About
About CISAPP: who publishes the platform
CISAPP is a European third-party risk and compliance platform. Who publishes it, on what expertise, with which hosting and security commitments.
TL;DR
CISAPP is published in France and hosted in the European Union. The platform covers third-party risk management (TPRM) and NIS2, DORA, ISO 27001 and GDPR compliance in a single system of record. Content on this site is written by CISAPP's product and compliance team from the official texts cited as sources on each page.
Who publishes CISAPP?
CISAPP is published by a French company. The team combines cybersecurity, compliance and software engineering backgrounds, from contexts where third-party risk is a daily operational constraint: ISO 27001 audits, GDPR remediation programmes, incident response, and answering security questionnaires on both the vendor and the buyer side.
What expertise is the content based on?
Every regulatory page is built from the official text — regulations and directives published in the Official Journal of the European Union, guidance from national authorities (ANSSI, CNIL) and European ones (ENISA, financial supervisory authorities), and ISO standards. Sources are cited with their publisher and date at the bottom of each page. We publish no market figure without a link to its issuer, and we date every update.
Where is the data hosted?
CISAPP's infrastructure is hosted in the European Union. Your vendor data, assessments and compliance evidence do not leave the European area as part of the service. This is a structural choice: third-party risk data documents your critical dependencies precisely, which makes it sensitive by nature.
What are the security commitments?
Encryption in transit and at rest, strict data separation per organisation, access logging, role and permission management per module, and a published security.txt file for reporting a vulnerability. Our own supply chain is managed inside CISAPP, under the same requirements we provide tooling for.
FAQ
CISAPP's product and compliance team, working from the official texts. Every page states its last review date and lists the sources used, with their publisher.
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours