GRC platform · Third-party risk · Compliance

Take control of third-party risk, end to end

Vendor register, assessments, dependency mapping, NIS2/DORA/GDPR compliance and a public Trust Center — in a single European platform.

Try it free
  • Free vendor portal
  • Hosted in the European Union
  • Aligned with ISO 27001 / EBIOS RM

How many third parties can reach your data today?

The exact number isn't in any file. Procurement keeps one list, IT keeps another, business units sign on their own. None is complete — and none tells you what stops when one of them goes down.

  • Moving perimeter

    A SaaS tool bought on a company card, a contractor added mid-project, a contract never terminated: the perimeter moves faster than the file.

  • Invisible dependencies

    Which vendor is your single point of failure? Which fourth parties touch your data?

  • Due diligence eats time

    Questionnaires on repeat, manual chasing, answers lost in inboxes. No traceability.

  • Regulatory pressure

    NIS2 supply chain, DORA ICT, GDPR processors: each framework ends up in a different file.

CISAPP connects all of it into one continuous chain — from the first vendor you onboard to the evidence you hand an auditor.

For enterprises

Master your cyber supply chain

From vendor qualification to proof of compliance, it's all in CISAPP.

For vendors

Respond faster, show your posture

CISAPP becomes your security dashboard for your clients.

AI

AI speeds up data entry. It doesn't decide for you.

Four concrete uses, all reviewable by a human before anything is validated.

  • Excel questionnaire import

    A messy client file becomes a structured questionnaire, reviewed before import.

  • Answer pre-fill

    Answers already given to other clients are suggested, never sent automatically.

  • Document search

    Query your policies and evidence in plain language, with the source cited.

  • Drafting help

    A first draft of a policy or a measure, for you to edit and approve.

No risk, score or compliance decision is made by a model. AI processing can be switched off at organisation level.

Frequently asked questions

The objections we hear most, answered directly.

In the European Union. Hosting and subprocessor details are published on our Trust Center and in our public subprocessor register.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account