GRC platform · Third-party risk · Compliance
Take control of third-party risk, end to end
Vendor register, assessments, dependency mapping, NIS2/DORA/GDPR compliance and a public Trust Center — in a single European platform.
- Free vendor portal
- Hosted in the European Union
- Aligned with ISO 27001 / EBIOS RM
How many third parties can reach your data today?
The exact number isn't in any file. Procurement keeps one list, IT keeps another, business units sign on their own. None is complete — and none tells you what stops when one of them goes down.
Moving perimeter
A SaaS tool bought on a company card, a contractor added mid-project, a contract never terminated: the perimeter moves faster than the file.
Invisible dependencies
Which vendor is your single point of failure? Which fourth parties touch your data?
Due diligence eats time
Questionnaires on repeat, manual chasing, answers lost in inboxes. No traceability.
Regulatory pressure
NIS2 supply chain, DORA ICT, GDPR processors: each framework ends up in a different file.
CISAPP connects all of it into one continuous chain — from the first vendor you onboard to the evidence you hand an auditor.
For enterprises
Master your cyber supply chain
From vendor qualification to proof of compliance, it's all in CISAPP.
For vendors
Respond faster, show your posture
CISAPP becomes your security dashboard for your clients.
AI
AI speeds up data entry. It doesn't decide for you.
Four concrete uses, all reviewable by a human before anything is validated.
Excel questionnaire import
A messy client file becomes a structured questionnaire, reviewed before import.
Answer pre-fill
Answers already given to other clients are suggested, never sent automatically.
Document search
Query your policies and evidence in plain language, with the source cited.
Drafting help
A first draft of a policy or a measure, for you to edit and approve.
No risk, score or compliance decision is made by a model. AI processing can be switched off at organisation level.
Frequently asked questions
The objections we hear most, answered directly.
In the European Union. Hosting and subprocessor details are published on our Trust Center and in our public subprocessor register.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours