[{"data":1,"prerenderedAt":2643},["ShallowReactive",2],{"roadmap-en":3,"section-links-solutions-en":2543,"section-links-reglementation-en":2576,"section-links-guides-en":2605,"section-links-comparatifs-en":2630},[4,33,111,173,192,211,266,285,304,367,386,446,513,563,627,686,751,816,877,896,914,933,993,1012,1031,1050,1110,1129,1190,1208,1227,1293,1312,1331,1397,1457,1475,1493,1512,1531,1550,1604,1664,1682,1748,1767,1833,1893,1954,2014,2074,2093,2155,2219,2278,2338,2356,2374,2440,2459,2525],{"id":5,"title":6,"body":7,"connectors":14,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":18,"navigation":19,"path":20,"period":17,"persona":21,"rawbody":22,"regulations":23,"relatedPages":24,"seo":25,"shippedAt":26,"slug":27,"status":28,"stem":29,"summary":30,"theme":31,"updatedAt":17,"__hash__":32},"roadmap_en\u002Fen\u002Froadmap\u002Fabonnement-et-paiement.md","Subscription, usage and card payment",{"type":8,"value":9,"toc":10},"minimark",[],{"title":11,"searchDepth":12,"depth":12,"links":13},"",2,[],[],"md",false,null,{},true,"\u002Fen\u002Froadmap\u002Fabonnement-et-paiement","both","---\nslug: abonnement-et-paiement\ntitle: Subscription, usage and card payment\nsummary: See your subscription and usage, pay by card and discover which features your plan includes.\nstatus: shipped\nshippedAt: '2026-05-23'\ntheme: plateforme\n---\n",[],[],{"title":6,"description":11},"2026-05-23","abonnement-et-paiement","shipped","en\u002Froadmap\u002Fabonnement-et-paiement","See your subscription and usage, pay by card and discover which features your plan includes.","plateforme","lWBrabJB8dSxx6MUkhKRM_5SyHYCZB8pga6gBaTGRWs",{"id":34,"title":35,"body":36,"connectors":93,"description":11,"extension":15,"featured":16,"illustration":94,"media":17,"meta":95,"navigation":19,"path":96,"period":97,"persona":21,"rawbody":98,"regulations":99,"relatedPages":103,"seo":104,"shippedAt":17,"slug":105,"status":106,"stem":107,"summary":108,"theme":109,"updatedAt":17,"__hash__":110},"roadmap_en\u002Fen\u002Froadmap\u002Fanalyse-ecart-referentiels.md","Multi-framework gap analysis",{"type":8,"value":37,"toc":87},[38,43,47,51,80,84],[39,40,42],"h3",{"id":41},"the-problem","The problem",[44,45,46],"p",{},"You're ISO 27001 certified, and now you're asked for NIS2, then DORA. Starting from scratch each time makes no sense: much of the work is already done.",[39,48,50],{"id":49},"what-changes","What changes",[52,53,54,62,68,74],"ul",{},[55,56,57,61],"li",{},[58,59,60],"strong",{},"Credit for what you already have",": your existing measures are matched against the new framework's requirements.",[55,63,64,67],{},[58,65,66],{},"What's missing, spelled out",": the list of gaps, requirement by requirement.",[55,69,70,73],{},[58,71,72],{},"A prioritised plan",": actions ranked by impact and effort.",[55,75,76,79],{},[58,77,78],{},"A report for management",": where you stand, and what's left to do.",[39,81,83],{"id":82},"who-its-for","Who it's for",[44,85,86],{},"CISOs and compliance leads who answer to several frameworks.",{"title":11,"searchDepth":12,"depth":12,"links":88},[89,91,92],{"id":41,"depth":90,"text":42},3,{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"gap",{},"\u002Fen\u002Froadmap\u002Fanalyse-ecart-referentiels","2027-Q2","---\nslug: analyse-ecart-referentiels\ntitle: \"Multi-framework gap analysis\"\nsummary: \"Measure your gap per framework, see what your ISO 27001 certification already covers for NIS2 or DORA, and get a prioritised remediation plan.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: conformite\nregulations: [nis2, dora, iso-27001]\nillustration: gap\n---\n\n### The problem\n\nYou're ISO 27001 certified, and now you're asked for NIS2, then DORA. Starting from scratch each time makes no sense: much of the work is already done.\n\n### What changes\n\n- **Credit for what you already have**: your existing measures are matched against the new framework's requirements.\n- **What's missing, spelled out**: the list of gaps, requirement by requirement.\n- **A prioritised plan**: actions ranked by impact and effort.\n- **A report for management**: where you stand, and what's left to do.\n\n### Who it's for\n\nCISOs and compliance leads who answer to several frameworks.\n",[100,101,102],"nis2","dora","iso-27001",[],{"title":35,"description":11},"analyse-ecart-referentiels","planned","en\u002Froadmap\u002Fanalyse-ecart-referentiels","Measure your gap per framework, see what your ISO 27001 certification already covers for NIS2 or DORA, and get a prioritised remediation plan.","conformite","9Ivfpe5dO9Cbel88PTovTSBz9xNINcF2DJuFWRXwqlA",{"id":112,"title":113,"body":114,"connectors":159,"description":11,"extension":15,"featured":16,"illustration":160,"media":17,"meta":161,"navigation":19,"path":162,"period":163,"persona":21,"rawbody":164,"regulations":165,"relatedPages":166,"seo":168,"shippedAt":17,"slug":160,"status":106,"stem":169,"summary":170,"theme":171,"updatedAt":17,"__hash__":172},"roadmap_en\u002Fen\u002Froadmap\u002Fapplications.md","Application inventory",{"type":8,"value":115,"toc":154},[116,118,121,123,149,151],[39,117,42],{"id":41},[44,119,120],{},"A vendor is more than a single line: the same publisher may provide your payroll tool and your CRM, with very different uses and risks. Thinking only at vendor level hides what matters.",[39,122,50],{"id":49},[52,124,125,131,137,143],{},[55,126,127,130],{},[58,128,129],{},"An inventory of the applications you use",": which service, used by which team, for which activity.",[55,132,133,136],{},[58,134,135],{},"Criticality at the right level",": each application inherits the importance of the activities it supports.",[55,138,139,142],{},[58,140,141],{},"Targeted assessments",": assess one specific application rather than the whole vendor.",[55,144,145,148],{},[58,146,147],{},"A more accurate map",": your organisation, your activities, the applications and the vendors behind them.",[39,150,83],{"id":82},[44,152,153],{},"CISOs, CIOs and third-party risk owners who want to know exactly what depends on what.",{"title":11,"searchDepth":12,"depth":12,"links":155},[156,157,158],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"applications",{},"\u002Fen\u002Froadmap\u002Fapplications","2027-Q1","---\nslug: applications\ntitle: \"Application inventory\"\nsummary: \"Tell apart the applications of a single vendor, the activities that rely on them, their owning teams and the data they process, so each can be assessed and tracked separately.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: cartographie\nillustration: applications\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### The problem\n\nA vendor is more than a single line: the same publisher may provide your payroll tool and your CRM, with very different uses and risks. Thinking only at vendor level hides what matters.\n\n### What changes\n\n- **An inventory of the applications you use**: which service, used by which team, for which activity.\n- **Criticality at the right level**: each application inherits the importance of the activities it supports.\n- **Targeted assessments**: assess one specific application rather than the whole vendor.\n- **A more accurate map**: your organisation, your activities, the applications and the vendors behind them.\n\n### Who it's for\n\nCISOs, CIOs and third-party risk owners who want to know exactly what depends on what.\n",[],[167],"cybersecurite-supply-chain",{"title":113,"description":11},"en\u002Froadmap\u002Fapplications","Tell apart the applications of a single vendor, the activities that rely on them, their owning teams and the data they process, so each can be assessed and tracked separately.","cartographie","vNdJeh6U86YlUTp-aJ0HsKuLuwoz5XOVoyfNH6qtsqQ",{"id":174,"title":175,"body":176,"connectors":180,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":181,"navigation":19,"path":182,"period":17,"persona":21,"rawbody":183,"regulations":184,"relatedPages":185,"seo":186,"shippedAt":187,"slug":188,"status":28,"stem":189,"summary":190,"theme":31,"updatedAt":17,"__hash__":191},"roadmap_en\u002Fen\u002Froadmap\u002Fassistance-integree.md","Built-in support",{"type":8,"value":177,"toc":178},[],{"title":11,"searchDepth":12,"depth":12,"links":179},[],[],{},"\u002Fen\u002Froadmap\u002Fassistance-integree","---\nslug: assistance-integree\ntitle: Built-in support\nsummary: 'Reach support from inside the platform: your context is passed along, nothing to re-explain.'\nstatus: shipped\nshippedAt: '2026-05-16'\ntheme: plateforme\n---\n",[],[],{"title":175,"description":11},"2026-05-16","assistance-integree","en\u002Froadmap\u002Fassistance-integree","Reach support from inside the platform: your context is passed along, nothing to re-explain.","NrNswRdU5YKInT6vkP39s7Nd2cFJg457RgjkgkUXPG8",{"id":193,"title":194,"body":195,"connectors":199,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":200,"navigation":19,"path":201,"period":17,"persona":21,"rawbody":202,"regulations":203,"relatedPages":204,"seo":205,"shippedAt":206,"slug":207,"status":28,"stem":208,"summary":209,"theme":171,"updatedAt":17,"__hash__":210},"roadmap_en\u002Fen\u002Froadmap\u002Fcarte-risque-fournisseurs.md","Vendor risk map",{"type":8,"value":196,"toc":197},[],{"title":11,"searchDepth":12,"depth":12,"links":198},[],[],{},"\u002Fen\u002Froadmap\u002Fcarte-risque-fournisseurs","---\nslug: carte-risque-fournisseurs\ntitle: Vendor risk map\nsummary: See your vendors by criticality on a radar and read key statistics at a glance.\nstatus: shipped\nshippedAt: '2026-03-20'\ntheme: cartographie\n---\n",[],[],{"title":194,"description":11},"2026-03-20","carte-risque-fournisseurs","en\u002Froadmap\u002Fcarte-risque-fournisseurs","See your vendors by criticality on a radar and read key statistics at a glance.","GcVOw7hiMLfXOXuak0pBRRqWCWWARLEA3pOmKNr9DU8",{"id":212,"title":213,"body":214,"connectors":253,"description":11,"extension":15,"featured":19,"illustration":254,"media":17,"meta":255,"navigation":19,"path":256,"period":17,"persona":21,"rawbody":257,"regulations":258,"relatedPages":259,"seo":260,"shippedAt":261,"slug":262,"status":28,"stem":263,"summary":264,"theme":171,"updatedAt":17,"__hash__":265},"roadmap_en\u002Fen\u002Froadmap\u002Fcartographie-dependances.md","Dependency and exposure mapping",{"type":8,"value":215,"toc":248},[216,218,221,223,243,245],[39,217,42],{"id":41},[44,219,220],{},"A vendor registry is a list. Risk is a network: a tier-2 subcontractor shared by three critical providers is a single point of failure no spreadsheet will show.",[39,222,50],{"id":49},[52,224,225,231,237],{},[55,226,227,230],{},[58,228,229],{},"Multi-tier map",": vendors, nth-party subcontractors and assets on a single view.",[55,232,233,236],{},[58,234,235],{},"Concentration view",": shared dependencies stand out immediately.",[55,238,239,242],{},[58,240,241],{},"Controlled sharing",": a vendor can expose its own chain with cascading visibility.",[39,244,83],{"id":82},[44,246,247],{},"CISOs and procurement teams who must back a concentration analysis (DORA, art. 28-29) or map their supply chain (NIS2, art. 21).",{"title":11,"searchDepth":12,"depth":12,"links":249},[250,251,252],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"dependencies",{},"\u002Fen\u002Froadmap\u002Fcartographie-dependances","---\nslug: cartographie-dependances\ntitle: Dependency and exposure mapping\nsummary: An interactive map links your vendors, their subcontractors and your assets across several tiers, and a concentration view shows where risk piles up in your supply chain.