, every framework — crosswalks cover two audits.

Starter+

Explore module
Available now

Policy management

Policies people actually read — with a policy centre.

Starter+

Explore module
Available now

Audit programme

External auditors see only what they need — securely, and only for a limited time.

Starter+

Explore module
Available now

GDPR / privacy

GDPR built into GRC — with AI for RoPA, DPIA and DPA.

Starter+

Explore module
Available now

Incident management & BCM

From incident to notification in hours, not days.

Starter+

Explore module
Available now

Whistleblower protection (HinSchG)

A protected reporting portal under the HinSchG — anonymous, encrypted, provable.

Growth+

Explore module
Available now

SLA / OLA management

Spot SLA breaches before the customer does.

Professional+

Explore module
Available now

Third-party management (TPM)

A compliant supply chain — from assessment to questionnaire.

Growth+

Explore module
Available now

SBOM & vulnerability management

CRA-ready from day one — SBOM import, CVE scan and dependency graph.

Enterprise

Explore module
Available now

CRA / CE conformity

Cyber Resilience Act — conformity documented, not interpreted.

Enterprise

Explore module
Available now

EU AI Act (deployer)

EU AI Act deployer duties — classification and compliance in one module.

Growth+

Explore module
Available now

ISO 9001 / QMS

ISO 9001 and ISO 27001 on one platform — one audit, two certificates.

Add-on

Explore module
Available now

Process management

Model processes, don't just describe them — BPMN linked to GRC.

Growth+

Explore module
Available now

Visitor management

Visitors documented, NDA confirmed — ready for ISO 27001 Annex A.7.

Growth+

Explore module
Available now

Forms & requests

Request handling without SharePoint — with workflow and an audit trail.

Starter+

Explore module
Available now

Training & awareness

Awareness campaigns with evidence — ISO 27001 clause 7.2 covered.

Starter+

Explore module
Available now

Reports & export

Board-ready reports in minutes — not days of manual formatting.

Starter+

Explore module
Available now

File management

All evidence in one place — tenant-isolated, versioned, auditable.

All plans

Explore module
Available now

Dependency visualisation

See what is connected — risks, assets and controls as a graph.

All plans

Explore module
In development

Roadmap

In planning

Atlassian bridge (Jira & Confluence)

Two-way connection to Jira (incidents, actions, CAPA) and Confluence (policy mirroring). Issues, status changes and evidence flow without a media break.

In planning

Vulnerability connectors (Greenbone, OpenVAS, Nessus)

Import scan results from Greenbone / OpenVAS, Tenable Nessus and OWASP Dependency-Check. Automatic CVE/CVSS matching onto assets and controls.

Research

CMDB sync (ServiceNow, i-doit)

Two-way sync with ServiceNow and i-doit: assets, owners and dependencies are imported automatically — deveca adds protection needs and control mapping.

Coming soon

DORA framework

Preconfigured control set for the Digital Operational Resilience Act in the financial sector.

Coming soon

SOC 2 Type II framework

Trust Services Criteria as a native mapping, with crosswalks to ISO 27001.

Coming soon

PCI DSS v4 framework

Payment Card Industry controls for payment service providers and merchants.