\nstatus: shipped\nshippedAt: '2026-07-01'\ntheme: cartographie\nillustration: dependencies\nregulations: [nis2, dora]\nfeatured: true\nrelatedPages: [cybersecurite-supply-chain, dora]\n---\n\n### The problem\n\nA vendor registry is a list. Risk is a network: a tier-2 subcontractor shared by three critical providers is a single point of failure no spreadsheet will show.\n\n### What changes\n\n- **Multi-tier map**: vendors, nth-party subcontractors and assets on a single view.\n- **Concentration view**: shared dependencies stand out immediately.\n- **Controlled sharing**: a vendor can expose its own chain with cascading visibility.\n\n### Who it's for\n\nCISOs and procurement teams who must back a concentration analysis (DORA, art. 28-29) or map their supply chain (NIS2, art. 21).\n",[100,101],[167,101],{"title":213,"description":11},"2026-07-01","cartographie-dependances","en\u002Froadmap\u002Fcartographie-dependances","An interactive map links your vendors, their subcontractors and your assets across several tiers, and a concentration view shows where risk piles up in your supply chain.","kJ0bW6kIhsjE-7UFxYjt_EyEE9s9bfE7q5SLVsgzrss",{"id":267,"title":268,"body":269,"connectors":273,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":274,"navigation":19,"path":275,"period":17,"persona":21,"rawbody":276,"regulations":277,"relatedPages":278,"seo":279,"shippedAt":17,"slug":280,"status":281,"stem":282,"summary":283,"theme":171,"updatedAt":17,"__hash__":284},"roadmap_en\u002Fen\u002Froadmap\u002Fcartographie-fournisseurs-organisation.md","Vendor mapping at scale",{"type":8,"value":270,"toc":271},[],{"title":11,"searchDepth":12,"depth":12,"links":272},[],[],{},"\u002Fen\u002Froadmap\u002Fcartographie-fournisseurs-organisation","---\nslug: cartographie-fournisseurs-organisation\ntitle: Vendor mapping at scale\nsummary: A smooth map of all your vendor relationships, built for hundreds of third parties, with filters by criticality and tier.\nstatus: in_progress\ntheme: cartographie\nregulations: [dora]\n---\n",[101],[],{"title":268,"description":11},"cartographie-fournisseurs-organisation","in_progress","en\u002Froadmap\u002Fcartographie-fournisseurs-organisation","A smooth map of all your vendor relationships, built for hundreds of third parties, with filters by criticality and tier.","U1Yqz2oWfF1ouJneWOpJoyFvNAV6AjasvvAp_2DnxFA",{"id":286,"title":287,"body":288,"connectors":292,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":293,"navigation":19,"path":294,"period":17,"persona":21,"rawbody":295,"regulations":296,"relatedPages":297,"seo":298,"shippedAt":299,"slug":300,"status":28,"stem":301,"summary":302,"theme":31,"updatedAt":17,"__hash__":303},"roadmap_en\u002Fen\u002Froadmap\u002Fcatalogue-technologies.md","Technology catalog",{"type":8,"value":289,"toc":290},[],{"title":11,"searchDepth":12,"depth":12,"links":291},[],[],{},"\u002Fen\u002Froadmap\u002Fcatalogue-technologies","---\nslug: catalogue-technologies\ntitle: Technology catalog\nsummary: Select the technologies in use from a shared list instead of typing them by hand.\nstatus: shipped\nshippedAt: '2026-06-30'\ntheme: plateforme\n---\n",[],[],{"title":287,"description":11},"2026-06-30","catalogue-technologies","en\u002Froadmap\u002Fcatalogue-technologies","Select the technologies in use from a shared list instead of typing them by hand.","5fY9JSqFKY-IjZPA4whdNacG0kg80tuyTWgD9YabsGk",{"id":305,"title":306,"body":307,"connectors":352,"description":11,"extension":15,"featured":16,"illustration":353,"media":17,"meta":354,"navigation":19,"path":355,"period":17,"persona":21,"rawbody":356,"regulations":357,"relatedPages":358,"seo":360,"shippedAt":17,"slug":361,"status":362,"stem":363,"summary":364,"theme":365,"updatedAt":17,"__hash__":366},"roadmap_en\u002Fen\u002Froadmap\u002Fclauses-contractuelles.md","Recommended contract clauses",{"type":8,"value":308,"toc":347},[309,311,314,316,342,344],[39,310,42],{"id":41},[44,312,313],{},"An assessment reveals a weakness at a vendor. Then what? Too often, the finding stays in the report and never makes it into the contract.",[39,315,50],{"id":49},[52,317,318,324,330,336],{},[55,319,320,323],{},[58,321,322],{},"The right clause at the right time",": a weak answer triggers a recommendation for a suitable clause.",[55,325,326,329],{},[58,327,328],{},"Every clause justified",": the answer that prompted it stays visible.",[55,331,332,335],{},[58,333,334],{},"A ready-to-use library",": subcontracting, data location, incident notification, audit, reversibility, use of AI…",[55,337,338,341],{},[58,339,340],{},"All the way to signature",": exportable clauses, tracked through contracting.",[39,343,83],{"id":82},[44,345,346],{},"Procurement, legal and CISOs negotiating with vendors.",{"title":11,"searchDepth":12,"depth":12,"links":348},[349,350,351],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"clauses",{},"\u002Fen\u002Froadmap\u002Fclauses-contractuelles","---\nslug: clauses-contractuelles\ntitle: \"Recommended contract clauses\"\nsummary: \"Based on a vendor's answers, CISAPP suggests suitable clauses, backed by the original answer and exportable for negotiation.\"\nstatus: exploring\ntheme: evaluations\nregulations: [dora, nis2]\nillustration: clauses\nrelatedPages: [gestion-risque-fournisseur]\n---\n\n### The problem\n\nAn assessment reveals a weakness at a vendor. Then what? Too often, the finding stays in the report and never makes it into the contract.\n\n### What changes\n\n- **The right clause at the right time**: a weak answer triggers a recommendation for a suitable clause.\n- **Every clause justified**: the answer that prompted it stays visible.\n- **A ready-to-use library**: subcontracting, data location, incident notification, audit, reversibility, use of AI…\n- **All the way to signature**: exportable clauses, tracked through contracting.\n\n### Who it's for\n\nProcurement, legal and CISOs negotiating with vendors.\n",[101,100],[359],"gestion-risque-fournisseur",{"title":306,"description":11},"clauses-contractuelles","exploring","en\u002Froadmap\u002Fclauses-contractuelles","Based on a vendor's answers, CISAPP suggests suitable clauses, backed by the original answer and exportable for negotiation.","evaluations","S5GarK4eBTW-Ew12UdzeaXd1dD-m5_wUFEP04-qI2eA",{"id":368,"title":369,"body":370,"connectors":374,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":375,"navigation":19,"path":376,"period":17,"persona":21,"rawbody":377,"regulations":378,"relatedPages":380,"seo":381,"shippedAt":17,"slug":382,"status":362,"stem":383,"summary":384,"theme":109,"updatedAt":17,"__hash__":385},"roadmap_en\u002Fen\u002Froadmap\u002Fconformite-ai-act.md","AI Act compliance",{"type":8,"value":371,"toc":372},[],{"title":11,"searchDepth":12,"depth":12,"links":373},[],[],{},"\u002Fen\u002Froadmap\u002Fconformite-ai-act","---\nslug: conformite-ai-act\ntitle: \"AI Act compliance\"\nsummary: \"Register of the AI systems you use, risk classification and tracking of your deployer obligations.\"\nstatus: exploring\ntheme: conformite\nregulations: [ai-act]\nrelatedPages: [ai-act]\n---\n",[379],"ai-act",[379],{"title":369,"description":11},"conformite-ai-act","en\u002Froadmap\u002Fconformite-ai-act","Register of the AI systems you use, risk classification and tracking of your deployer obligations.","NxPEBbvhdqlN_FVWxavcUlQhjU7u0nC137gxkPWlqsU",{"id":387,"title":388,"body":389,"connectors":434,"description":11,"extension":15,"featured":16,"illustration":435,"media":17,"meta":436,"navigation":19,"path":437,"period":97,"persona":21,"rawbody":438,"regulations":439,"relatedPages":440,"seo":441,"shippedAt":17,"slug":442,"status":106,"stem":443,"summary":444,"theme":109,"updatedAt":17,"__hash__":445},"roadmap_en\u002Fen\u002Froadmap\u002Fconformite-cra.md","Cyber Resilience Act compliance",{"type":8,"value":390,"toc":429},[391,393,396,398,424,426],[39,392,42],{"id":41},[44,394,395],{},"The Cyber Resilience Act requires makers of digital products to know what their products are made of, fix their vulnerabilities and report the most serious ones within very short deadlines.",[39,397,50],{"id":49},[52,399,400,406,412,418],{},[55,401,402,405],{},[58,403,404],{},"Your products and their components",": an up-to-date inventory, version by version.",[55,407,408,411],{},[58,409,410],{},"The vulnerabilities that affect you",": spotted and tracked until they're fixed.",[55,413,414,417],{},[58,415,416],{},"Guided reporting",": the 24 h, 72 h and 14-day deadlines tracked for you.",[55,419,420,423],{},[58,421,422],{},"Your disclosure policy published",": straight on your Trust Center.",[39,425,83],{"id":82},[44,427,428],{},"Software publishers and makers of connected products sold in the EU, and their clients who expect guarantees.",{"title":11,"searchDepth":12,"depth":12,"links":430},[431,432,433],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"cra",{},"\u002Fen\u002Froadmap\u002Fconformite-cra","---\nslug: conformite-cra\ntitle: \"Cyber Resilience Act compliance\"\nsummary: \"For vendors of digital products: product inventory, SBOM, vulnerability tracking and reporting within CRA deadlines.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: conformite\nillustration: cra\n---\n\n### The problem\n\nThe Cyber Resilience Act requires makers of digital products to know what their products are made of, fix their vulnerabilities and report the most serious ones within very short deadlines.\n\n### What changes\n\n- **Your products and their components**: an up-to-date inventory, version by version.\n- **The vulnerabilities that affect you**: spotted and tracked until they're fixed.\n- **Guided reporting**: the 24 h, 72 h and 14-day deadlines tracked for you.\n- **Your disclosure policy published**: straight on your Trust Center.\n\n### Who it's for\n\nSoftware publishers and makers of connected products sold in the EU, and their clients who expect guarantees.\n",[],[],{"title":388,"description":11},"conformite-cra","en\u002Froadmap\u002Fconformite-cra","For vendors of digital products: product inventory, SBOM, vulnerability tracking and reporting within CRA deadlines.","xvof8ayKXhpO3rtEUJ7QQrNAt590hJORsvVXxxQlmk4",{"id":447,"title":448,"body":449,"connectors":500,"description":11,"extension":15,"featured":19,"illustration":100,"media":17,"meta":501,"navigation":19,"path":502,"period":503,"persona":21,"rawbody":504,"regulations":505,"relatedPages":506,"seo":508,"shippedAt":17,"slug":509,"status":106,"stem":510,"summary":511,"theme":109,"updatedAt":17,"__hash__":512},"roadmap_en\u002Fen\u002Froadmap\u002Fconformite-nis2.md","NIS2 compliance management",{"type":8,"value":450,"toc":495},[451,453,456,458,490,492],[39,452,42],{"id":41},[44,454,455],{},"NIS2 greatly widens the number of organisations in scope, and many still don't know whether they're concerned, or where to start. Supply chain security is one of the required measures, and often the hardest to demonstrate.",[39,457,50],{"id":49},[52,459,460,466,472,478,484],{},[55,461,462,465],{},[58,463,464],{},"Know whether you're in scope",": a guided path determines whether you're an essential or important entity.",[55,467,468,471],{},[58,469,470],{},"A clear diagnosis",": where you stand on each required security measure, and what's left to do.",[55,473,474,477],{},[58,475,476],{},"A tracked action plan",": every gap becomes an action with an owner and a deadline.",[55,479,480,483],{},[58,481,482],{},"Your vendors already count",": assessments run in CISAPP feed straight into the supply chain requirement.",[55,485,486,489],{},[58,487,488],{},"Ready on incident day",": notification deadlines (24 h, 72 h, 1 month) are tracked for you.",[39,491,83],{"id":82},[44,493,494],{},"Essential and important entities, and the suppliers they ask for guarantees.",{"title":11,"searchDepth":12,"depth":12,"links":496},[497,498,499],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Fconformite-nis2","2026-Q4","---\nslug: conformite-nis2\ntitle: \"NIS2 compliance management\"\nsummary: \"Find out whether NIS2 applies to you, measure your gap against the Article 21 measures, track your action plan and link vendor assessments to the supply chain security requirement.\"\nstatus: planned\nperiod: '2026-Q4'\ntheme: conformite\nregulations: [nis2]\nfeatured: true\nillustration: nis2\nrelatedPages: [conformite-nis2-fournisseurs, nis2]\n---\n\n### The problem\n\nNIS2 greatly widens the number of organisations in scope, and many still don't know whether they're concerned, or where to start. Supply chain security is one of the required measures, and often the hardest to demonstrate.\n\n### What changes\n\n- **Know whether you're in scope**: a guided path determines whether you're an essential or important entity.\n- **A clear diagnosis**: where you stand on each required security measure, and what's left to do.\n- **A tracked action plan**: every gap becomes an action with an owner and a deadline.\n- **Your vendors already count**: assessments run in CISAPP feed straight into the supply chain requirement.\n- **Ready on incident day**: notification deadlines (24 h, 72 h, 1 month) are tracked for you.\n\n### Who it's for\n\nEssential and important entities, and the suppliers they ask for guarantees.\n",[100],[507,100],"conformite-nis2-fournisseurs",{"title":448,"description":11},"conformite-nis2","en\u002Froadmap\u002Fconformite-nis2","Find out whether NIS2 applies to you, measure your gap against the Article 21 measures, track your action plan and link vendor assessments to the supply chain security requirement.","y9xotAeY8lUhmlTIiUf7kGUW0GKLaK4MWgyywkrSMhY",{"id":514,"title":515,"body":516,"connectors":549,"description":11,"extension":15,"featured":16,"illustration":551,"media":17,"meta":552,"navigation":19,"path":553,"period":17,"persona":21,"rawbody":554,"regulations":555,"relatedPages":556,"seo":557,"shippedAt":261,"slug":558,"status":28,"stem":559,"summary":560,"theme":561,"updatedAt":17,"__hash__":562},"roadmap_en\u002Fen\u002Froadmap\u002Fconnecteur-github.md","GitHub connector and Dependabot alerts",{"type":8,"value":517,"toc":545},[518,520,538,542],[39,519,50],{"id":49},[52,521,522,529,535],{},[55,523,524,525,528],{},"Connection through a ",[58,526,527],{},"GitHub App",": read-only permissions, revocable at any time.",[55,530,531,534],{},[58,532,533],{},"Dependabot alerts"," flow in automatically and join your vulnerability tracking.",[55,536,537],{},"A single Connectors page to enable, configure and monitor each integration.",[39,539,541],{"id":540},"whats-next","What's next",[44,543,544],{},"GitHub is the first connector on a generic foundation: every new integration reuses the same configuration and sync framework.",{"title":11,"searchDepth":12,"depth":12,"links":546},[547,548],{"id":49,"depth":90,"text":50},{"id":540,"depth":90,"text":541},[550],"github","connectors",{},"\u002Fen\u002Froadmap\u002Fconnecteur-github","---\nslug: connecteur-github\ntitle: GitHub connector and Dependabot alerts\nsummary: \"First connector of the integrations platform: link your GitHub repositories and centralise Dependabot alerts in your vulnerability inventory.\"\nstatus: shipped\nshippedAt: '2026-07-01'\ntheme: integrations\nillustration: connectors\nconnectors: [github]\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### What changes\n\n- Connection through a **GitHub App**: read-only permissions, revocable at any time.\n- **Dependabot alerts** flow in automatically and join your vulnerability tracking.\n- A single Connectors page to enable, configure and monitor each integration.\n\n### What's next\n\nGitHub is the first connector on a generic foundation: every new integration reuses the same configuration and sync framework.\n",[],[167],{"title":515,"description":11},"connecteur-github","en\u002Froadmap\u002Fconnecteur-github","First connector of the integrations platform: link your GitHub repositories and centralise Dependabot alerts in your vulnerability inventory.","integrations","PZrruAxLeQI7U54R14WFbeYLWHoEci_BtMvE-GN7DDw",{"id":564,"title":565,"body":566,"connectors":609,"description":11,"extension":15,"featured":16,"illustration":551,"media":17,"meta":617,"navigation":19,"path":618,"period":17,"persona":21,"rawbody":619,"regulations":620,"relatedPages":621,"seo":622,"shippedAt":17,"slug":623,"status":362,"stem":624,"summary":625,"theme":561,"updatedAt":17,"__hash__":626},"roadmap_en\u002Fen\u002Froadmap\u002Fconnecteurs-a-l-etude.md","Connectors under consideration: Salesforce, Zendesk, Shopify, Sage…",{"type":8,"value":567,"toc":605},[568,572,598,602],[39,569,571],{"id":570},"under-consideration","Under consideration",[52,573,574,580,586,592],{},[55,575,576,579],{},[58,577,578],{},"Salesforce and Zendesk",": connect customer relationship and support to your security commitments.",[55,581,582,585],{},[58,583,584],{},"Shopify, Mixpanel and Vercel",": cover the tools used by e-commerce, product and web teams.",[55,587,588,591],{},[58,589,590],{},"Sage",": bring your vendors together with your purchasing data.",[55,593,594,597],{},[58,595,596],{},"Zapier",": connect CISAPP to tools not yet on this list.",[39,599,601],{"id":600},"your-input-matters","Your input matters",[44,603,604],{},"The order of these integrations depends on your needs. Talk to your CISAPP contact or book a demo.",{"title":11,"searchDepth":12,"depth":12,"links":606},[607,608],{"id":570,"depth":90,"text":571},{"id":600,"depth":90,"text":601},[610,611,612,613,614,615,616],"salesforce","zendesk","shopify","mixpanel","sage","vercel","zapier",{},"\u002Fen\u002Froadmap\u002Fconnecteurs-a-l-etude","---\nslug: connecteurs-a-l-etude\ntitle: \"Connectors under consideration: Salesforce, Zendesk, Shopify, Sage…\"\nsummary: \"These integrations are being considered next. Tell us which ones matter to you: your feedback sets the order.\"\nstatus: exploring\ntheme: integrations\nillustration: connectors\nconnectors: [salesforce, zendesk, shopify, mixpanel, sage, vercel, zapier]\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### Under consideration\n\n- **Salesforce and Zendesk**: connect customer relationship and support to your security commitments.\n- **Shopify, Mixpanel and Vercel**: cover the tools used by e-commerce, product and web teams.\n- **Sage**: bring your vendors together with your purchasing data.\n- **Zapier**: connect CISAPP to tools not yet on this list.\n\n### Your input matters\n\nThe order of these integrations depends on your needs. Talk to your CISAPP contact or book a demo.\n",[],[167],{"title":565,"description":11},"connecteurs-a-l-etude","en\u002Froadmap\u002Fconnecteurs-a-l-etude","These integrations are being considered next. Tell us which ones matter to you: your feedback sets the order.","k32V1gZqeCnNwTWfd3AA0UEGkAp5sTdGm5mUqJ18e3U",{"id":628,"title":629,"body":630,"connectors":669,"description":11,"extension":15,"featured":16,"illustration":551,"media":17,"meta":676,"navigation":19,"path":677,"period":97,"persona":21,"rawbody":678,"regulations":679,"relatedPages":680,"seo":681,"shippedAt":17,"slug":682,"status":106,"stem":683,"summary":684,"theme":561,"updatedAt":17,"__hash__":685},"roadmap_en\u002Fen\u002Froadmap\u002Fconnecteurs-cloud-et-suivi.md","Azure, Google Cloud, Scaleway, OVHcloud, Linear and Aikido connectors",{"type":8,"value":631,"toc":665},[632,634,660,662],[39,633,50],{"id":49},[52,635,636,642,648,654],{},[55,637,638,641],{},[58,639,640],{},"Azure and Google Cloud",": the same up-to-date evidence as AWS, whatever your cloud provider.",[55,643,644,647],{},[58,645,646],{},"Scaleway and OVHcloud",": European hosting providers, for organisations that have chosen sovereignty.",[55,649,650,653],{},[58,651,652],{},"Linear",": your remediation plans in your product teams' tool, with progress tracking.",[55,655,656,659],{},[58,657,658],{},"Aikido",": your application vulnerabilities brought together with the rest of your security posture.",[39,661,83],{"id":82},[44,663,664],{},"Teams working across several clouds, and those for whom European hosting is a requirement.",{"title":11,"searchDepth":12,"depth":12,"links":666},[667,668],{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[670,671,672,673,674,675],"azure","gcp","scaleway","ovh","linear","aikido",{},"\u002Fen\u002Froadmap\u002Fconnecteurs-cloud-et-suivi","---\nslug: connecteurs-cloud-et-suivi\ntitle: \"Azure, Google Cloud, Scaleway, OVHcloud, Linear and Aikido connectors\"\nsummary: \"All your clouds covered, European hosting providers included, your application vulnerabilities in one place and your action plans in Linear.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: integrations\nillustration: connectors\nconnectors: [azure, gcp, scaleway, ovh, linear, aikido]\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### What changes\n\n- **Azure and Google Cloud**: the same up-to-date evidence as AWS, whatever your cloud provider.\n- **Scaleway and OVHcloud**: European hosting providers, for organisations that have chosen sovereignty.\n- **Linear**: your remediation plans in your product teams' tool, with progress tracking.\n- **Aikido**: your application vulnerabilities brought together with the rest of your security posture.\n\n### Who it's for\n\nTeams working across several clouds, and those for whom European hosting is a requirement.\n",[],[167],{"title":629,"description":11},"connecteurs-cloud-et-suivi","en\u002Froadmap\u002Fconnecteurs-cloud-et-suivi","All your clouds covered, European hosting providers included, your application vulnerabilities in one place and your action plans in Linear.","WVxrZgGk1f83OYzYdWP6didviKJ1_hwiGIcsLk4YFVo",{"id":687,"title":688,"body":689,"connectors":734,"description":11,"extension":15,"featured":16,"illustration":551,"media":17,"meta":740,"navigation":19,"path":741,"period":742,"persona":21,"rawbody":743,"regulations":744,"relatedPages":745,"seo":746,"shippedAt":17,"slug":747,"status":106,"stem":748,"summary":749,"theme":561,"updatedAt":17,"__hash__":750},"roadmap_en\u002Fen\u002Froadmap\u002Fconnecteurs-supervision-et-sensibilisation.md","Datadog, Azure DevOps, Confluence, Riot and Akamai connectors",{"type":8,"value":690,"toc":730},[691,693,725,727],[39,692,50],{"id":49},[52,694,695,701,707,713,719],{},[55,696,697,700],{},[58,698,699],{},"Datadog",": your monitoring and log retention demonstrated continuously.",[55,702,703,706],{},[58,704,705],{},"Azure DevOps",": remediation and code checks for Microsoft-based teams.",[55,708,709,712],{},[58,710,711],{},"Confluence",": your documented policies and procedures, linked to the requirements they cover.",[55,714,715,718],{},[58,716,717],{},"Riot",": your staff's security awareness as training evidence, expected by NIS2 among others.",[55,720,721,724],{},[58,722,723],{},"Akamai",": the protection of your exposed applications reflected in your posture.",[39,726,83],{"id":82},[44,728,729],{},"Organisations that want to prove what they already do, without producing extra paperwork.",{"title":11,"searchDepth":12,"depth":12,"links":731},[732,733],{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[735,736,737,738,739],"datadog","azure-devops","confluence","riot","akamai",{},"\u002Fen\u002Froadmap\u002Fconnecteurs-supervision-et-sensibilisation","2027-Q3","---\nslug: connecteurs-supervision-et-sensibilisation\ntitle: \"Datadog, Azure DevOps, Confluence, Riot and Akamai connectors\"\nsummary: \"Your monitoring, documentation and staff awareness become evidence, with no extra effort.\"\nstatus: planned\nperiod: '2027-Q3'\ntheme: integrations\nillustration: connectors\nconnectors: [datadog, azure-devops, confluence, riot, akamai]\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### What changes\n\n- **Datadog**: your monitoring and log retention demonstrated continuously.\n- **Azure DevOps**: remediation and code checks for Microsoft-based teams.\n- **Confluence**: your documented policies and procedures, linked to the requirements they cover.\n- **Riot**: your staff's security awareness as training evidence, expected by NIS2 among others.\n- **Akamai**: the protection of your exposed applications reflected in your posture.\n\n### Who it's for\n\nOrganisations that want to prove what they already do, without producing extra paperwork.\n",[],[167],{"title":688,"description":11},"connecteurs-supervision-et-sensibilisation","en\u002Froadmap\u002Fconnecteurs-supervision-et-sensibilisation","Your monitoring, documentation and staff awareness become evidence, with no extra effort.","17ssTab6biiWsHLQd6xD1EyQa5qwhCu-5jrYo1506cw",{"id":752,"title":753,"body":754,"connectors":801,"description":11,"extension":15,"featured":16,"illustration":551,"media":17,"meta":806,"navigation":19,"path":807,"period":163,"persona":21,"rawbody":808,"regulations":809,"relatedPages":810,"seo":811,"shippedAt":17,"slug":812,"status":106,"stem":813,"summary":814,"theme":561,"updatedAt":17,"__hash__":815},"roadmap_en\u002Fen\u002Froadmap\u002Fconnecteurs-supplementaires.md","AWS, Jira, Slack and GitLab connectors",{"type":8,"value":755,"toc":796},[756,758,761,763,789,793],[39,757,42],{"id":41},[44,759,760],{},"Security evidence already lives in your tools: your cloud configuration, your code repositories, your tickets. Copying it into a questionnaire or a spreadsheet takes time, and it's out of date the next day.",[39,762,50],{"id":49},[52,764,765,771,777,783],{},[55,766,767,770],{},[58,768,769],{},"AWS",": your cloud configuration becomes up-to-date evidence, no screenshots needed.",[55,772,773,776],{},[58,774,775],{},"GitLab",": the same checks as GitHub, for teams working on GitLab.",[55,778,779,782],{},[58,780,781],{},"Jira",": remediation actions go straight into your teams' backlog, and their progress flows back into CISAPP.",[55,784,785,788],{},[58,786,787],{},"Slack",": the alerts that matter (vendor incident, expired evidence, assessment received) reach your channels.",[39,790,792],{"id":791},"why-these-first","Why these first",[44,794,795],{},"They're the tools that bring the most evidence and save the most time day to day. More will follow throughout the year.",{"title":11,"searchDepth":12,"depth":12,"links":797},[798,799,800],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":791,"depth":90,"text":792},[802,803,804,805],"aws","jira","slack","gitlab",{},"\u002Fen\u002Froadmap\u002Fconnecteurs-supplementaires","---\nslug: connecteurs-supplementaires\ntitle: \"AWS, Jira, Slack and GitLab connectors\"\nsummary: \"Your cloud and code evidence flows in on its own, action plans land in your tracking tools and alerts reach your team where it already works.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: integrations\nillustration: connectors\nconnectors: [aws, jira, slack, gitlab]\nrelatedPages: [cybersecurite-supply-chain]\n---\n\n### The problem\n\nSecurity evidence already lives in your tools: your cloud configuration, your code repositories, your tickets. Copying it into a questionnaire or a spreadsheet takes time, and it's out of date the next day.\n\n### What changes\n\n- **AWS**: your cloud configuration becomes up-to-date evidence, no screenshots needed.\n- **GitLab**: the same checks as GitHub, for teams working on GitLab.\n- **Jira**: remediation actions go straight into your teams' backlog, and their progress flows back into CISAPP.\n- **Slack**: the alerts that matter (vendor incident, expired evidence, assessment received) reach your channels.\n\n### Why these first\n\nThey're the tools that bring the most evidence and save the most time day to day. More will follow throughout the year.\n",[],[167],{"title":753,"description":11},"connecteurs-supplementaires","en\u002Froadmap\u002Fconnecteurs-supplementaires","Your cloud and code evidence flows in on its own, action plans land in your tracking tools and alerts reach your team where it already works.","rkfTPH6hQBqbqpdwJocpnYvQ1Cs80yxpzWW2qm1eaxM",{"id":817,"title":818,"body":819,"connectors":864,"description":11,"extension":15,"featured":16,"illustration":865,"media":17,"meta":866,"navigation":19,"path":867,"period":17,"persona":21,"rawbody":868,"regulations":869,"relatedPages":870,"seo":871,"shippedAt":872,"slug":873,"status":28,"stem":874,"summary":875,"theme":31,"updatedAt":17,"__hash__":876},"roadmap_en\u002Fen\u002Froadmap\u002Fconnexion-securisee-sso-mfa.md","Secure sign-in: SSO and two-factor authentication",{"type":8,"value":820,"toc":859},[821,823,826,828,854,856],[39,822,42],{"id":41},[44,824,825],{},"Passwords alone don't protect sensitive data, and extra accounts slow adoption.",[39,827,50],{"id":49},[52,829,830,836,842,848],{},[55,831,832,835],{},[58,833,834],{},"One-click sign-in"," with Google, Microsoft or your company SSO.",[55,837,838,841],{},[58,839,840],{},"Two-factor authentication"," of your choice: authenticator app, SMS or email.",[55,843,844,847],{},[58,845,846],{},"Easy invitations",": colleagues activate their account and set their own password.",[55,849,850,853],{},[58,851,852],{},"Protected sessions",", with verification methods ranked by your preference.",[39,855,83],{"id":82},[44,857,858],{},"Every team, and CISOs in particular who must show controlled access to the platform.",{"title":11,"searchDepth":12,"depth":12,"links":860},[861,862,863],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"auth",{},"\u002Fen\u002Froadmap\u002Fconnexion-securisee-sso-mfa","---\nslug: connexion-securisee-sso-mfa\ntitle: 'Secure sign-in: SSO and two-factor authentication'\nsummary: Sign in with your Google or Microsoft account, or company SSO, and protect every account with a second verification step.\nstatus: shipped\nshippedAt: '2024-10-17'\ntheme: plateforme\nillustration: auth\n---\n\n### The problem\n\nPasswords alone don't protect sensitive data, and extra accounts slow adoption.\n\n### What changes\n\n- **One-click sign-in** with Google, Microsoft or your company SSO.\n- **Two-factor authentication** of your choice: authenticator app, SMS or email.\n- **Easy invitations**: colleagues activate their account and set their own password.\n- **Protected sessions**, with verification methods ranked by your preference.\n\n### Who it's for\n\nEvery team, and CISOs in particular who must show controlled access to the platform.\n",[],[],{"title":818,"description":11},"2024-10-17","connexion-securisee-sso-mfa","en\u002Froadmap\u002Fconnexion-securisee-sso-mfa","Sign in with your Google or Microsoft account, or company SSO, and protect every account with a second verification step.","wTsLoZyGOAQKR9Ti5Sg_882Yke2l_CIeDaj6JIF3HOc",{"id":878,"title":879,"body":880,"connectors":884,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":885,"navigation":19,"path":886,"period":17,"persona":21,"rawbody":887,"regulations":888,"relatedPages":889,"seo":890,"shippedAt":891,"slug":892,"status":28,"stem":893,"summary":894,"theme":171,"updatedAt":17,"__hash__":895},"roadmap_en\u002Fen\u002Froadmap\u002Fcontroles-techniques-services.md","Technical service checks",{"type":8,"value":881,"toc":882},[],{"title":11,"searchDepth":12,"depth":12,"links":883},[],[],{},"\u002Fen\u002Froadmap\u002Fcontroles-techniques-services","---\nslug: controles-techniques-services\ntitle: Technical service checks\nsummary: 'Check the security setup of your services: SSL certificate, email protection and blocklist presence.'\nstatus: shipped\nshippedAt: '2025-07-21'\ntheme: cartographie\n---\n",[],[],{"title":879,"description":11},"2025-07-21","controles-techniques-services","en\u002Froadmap\u002Fcontroles-techniques-services","Check the security setup of your services: SSL certificate, email protection and blocklist presence.","B1dybcLSmwxQQe_G5g681Larpv7mELJqz0Gfhy-AzQo",{"id":897,"title":898,"body":899,"connectors":903,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":904,"navigation":19,"path":905,"period":17,"persona":21,"rawbody":906,"regulations":907,"relatedPages":908,"seo":909,"shippedAt":299,"slug":910,"status":28,"stem":911,"summary":912,"theme":365,"updatedAt":17,"__hash__":913},"roadmap_en\u002Fen\u002Froadmap\u002Fdemandes-acces-fournisseur.md","Vendor access requests",{"type":8,"value":900,"toc":901},[],{"title":11,"searchDepth":12,"depth":12,"links":902},[],[],{},"\u002Fen\u002Froadmap\u002Fdemandes-acces-fournisseur","---\nslug: demandes-acces-fournisseur\ntitle: Vendor access requests\nsummary: A vendor contact requests access to your workspace, a reviewer approves or declines, and both sides are notified by email at each step.\nstatus: shipped\nshippedAt: '2026-06-30'\ntheme: evaluations\n---\n",[],[],{"title":898,"description":11},"demandes-acces-fournisseur","en\u002Froadmap\u002Fdemandes-acces-fournisseur","A vendor contact requests access to your workspace, a reviewer approves or declines, and both sides are notified by email at each step.","LE_VCQGc-WTlo_SuKh-rSJOUbyAC4KMk1k87KPEsLX8",{"id":915,"title":916,"body":917,"connectors":921,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":922,"navigation":19,"path":923,"period":17,"persona":21,"rawbody":924,"regulations":925,"relatedPages":926,"seo":927,"shippedAt":928,"slug":929,"status":28,"stem":930,"summary":931,"theme":109,"updatedAt":17,"__hash__":932},"roadmap_en\u002Fen\u002Froadmap\u002Fderogations.md","Policy exemptions",{"type":8,"value":918,"toc":919},[],{"title":11,"searchDepth":12,"depth":12,"links":920},[],[],{},"\u002Fen\u002Froadmap\u002Fderogations","---\nslug: derogations\ntitle: Policy exemptions\nsummary: Request, document and track exceptions to your internal rules, with a guided three-step flow.\nstatus: shipped\nshippedAt: '2026-04-21'\ntheme: conformite\n---\n",[],[],{"title":916,"description":11},"2026-04-21","derogations","en\u002Froadmap\u002Fderogations","Request, document and track exceptions to your internal rules, with a guided three-step flow.","nzjdG3s8zZFf6LxD9S_DIb7zuB-e_tHjo5-4577_Ets",{"id":934,"title":935,"body":936,"connectors":981,"description":11,"extension":15,"featured":16,"illustration":982,"media":17,"meta":983,"navigation":19,"path":984,"period":163,"persona":21,"rawbody":985,"regulations":986,"relatedPages":987,"seo":988,"shippedAt":17,"slug":989,"status":106,"stem":990,"summary":991,"theme":365,"updatedAt":17,"__hash__":992},"roadmap_en\u002Fen\u002Froadmap\u002Fechange-documents.md","Vendor-customer document exchange",{"type":8,"value":937,"toc":976},[938,940,943,945,971,973],[39,939,42],{"id":41},[44,941,942],{},"Attestations, certificates, data processing agreements: your vendors' documents are scattered across inboxes, questionnaires and shared folders. Nobody notices when a certificate expires.",[39,944,50],{"id":49},[52,946,947,953,959,965],{},[55,948,949,952],{},[58,950,951],{},"A Documents space for each vendor",": everything they've sent you, in one place.",[55,954,955,958],{},[58,956,957],{},"Request, remind, receive",": a request with a due date and automatic reminders.",[55,960,961,964],{},[58,962,963],{},"Expiry alerts",": when a document is about to expire, the renewal request goes out on its own.",[55,966,967,970],{},[58,968,969],{},"For suppliers, share once",": the same document for several clients, with a clear list of who has access and until when.",[39,972,83],{"id":82},[44,974,975],{},"Procurement and security teams on the client side, and suppliers who share documents with several clients.",{"title":11,"searchDepth":12,"depth":12,"links":977},[978,979,980],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"documents",{},"\u002Fen\u002Froadmap\u002Fechange-documents","---\nslug: echange-documents\ntitle: \"Vendor-customer document exchange\"\nsummary: \"A document space for each relationship: request a document with a due date and reminders, track its validity and share it once with several customers.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: evaluations\nillustration: documents\n---\n\n### The problem\n\nAttestations, certificates, data processing agreements: your vendors' documents are scattered across inboxes, questionnaires and shared folders. Nobody notices when a certificate expires.\n\n### What changes\n\n- **A Documents space for each vendor**: everything they've sent you, in one place.\n- **Request, remind, receive**: a request with a due date and automatic reminders.\n- **Expiry alerts**: when a document is about to expire, the renewal request goes out on its own.\n- **For suppliers, share once**: the same document for several clients, with a clear list of who has access and until when.\n\n### Who it's for\n\nProcurement and security teams on the client side, and suppliers who share documents with several clients.\n",[],[],{"title":935,"description":11},"echange-documents","en\u002Froadmap\u002Fechange-documents","A document space for each relationship: request a document with a due date and reminders, track its validity and share it once with several customers.","6wINoXnjChf--Y4tS6MAFAraR4jbghDDFqbctIGQvfQ",{"id":994,"title":995,"body":996,"connectors":1000,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1001,"navigation":19,"path":1002,"period":17,"persona":21,"rawbody":1003,"regulations":1004,"relatedPages":1005,"seo":1006,"shippedAt":1007,"slug":1008,"status":28,"stem":1009,"summary":1010,"theme":31,"updatedAt":17,"__hash__":1011},"roadmap_en\u002Fen\u002Froadmap\u002Fequipes-roles-permissions.md","Teams, roles and permissions",{"type":8,"value":997,"toc":998},[],{"title":11,"searchDepth":12,"depth":12,"links":999},[],[],{},"\u002Fen\u002Froadmap\u002Fequipes-roles-permissions","---\nslug: equipes-roles-permissions\ntitle: Teams, roles and permissions\nsummary: Invite colleagues, organize them into teams and decide who can see or edit each vendor, scope and project.\nstatus: shipped\nshippedAt: '2025-05-26'\ntheme: plateforme\n---\n",[],[],{"title":995,"description":11},"2025-05-26","equipes-roles-permissions","en\u002Froadmap\u002Fequipes-roles-permissions","Invite colleagues, organize them into teams and decide who can see or edit each vendor, scope and project.","SCkuKCnTpnLT1iEcOjQFsubm16bDn0p52gI7bxAsjaM",{"id":1013,"title":1014,"body":1015,"connectors":1019,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1020,"navigation":19,"path":1021,"period":17,"persona":21,"rawbody":1022,"regulations":1023,"relatedPages":1024,"seo":1025,"shippedAt":1026,"slug":1027,"status":28,"stem":1028,"summary":1029,"theme":31,"updatedAt":17,"__hash__":1030},"roadmap_en\u002Fen\u002Froadmap\u002Fetiquettes.md","Custom tags",{"type":8,"value":1016,"toc":1017},[],{"title":11,"searchDepth":12,"depth":12,"links":1018},[],[],{},"\u002Fen\u002Froadmap\u002Fetiquettes","---\nslug: etiquettes\ntitle: Custom tags\nsummary: Classify vendors and scopes with your own tags to filter and find what matters fast.\nstatus: shipped\nshippedAt: '2026-06-07'\ntheme: plateforme\n---\n",[],[],{"title":1014,"description":11},"2026-06-07","etiquettes","en\u002Froadmap\u002Fetiquettes","Classify vendors and scopes with your own tags to filter and find what matters fast.","Cmd2IEYLebWmzsdXGRcMW7UuqatZ43eUFNCXHBudcyc",{"id":1032,"title":1033,"body":1034,"connectors":1038,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1039,"navigation":19,"path":1040,"period":17,"persona":21,"rawbody":1041,"regulations":1042,"relatedPages":1043,"seo":1044,"shippedAt":1045,"slug":1046,"status":28,"stem":1047,"summary":1048,"theme":365,"updatedAt":17,"__hash__":1049},"roadmap_en\u002Fen\u002Froadmap\u002Fevaluations-clients-fournisseur.md","Assessments from the vendor side",{"type":8,"value":1035,"toc":1036},[],{"title":11,"searchDepth":12,"depth":12,"links":1037},[],[],{},"\u002Fen\u002Froadmap\u002Fevaluations-clients-fournisseur","---\nslug: evaluations-clients-fournisseur\ntitle: Assessments from the vendor side\nsummary: Answer your clients' assessments and compare your vendors in a matrix to decide faster.\nstatus: shipped\nshippedAt: '2026-07-10'\ntheme: evaluations\n---\n",[],[],{"title":1033,"description":11},"2026-07-10","evaluations-clients-fournisseur","en\u002Froadmap\u002Fevaluations-clients-fournisseur","Answer your clients' assessments and compare your vendors in a matrix to decide faster.","qyrDsGCyhilkHRZqNy6h6pn4-plgA0hY9qtEGrnmH0g",{"id":1051,"title":1052,"body":1053,"connectors":1098,"description":11,"extension":15,"featured":16,"illustration":365,"media":17,"meta":1099,"navigation":19,"path":1100,"period":17,"persona":21,"rawbody":1101,"regulations":1102,"relatedPages":1103,"seo":1104,"shippedAt":1105,"slug":1106,"status":28,"stem":1107,"summary":1108,"theme":365,"updatedAt":17,"__hash__":1109},"roadmap_en\u002Fen\u002Froadmap\u002Fevaluations-fournisseurs.md","Vendor assessments",{"type":8,"value":1054,"toc":1093},[1055,1057,1060,1062,1088,1090],[39,1056,42],{"id":41},[44,1058,1059],{},"Assessments are tracked by email and spreadsheet: nobody knows who answered or where the review stands.",[39,1061,50],{"id":49},[52,1063,1064,1070,1076,1082],{},[55,1065,1066,1069],{},[58,1067,1068],{},"Creation wizard",": choose questionnaires, vendors and access rights.",[55,1071,1072,1075],{},[58,1073,1074],{},"Sending with a due date"," and a personal message.",[55,1077,1078,1081],{},[58,1079,1080],{},"Answer review",": approve, send back, reject with a reason, or approve in bulk.",[55,1083,1084,1087],{},[58,1085,1086],{},"Side-by-side comparison"," of vendors.",[39,1089,83],{"id":82},[44,1091,1092],{},"Security and procurement teams running several assessments in parallel.",{"title":11,"searchDepth":12,"depth":12,"links":1094},[1095,1096,1097],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Fevaluations-fournisseurs","---\nslug: evaluations-fournisseurs\ntitle: Vendor assessments\nsummary: Launch an assessment, send it with a due date, review the answers and approve them, all tracked in one table.\nstatus: shipped\nshippedAt: '2025-11-02'\ntheme: evaluations\nillustration: evaluations\n---\n\n### The problem\n\nAssessments are tracked by email and spreadsheet: nobody knows who answered or where the review stands.\n\n### What changes\n\n- **Creation wizard**: choose questionnaires, vendors and access rights.\n- **Sending with a due date** and a personal message.\n- **Answer review**: approve, send back, reject with a reason, or approve in bulk.\n- **Side-by-side comparison** of vendors.\n\n### Who it's for\n\nSecurity and procurement teams running several assessments in parallel.\n",[],[],{"title":1052,"description":11},"2025-11-02","evaluations-fournisseurs","en\u002Froadmap\u002Fevaluations-fournisseurs","Launch an assessment, send it with a due date, review the answers and approve them, all tracked in one table.","N0JLEl7QNlqPy6KThfTwcTDOTDayuLKQ5SEjjlckny4",{"id":1111,"title":1112,"body":1113,"connectors":1117,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1118,"navigation":19,"path":1119,"period":17,"persona":21,"rawbody":1120,"regulations":1121,"relatedPages":1122,"seo":1123,"shippedAt":1124,"slug":1125,"status":28,"stem":1126,"summary":1127,"theme":31,"updatedAt":17,"__hash__":1128},"roadmap_en\u002Fen\u002Froadmap\u002Fexplorateur-documents-tlp.md","Document explorer with TLP sharing levels",{"type":8,"value":1114,"toc":1115},[],{"title":11,"searchDepth":12,"depth":12,"links":1116},[],[],{},"\u002Fen\u002Froadmap\u002Fexplorateur-documents-tlp","---\nslug: explorateur-documents-tlp\ntitle: Document explorer with TLP sharing levels\nsummary: Browse, preview and classify your sensitive documents by TLP sharing level, with a view of the storage space used.\nstatus: shipped\nshippedAt: '2026-07-16'\ntheme: plateforme\n---\n",[],[],{"title":1112,"description":11},"2026-07-16","explorateur-documents-tlp","en\u002Froadmap\u002Fexplorateur-documents-tlp","Browse, preview and classify your sensitive documents by TLP sharing level, with a view of the storage space used.","3cV5AsKdzKGCZt40M0OLZV0mdQ2zpO5Ebx5R7ZpR39U",{"id":1130,"title":1131,"body":1132,"connectors":1177,"description":11,"extension":15,"featured":16,"illustration":1178,"media":17,"meta":1179,"navigation":19,"path":1180,"period":17,"persona":21,"rawbody":1181,"regulations":1182,"relatedPages":1183,"seo":1185,"shippedAt":17,"slug":1186,"status":362,"stem":1187,"summary":1188,"theme":365,"updatedAt":17,"__hash__":1189},"roadmap_en\u002Fen\u002Froadmap\u002Fextension-navigateur.md","Browser extension",{"type":8,"value":1133,"toc":1172},[1134,1136,1139,1141,1167,1169],[39,1135,42],{"id":41},[44,1137,1138],{},"Some of your clients send their questionnaires through their own portals. Your existing answers can't be reused there: everything is done by hand, question by question.",[39,1140,50],{"id":49},[52,1142,1143,1149,1155,1161],{},[55,1144,1145,1148],{},[58,1146,1147],{},"Your answers on any portal",": CISAPP suggests the right answer from your library.",[55,1150,1151,1154],{},[58,1152,1153],{},"One-click insertion",": with the source of each suggestion.",[55,1156,1157,1160],{},[58,1158,1159],{},"A library that grows",": every approved answer is kept for next time.",[55,1162,1163,1166],{},[58,1164,1165],{},"Hours saved",": the same work is done once, whatever the portal.",[39,1168,83],{"id":82},[44,1170,1171],{},"Security, compliance and pre-sales teams on the supplier side.",{"title":11,"searchDepth":12,"depth":12,"links":1173},[1174,1175,1176],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"browser",{},"\u002Fen\u002Froadmap\u002Fextension-navigateur","---\nslug: extension-navigateur\ntitle: \"Browser extension\"\nsummary: \"Reuse your answer library directly inside your customers' questionnaire portals.\"\nstatus: exploring\ntheme: evaluations\nillustration: browser\nrelatedPages: [questionnaire-securite-fournisseur]\n---\n\n### The problem\n\nSome of your clients send their questionnaires through their own portals. Your existing answers can't be reused there: everything is done by hand, question by question.\n\n### What changes\n\n- **Your answers on any portal**: CISAPP suggests the right answer from your library.\n- **One-click insertion**: with the source of each suggestion.\n- **A library that grows**: every approved answer is kept for next time.\n- **Hours saved**: the same work is done once, whatever the portal.\n\n### Who it's for\n\nSecurity, compliance and pre-sales teams on the supplier side.\n",[],[1184],"questionnaire-securite-fournisseur",{"title":1131,"description":11},"extension-navigateur","en\u002Froadmap\u002Fextension-navigateur","Reuse your answer library directly inside your customers' questionnaire portals.","i6q8qJQ_UucLU5pDMG6WKnYJ7EB5tcHRBoIgyKNG2wQ",{"id":1191,"title":1192,"body":1193,"connectors":1197,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1198,"navigation":19,"path":1199,"period":17,"persona":21,"rawbody":1200,"regulations":1201,"relatedPages":1202,"seo":1203,"shippedAt":17,"slug":1204,"status":281,"stem":1205,"summary":1206,"theme":31,"updatedAt":17,"__hash__":1207},"roadmap_en\u002Fen\u002Froadmap\u002Ffil-actualites-cyber.md","Cyber news feed",{"type":8,"value":1194,"toc":1195},[],{"title":11,"searchDepth":12,"depth":12,"links":1196},[],[],{},"\u002Fen\u002Froadmap\u002Ffil-actualites-cyber","---\nslug: fil-actualites-cyber\ntitle: Cyber news feed\nsummary: A feed of cyber and regulatory news on your dashboard, with the option to add your own sources.\nstatus: in_progress\ntheme: plateforme\n---\n",[],[],{"title":1192,"description":11},"fil-actualites-cyber","en\u002Froadmap\u002Ffil-actualites-cyber","A feed of cyber and regulatory news on your dashboard, with the option to add your own sources.","KUK1SAtsahxGKtXuY92hNBlw3fUasfeFEDWwXkUA904",{"id":1209,"title":1210,"body":1211,"connectors":1215,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1216,"navigation":19,"path":1217,"period":17,"persona":21,"rawbody":1218,"regulations":1219,"relatedPages":1220,"seo":1221,"shippedAt":1222,"slug":1223,"status":28,"stem":1224,"summary":1225,"theme":109,"updatedAt":17,"__hash__":1226},"roadmap_en\u002Fen\u002Froadmap\u002Fgestion-de-crise.md","Crisis management",{"type":8,"value":1212,"toc":1213},[],{"title":11,"searchDepth":12,"depth":12,"links":1214},[],[],{},"\u002Fen\u002Froadmap\u002Fgestion-de-crise","---\nslug: gestion-de-crise\ntitle: Crisis management\nsummary: Bring crisis cells, communication channels and stakeholders together in a space ready when you need it.\nstatus: shipped\nshippedAt: '2026-04-18'\ntheme: conformite\n---\n",[],[],{"title":1210,"description":11},"2026-04-18","gestion-de-crise","en\u002Froadmap\u002Fgestion-de-crise","Bring crisis cells, communication channels and stakeholders together in a space ready when you need it.","ome84qWcQmcebE9fE3pSQDPcbl9z4TF0Cja2oIjeivg",{"id":1228,"title":1229,"body":1230,"connectors":1281,"description":11,"extension":15,"featured":16,"illustration":1282,"media":17,"meta":1283,"navigation":19,"path":1284,"period":163,"persona":21,"rawbody":1285,"regulations":1286,"relatedPages":1287,"seo":1288,"shippedAt":17,"slug":1289,"status":106,"stem":1290,"summary":1291,"theme":109,"updatedAt":17,"__hash__":1292},"roadmap_en\u002Fen\u002Froadmap\u002Fgestion-de-crise-v2.md","Enhanced crisis management",{"type":8,"value":1231,"toc":1276},[1232,1234,1237,1239,1271,1273],[39,1233,42],{"id":41},[44,1235,1236],{},"When an incident hits, everything happens in the first few hours: who does what, do you need to notify the authority, and by when? Without preparation, you improvise under pressure.",[39,1238,50],{"id":49},[52,1240,1241,1247,1253,1259,1265],{},[55,1242,1243,1246],{},[58,1244,1245],{},"Regulatory deadlines in plain sight",": NIS2, DORA, GDPR. CISAPP tells you whether to notify, whom, and by when.",[55,1248,1249,1252],{},[58,1250,1251],{},"Ready-made action plans",": the steps to follow for each type of incident (ransomware, data leak, vendor failure).",[55,1254,1255,1258],{},[58,1256,1257],{},"Practise before the real thing",": crisis exercises with a scenario and a debrief.",[55,1260,1261,1264],{},[58,1262,1263],{},"Impact visible at once",": an incident at a vendor shows the activities and applications affected.",[55,1266,1267,1270],{},[58,1268,1269],{},"Learn from every incident",": a structured post-incident review at closure.",[39,1272,83],{"id":82},[44,1274,1275],{},"CISOs, crisis teams and organisations subject to NIS2 or DORA.",{"title":11,"searchDepth":12,"depth":12,"links":1277},[1278,1279,1280],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"crisis",{},"\u002Fen\u002Froadmap\u002Fgestion-de-crise-v2","---\nslug: gestion-de-crise-v2\ntitle: \"Enhanced crisis management\"\nsummary: \"Regulatory notification deadlines, playbooks by incident type, structured post-mortems and impact analysis when a vendor is affected.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: conformite\nregulations: [nis2, dora]\nillustration: crisis\n---\n\n### The problem\n\nWhen an incident hits, everything happens in the first few hours: who does what, do you need to notify the authority, and by when? Without preparation, you improvise under pressure.\n\n### What changes\n\n- **Regulatory deadlines in plain sight**: NIS2, DORA, GDPR. CISAPP tells you whether to notify, whom, and by when.\n- **Ready-made action plans**: the steps to follow for each type of incident (ransomware, data leak, vendor failure).\n- **Practise before the real thing**: crisis exercises with a scenario and a debrief.\n- **Impact visible at once**: an incident at a vendor shows the activities and applications affected.\n- **Learn from every incident**: a structured post-incident review at closure.\n\n### Who it's for\n\nCISOs, crisis teams and organisations subject to NIS2 or DORA.\n",[100,101],[],{"title":1229,"description":11},"gestion-de-crise-v2","en\u002Froadmap\u002Fgestion-de-crise-v2","Regulatory notification deadlines, playbooks by incident type, structured post-mortems and impact analysis when a vendor is affected.","myiqasCtmw2A6mqcQLHPOSksb6u0cqMC5ho6v1yl3VE",{"id":1294,"title":1295,"body":1296,"connectors":1300,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1301,"navigation":19,"path":1302,"period":17,"persona":21,"rawbody":1303,"regulations":1304,"relatedPages":1305,"seo":1306,"shippedAt":1307,"slug":1308,"status":28,"stem":1309,"summary":1310,"theme":31,"updatedAt":17,"__hash__":1311},"roadmap_en\u002Fen\u002Froadmap\u002Fgestion-des-clients.md","Client management",{"type":8,"value":1297,"toc":1298},[],{"title":11,"searchDepth":12,"depth":12,"links":1299},[],[],{},"\u002Fen\u002Froadmap\u002Fgestion-des-clients","---\nslug: gestion-des-clients\ntitle: Client management\nsummary: Vendors and service providers see the client organizations assessing them, with a detail page for each.\nstatus: shipped\nshippedAt: '2025-11-25'\ntheme: plateforme\n---\n",[],[],{"title":1295,"description":11},"2025-11-25","gestion-des-clients","en\u002Froadmap\u002Fgestion-des-clients","Vendors and service providers see the client organizations assessing them, with a detail page for each.","lvsVnKChu4LQRU7_DvL53EYyyt6yK5QdiQ44MGWR-1c",{"id":1313,"title":1314,"body":1315,"connectors":1319,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1320,"navigation":19,"path":1321,"period":17,"persona":21,"rawbody":1322,"regulations":1323,"relatedPages":1324,"seo":1325,"shippedAt":1326,"slug":1327,"status":28,"stem":1328,"summary":1329,"theme":109,"updatedAt":17,"__hash__":1330},"roadmap_en\u002Fen\u002Froadmap\u002Fgestion-des-incidents.md","Security incident management",{"type":8,"value":1316,"toc":1317},[],{"title":11,"searchDepth":12,"depth":12,"links":1318},[],[],{},"\u002Fen\u002Froadmap\u002Fgestion-des-incidents","---\nslug: gestion-des-incidents\ntitle: Security incident management\nsummary: Log your incidents and notify the affected client organizations directly from the platform.\nstatus: shipped\nshippedAt: '2026-04-22'\ntheme: conformite\n---\n",[],[],{"title":1314,"description":11},"2026-04-22","gestion-des-incidents","en\u002Froadmap\u002Fgestion-des-incidents","Log your incidents and notify the affected client organizations directly from the platform.","iVdhTRqxyI4m_jofrrjemTCKa9Zut4lSG0956u1LS4Q",{"id":1332,"title":1333,"body":1334,"connectors":1385,"description":11,"extension":15,"featured":19,"illustration":1386,"media":17,"meta":1387,"navigation":19,"path":1388,"period":163,"persona":21,"rawbody":1389,"regulations":1390,"relatedPages":1391,"seo":1392,"shippedAt":17,"slug":1393,"status":106,"stem":1394,"summary":1395,"theme":31,"updatedAt":17,"__hash__":1396},"roadmap_en\u002Fen\u002Froadmap\u002Fgroupe-filiales.md","Group and subsidiary management",{"type":8,"value":1335,"toc":1380},[1336,1338,1341,1343,1375,1377],[39,1337,42],{"id":41},[44,1339,1340],{},"In a group, each subsidiary manages its vendors on its own. The same provider gets five different questionnaires, and group security has no overall picture without stitching spreadsheets together by hand.",[39,1342,50],{"id":49},[52,1344,1345,1351,1357,1363,1369],{},[55,1346,1347,1350],{},[58,1348,1349],{},"One group view, autonomous subsidiaries",": each subsidiary keeps its own vendors, teams and data. The group sees everything; subsidiaries don't see each other.",[55,1352,1353,1356],{},[58,1354,1355],{},"A shared vendor register",": a provider used by several subsidiaries is assessed once, and every entity benefits.",[55,1358,1359,1362],{},[58,1360,1361],{},"Common rules",": questionnaires, policies and risk methodology are published by the group and applied everywhere.",[55,1364,1365,1368],{},[58,1366,1367],{},"One login",": your people move from one subsidiary to another with the same account and the group's company sign-in.",[55,1370,1371,1374],{},[58,1372,1373],{},"Consolidated indicators",": compare subsidiaries and spot the vendors several entities depend on.",[39,1376,83],{"id":82},[44,1378,1379],{},"Groups and multi-entity companies, and their group security, compliance and procurement teams. Included in the Enterprise plan.",{"title":11,"searchDepth":12,"depth":12,"links":1381},[1382,1383,1384],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"group",{},"\u002Fen\u002Froadmap\u002Fgroupe-filiales","---\nslug: groupe-filiales\ntitle: \"Group and subsidiary management\"\nsummary: \"Run a group and its subsidiaries from one account: dedicated roles, perimeters, shared vendors and consolidated views, with strict isolation between subsidiaries. Enterprise plan only.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: plateforme\nfeatured: true\nillustration: group\nrelatedPages: [gestion-risque-fournisseur]\n---\n\n### The problem\n\nIn a group, each subsidiary manages its vendors on its own. The same provider gets five different questionnaires, and group security has no overall picture without stitching spreadsheets together by hand.\n\n### What changes\n\n- **One group view, autonomous subsidiaries**: each subsidiary keeps its own vendors, teams and data. The group sees everything; subsidiaries don't see each other.\n- **A shared vendor register**: a provider used by several subsidiaries is assessed once, and every entity benefits.\n- **Common rules**: questionnaires, policies and risk methodology are published by the group and applied everywhere.\n- **One login**: your people move from one subsidiary to another with the same account and the group's company sign-in.\n- **Consolidated indicators**: compare subsidiaries and spot the vendors several entities depend on.\n\n### Who it's for\n\nGroups and multi-entity companies, and their group security, compliance and procurement teams. Included in the Enterprise plan.\n",[],[359],{"title":1333,"description":11},"groupe-filiales","en\u002Froadmap\u002Fgroupe-filiales","Run a group and its subsidiaries from one account: dedicated roles, perimeters, shared vendors and consolidated views, with strict isolation between subsidiaries. Enterprise plan only.","k9gckHHwYYmoSabaE30ZvWu_YXl-5Fchn_cn5jeg2KE",{"id":1398,"title":1399,"body":1400,"connectors":1445,"description":11,"extension":15,"featured":19,"illustration":1446,"media":17,"meta":1447,"navigation":19,"path":1448,"period":17,"persona":21,"rawbody":1449,"regulations":1450,"relatedPages":1451,"seo":1452,"shippedAt":261,"slug":1453,"status":28,"stem":1454,"summary":1455,"theme":365,"updatedAt":17,"__hash__":1456},"roadmap_en\u002Fen\u002Froadmap\u002Fimport-ia-questionnaires.md","AI-assisted Excel questionnaire import",{"type":8,"value":1401,"toc":1440},[1402,1404,1407,1409,1435,1437],[39,1403,42],{"id":41},[44,1405,1406],{},"Every customer sends its own Excel file. Vendor security teams answer the same questions dozens of times a year.",[39,1408,50],{"id":49},[52,1410,1411,1417,1423,1429],{},[55,1412,1413,1416],{},[58,1414,1415],{},"Direct import"," of the customer's file, no retyping.",[55,1418,1419,1422],{},[58,1420,1421],{},"AI-drafted answers",", sourced from your previous answers and documents.",[55,1424,1425,1428],{},[58,1426,1427],{},"Three-pane review",": question, draft, evidence. Accept, edit or reject.",[55,1430,1431,1434],{},[58,1432,1433],{},"Progress tracking"," through to export in the original format.",[39,1436,83],{"id":82},[44,1438,1439],{},"Vendors flooded with security questionnaires, and buyers who want faster, better-evidenced answers.",{"title":11,"searchDepth":12,"depth":12,"links":1441},[1442,1443,1444],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"ai-import",{},"\u002Fen\u002Froadmap\u002Fimport-ia-questionnaires","---\nslug: import-ia-questionnaires\ntitle: AI-assisted Excel questionnaire import\nsummary: Import any Excel security questionnaire; AI drafts answers from your existing evidence and a three-pane review space lets you validate everything before sending.\nstatus: shipped\nshippedAt: '2026-07-01'\ntheme: evaluations\nillustration: ai-import\nfeatured: true\nrelatedPages: [questionnaire-securite-fournisseur]\n---\n\n### The problem\n\nEvery customer sends its own Excel file. Vendor security teams answer the same questions dozens of times a year.\n\n### What changes\n\n- **Direct import** of the customer's file, no retyping.\n- **AI-drafted answers**, sourced from your previous answers and documents.\n- **Three-pane review**: question, draft, evidence. Accept, edit or reject.\n- **Progress tracking** through to export in the original format.\n\n### Who it's for\n\nVendors flooded with security questionnaires, and buyers who want faster, better-evidenced answers.\n",[],[1184],{"title":1399,"description":11},"import-ia-questionnaires","en\u002Froadmap\u002Fimport-ia-questionnaires","Import any Excel security questionnaire; AI drafts answers from your existing evidence and a three-pane review space lets you validate everything before sending.","7kfis0mi2ANjJPScC_3UAibnfrRhK4zH2vEaBHS2pzs",{"id":1458,"title":1459,"body":1460,"connectors":1464,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1465,"navigation":19,"path":1466,"period":97,"persona":21,"rawbody":1467,"regulations":1468,"relatedPages":1469,"seo":1470,"shippedAt":17,"slug":1471,"status":106,"stem":1472,"summary":1473,"theme":365,"updatedAt":17,"__hash__":1474},"roadmap_en\u002Fen\u002Froadmap\u002Fimport-trust-center.md","Import answers from a Trust Center",{"type":8,"value":1461,"toc":1462},[],{"title":11,"searchDepth":12,"depth":12,"links":1463},[],[],{},"\u002Fen\u002Froadmap\u002Fimport-trust-center","---\nslug: import-trust-center\ntitle: \"Import answers from a Trust Center\"\nsummary: \"Pre-fill an assessment from a vendor's Trust Center, with cited sources and answers pending validation.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: evaluations\nrelatedPages: [questionnaire-securite-fournisseur]\n---\n",[],[1184],{"title":1459,"description":11},"import-trust-center","en\u002Froadmap\u002Fimport-trust-center","Pre-fill an assessment from a vendor's Trust Center, with cited sources and answers pending validation.","1Rh58fPQL8_04GqPX6DF6JEh6Emk5TCxU_rxGukZpPE",{"id":1476,"title":1477,"body":1478,"connectors":1482,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1483,"navigation":19,"path":1484,"period":17,"persona":21,"rawbody":1485,"regulations":1486,"relatedPages":1487,"seo":1488,"shippedAt":17,"slug":1489,"status":17,"stem":1490,"summary":1491,"theme":17,"updatedAt":17,"__hash__":1492},"roadmap_en\u002Fen\u002Froadmap\u002Fimport-utilisateurs.md","Bulk user import",{"type":8,"value":1479,"toc":1480},[],{"title":11,"searchDepth":12,"depth":12,"links":1481},[],[],{},"\u002Fen\u002Froadmap\u002Fimport-utilisateurs","---\nslug: import-utilisateurs\ntitle: Bulk user import\nsummary: Import your teams from a CSV or Excel file in three steps: upload, data preview, result summary.\nstatus: shipped\nshippedAt: '2026-09-23'\ntheme: plateforme\n---\n",[],[],{"title":1477,"description":11},"import-utilisateurs","en\u002Froadmap\u002Fimport-utilisateurs","[object Object]","cGlsBzNWMIcJ9_sgijmsTMK4srOiS8pnOLi39CefLUI",{"id":1494,"title":1495,"body":1496,"connectors":1500,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1501,"navigation":19,"path":1502,"period":17,"persona":21,"rawbody":1503,"regulations":1504,"relatedPages":1505,"seo":1506,"shippedAt":1507,"slug":1508,"status":28,"stem":1509,"summary":1510,"theme":31,"updatedAt":17,"__hash__":1511},"roadmap_en\u002Fen\u002Froadmap\u002Fnotes-fournisseurs.md","Internal vendor notes",{"type":8,"value":1497,"toc":1498},[],{"title":11,"searchDepth":12,"depth":12,"links":1499},[],[],{},"\u002Fen\u002Froadmap\u002Fnotes-fournisseurs","---\nslug: notes-fournisseurs\ntitle: Internal vendor notes\nsummary: Timestamped, attributed notes on every vendor record to keep track of discussions and decisions.\nstatus: shipped\nshippedAt: '2026-09-24'\ntheme: plateforme\n---\n",[],[],{"title":1495,"description":11},"2026-09-24","notes-fournisseurs","en\u002Froadmap\u002Fnotes-fournisseurs","Timestamped, attributed notes on every vendor record to keep track of discussions and decisions.","l___-NS7PrYohn9tJmv1Bm3-I2qJ_TC9PuV1MdiuEcw",{"id":1513,"title":1514,"body":1515,"connectors":1519,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1520,"navigation":19,"path":1521,"period":17,"persona":21,"rawbody":1522,"regulations":1523,"relatedPages":1524,"seo":1525,"shippedAt":1526,"slug":1527,"status":28,"stem":1528,"summary":1529,"theme":31,"updatedAt":17,"__hash__":1530},"roadmap_en\u002Fen\u002Froadmap\u002Fnotifications-temps-reel.md","In-app notifications and browser alerts",{"type":8,"value":1516,"toc":1517},[],{"title":11,"searchDepth":12,"depth":12,"links":1518},[],[],{},"\u002Fen\u002Froadmap\u002Fnotifications-temps-reel","---\nslug: notifications-temps-reel\ntitle: In-app notifications and browser alerts\nsummary: A notification center in the app and browser alerts so you never miss a vendor response, a deadline or an access request.\nstatus: shipped\nshippedAt: '2026-07-04'\ntheme: plateforme\n---\n",[],[],{"title":1514,"description":11},"2026-07-04","notifications-temps-reel","en\u002Froadmap\u002Fnotifications-temps-reel","A notification center in the app and browser alerts so you never miss a vendor response, a deadline or an access request.","RSwiNkV7FLi7nuHEqwnTnv0pEo9w_43eUjNzMaxfL7Q",{"id":1532,"title":1533,"body":1534,"connectors":1538,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1539,"navigation":19,"path":1540,"period":17,"persona":21,"rawbody":1541,"regulations":1542,"relatedPages":1543,"seo":1544,"shippedAt":1545,"slug":1546,"status":28,"stem":1547,"summary":1548,"theme":31,"updatedAt":17,"__hash__":1549},"roadmap_en\u002Fen\u002Froadmap\u002Fpalette-de-commandes.md","Command palette",{"type":8,"value":1535,"toc":1536},[],{"title":11,"searchDepth":12,"depth":12,"links":1537},[],[],{},"\u002Fen\u002Froadmap\u002Fpalette-de-commandes","---\nslug: palette-de-commandes\ntitle: Command palette\nsummary: Reach any page or action from the keyboard, without going through menus.\nstatus: shipped\nshippedAt: '2026-04-26'\ntheme: plateforme\n---\n",[],[],{"title":1533,"description":11},"2026-04-26","palette-de-commandes","en\u002Froadmap\u002Fpalette-de-commandes","Reach any page or action from the keyboard, without going through menus.","ZZ1RgNIW6N5CjoefWUtVwUG0VxVNEG8veYUOXQZUEXg",{"id":1551,"title":1552,"body":1553,"connectors":1592,"description":11,"extension":15,"featured":19,"illustration":1593,"media":17,"meta":1594,"navigation":19,"path":1595,"period":17,"persona":21,"rawbody":1596,"regulations":1597,"relatedPages":1598,"seo":1599,"shippedAt":17,"slug":1600,"status":281,"stem":1601,"summary":1602,"theme":365,"updatedAt":17,"__hash__":1603},"roadmap_en\u002Fen\u002Froadmap\u002Fparcours-evaluation-fournisseur.md","End-to-end vendor assessment journey",{"type":8,"value":1554,"toc":1587},[1555,1557,1560,1562,1582,1584],[39,1556,42],{"id":41},[44,1558,1559],{},"Assessing a vendor isn't a one-off: you compare before signing, assess at contracting, then reassess on a schedule. Those three moments often live in different tools.",[39,1561,50],{"id":49},[52,1563,1564,1570,1576],{},[55,1565,1566,1569],{},[58,1567,1568],{},"Selection",": compare several candidates on the same criteria before choosing.",[55,1571,1572,1575],{},[58,1573,1574],{},"Contracting",": the chosen assessment follows the selected vendor.",[55,1577,1578,1581],{},[58,1579,1580],{},"Monitoring",": recurrence set by criticality, automatic reminders.",[39,1583,83],{"id":82},[44,1585,1586],{},"Procurement and security teams who must show continuous oversight of their third parties (NIS2, DORA, ISO 27001 A.5.19-5.22).",{"title":11,"searchDepth":12,"depth":12,"links":1588},[1589,1590,1591],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"journey",{},"\u002Fen\u002Froadmap\u002Fparcours-evaluation-fournisseur","---\nslug: parcours-evaluation-fournisseur\ntitle: End-to-end vendor assessment journey\nsummary: A single journey covers selecting a new vendor, comparing several candidates and recurring monitoring of the vendors already in place.\nstatus: in_progress\ntheme: evaluations\nillustration: journey\nregulations: [nis2, dora, iso-27001]\nfeatured: true\nrelatedPages: [gestion-risque-fournisseur, questionnaire-securite-fournisseur]\n---\n\n### The problem\n\nAssessing a vendor isn't a one-off: you compare before signing, assess at contracting, then reassess on a schedule. Those three moments often live in different tools.\n\n### What changes\n\n- **Selection**: compare several candidates on the same criteria before choosing.\n- **Contracting**: the chosen assessment follows the selected vendor.\n- **Monitoring**: recurrence set by criticality, automatic reminders.\n\n### Who it's for\n\nProcurement and security teams who must show continuous oversight of their third parties (NIS2, DORA, ISO 27001 A.5.19-5.22).\n",[100,101,102],[359,1184],{"title":1552,"description":11},"parcours-evaluation-fournisseur","en\u002Froadmap\u002Fparcours-evaluation-fournisseur","A single journey covers selecting a new vendor, comparing several candidates and recurring monitoring of the vendors already in place.","PkWHkW3sH3Xol_pvK25lhqDcWZGy14FQGkyIveS2mE0",{"id":1605,"title":1606,"body":1607,"connectors":1652,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1653,"navigation":19,"path":1654,"period":17,"persona":21,"rawbody":1655,"regulations":1656,"relatedPages":1657,"seo":1658,"shippedAt":1659,"slug":1660,"status":28,"stem":1661,"summary":1662,"theme":171,"updatedAt":17,"__hash__":1663},"roadmap_en\u002Fen\u002Froadmap\u002Fperimetres-activites-critiques.md","Scopes and critical activities",{"type":8,"value":1608,"toc":1647},[1609,1611,1614,1616,1642,1644],[39,1610,42],{"id":41},[44,1612,1613],{},"Without a clear view of essential activities, you can't tell which vendors really matter.",[39,1615,50],{"id":49},[52,1617,1618,1624,1630,1636],{},[55,1619,1620,1623],{},[58,1621,1622],{},"Scopes"," describing your activities, services or entities.",[55,1625,1626,1629],{},[58,1627,1628],{},"Criticality rated"," and re-rated over time.",[55,1631,1632,1635],{},[58,1633,1634],{},"Vendors linked"," to each scope so you can prioritize your efforts.",[55,1637,1638,1641],{},[58,1639,1640],{},"Bulk import"," from a file.",[39,1643,83],{"id":82},[44,1645,1646],{},"CISOs and compliance leads who need to prioritize their controls.",{"title":11,"searchDepth":12,"depth":12,"links":1648},[1649,1650,1651],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Fperimetres-activites-critiques","---\nslug: perimetres-activites-critiques\ntitle: Scopes and critical activities\nsummary: Define the activities to protect, rate their criticality and link them to the vendors they depend on.\nstatus: shipped\nshippedAt: '2025-10-06'\ntheme: cartographie\n---\n\n### The problem\n\nWithout a clear view of essential activities, you can't tell which vendors really matter.\n\n### What changes\n\n- **Scopes** describing your activities, services or entities.\n- **Criticality rated** and re-rated over time.\n- **Vendors linked** to each scope so you can prioritize your efforts.\n- **Bulk import** from a file.\n\n### Who it's for\n\nCISOs and compliance leads who need to prioritize their controls.\n",[],[],{"title":1606,"description":11},"2025-10-06","perimetres-activites-critiques","en\u002Froadmap\u002Fperimetres-activites-critiques","Define the activities to protect, rate their criticality and link them to the vendors they depend on.","_Q6G1gitmwDIjteZw3aDcyRbw6bHUs6Eu0ORXdGyX7A",{"id":1665,"title":1666,"body":1667,"connectors":1671,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1672,"navigation":19,"path":1673,"period":17,"persona":21,"rawbody":1674,"regulations":1675,"relatedPages":1676,"seo":1677,"shippedAt":1326,"slug":1678,"status":28,"stem":1679,"summary":1680,"theme":109,"updatedAt":17,"__hash__":1681},"roadmap_en\u002Fen\u002Froadmap\u002Fpolitiques-securite.md","Security policies",{"type":8,"value":1668,"toc":1669},[],{"title":11,"searchDepth":12,"depth":12,"links":1670},[],[],{},"\u002Fen\u002Froadmap\u002Fpolitiques-securite","---\nslug: politiques-securite\ntitle: Security policies\nsummary: Write and maintain your security policies and their requirements in one shared, versioned space.\nstatus: shipped\nshippedAt: '2026-04-22'\ntheme: conformite\n---\n",[],[],{"title":1666,"description":11},"politiques-securite","en\u002Froadmap\u002Fpolitiques-securite","Write and maintain your security policies and their requirements in one shared, versioned space.","DeMFUJ9bHMgiP6-P6Lyme90JUFh-7XNyEWOz-CGs5Vo",{"id":1683,"title":1684,"body":1685,"connectors":1736,"description":11,"extension":15,"featured":19,"illustration":1737,"media":17,"meta":1738,"navigation":19,"path":1739,"period":163,"persona":21,"rawbody":1740,"regulations":1741,"relatedPages":1742,"seo":1743,"shippedAt":17,"slug":1744,"status":106,"stem":1745,"summary":1746,"theme":365,"updatedAt":17,"__hash__":1747},"roadmap_en\u002Fen\u002Froadmap\u002Fpreuves-liees-aux-reponses.md","Evidence linked to questionnaire answers",{"type":8,"value":1686,"toc":1731},[1687,1689,1692,1694,1726,1728],[39,1688,42],{"id":41},[44,1690,1691],{},"In a questionnaire, a \"yes\" is only worth the evidence behind it. Today you attach a PDF that starts ageing the moment it's sent, and the client has no way of knowing whether it's still current.",[39,1693,50],{"id":49},[52,1695,1696,1702,1708,1714,1720],{},[55,1697,1698,1701],{},[58,1699,1700],{},"Living evidence",": back an answer with a result from CISAPP's tools or your connected tools, always up to date.",[55,1703,1704,1707],{},[58,1705,1706],{},"The right evidence, suggested",": for each question, CISAPP proposes what you already have.",[55,1709,1710,1713],{},[58,1711,1712],{},"A trust badge",": your client can tell verified evidence from a plain statement.",[55,1715,1716,1719],{},[58,1717,1718],{},"Never out of date",": when evidence is about to expire, you hear about it before your client does.",[55,1721,1722,1725],{},[58,1723,1724],{},"You stay in control",": the client sees a dated attestation, not the sensitive details.",[39,1727,83],{"id":82},[44,1729,1730],{},"Suppliers who want to convince faster, and clients who want answers they can rely on.",{"title":11,"searchDepth":12,"depth":12,"links":1732},[1733,1734,1735],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"evidence",{},"\u002Fen\u002Froadmap\u002Fpreuves-liees-aux-reponses","---\nslug: preuves-liees-aux-reponses\ntitle: \"Evidence linked to questionnaire answers\"\nsummary: \"Back an answer with live evidence from your CISAPP tools or connectors instead of a static file. The customer sees a dated, verified attestation.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: evaluations\nregulations: [nis2, iso-27001]\nfeatured: true\nillustration: evidence\nrelatedPages: [questionnaire-securite-fournisseur]\n---\n\n### The problem\n\nIn a questionnaire, a \"yes\" is only worth the evidence behind it. Today you attach a PDF that starts ageing the moment it's sent, and the client has no way of knowing whether it's still current.\n\n### What changes\n\n- **Living evidence**: back an answer with a result from CISAPP's tools or your connected tools, always up to date.\n- **The right evidence, suggested**: for each question, CISAPP proposes what you already have.\n- **A trust badge**: your client can tell verified evidence from a plain statement.\n- **Never out of date**: when evidence is about to expire, you hear about it before your client does.\n- **You stay in control**: the client sees a dated attestation, not the sensitive details.\n\n### Who it's for\n\nSuppliers who want to convince faster, and clients who want answers they can rely on.\n",[100,102],[1184],{"title":1684,"description":11},"preuves-liees-aux-reponses","en\u002Froadmap\u002Fpreuves-liees-aux-reponses","Back an answer with live evidence from your CISAPP tools or connectors instead of a static file. The customer sees a dated, verified attestation.","myt94aAYIZo1_zlKVNBKDHgLDJFSTaahnIxx7f2kv_I",{"id":1749,"title":1750,"body":1751,"connectors":1755,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1756,"navigation":19,"path":1757,"period":17,"persona":21,"rawbody":1758,"regulations":1759,"relatedPages":1760,"seo":1761,"shippedAt":1762,"slug":1763,"status":28,"stem":1764,"summary":1765,"theme":31,"updatedAt":17,"__hash__":1766},"roadmap_en\u002Fen\u002Froadmap\u002Fprofil-et-onboarding.md","Profile and guided onboarding",{"type":8,"value":1752,"toc":1753},[],{"title":11,"searchDepth":12,"depth":12,"links":1754},[],[],{},"\u002Fen\u002Froadmap\u002Fprofil-et-onboarding","---\nslug: profil-et-onboarding\ntitle: Profile and guided onboarding\nsummary: New users fill in their profile and company in a few steps, then land straight in the platform.\nstatus: shipped\nshippedAt: '2025-06-13'\ntheme: plateforme\n---\n",[],[],{"title":1750,"description":11},"2025-06-13","profil-et-onboarding","en\u002Froadmap\u002Fprofil-et-onboarding","New users fill in their profile and company in a few steps, then land straight in the platform.","9L6GWRrh6vomRbkU93k6TgOxs7wcQUN1p4gh7KP_6_I",{"id":1768,"title":1769,"body":1770,"connectors":1821,"description":11,"extension":15,"featured":16,"illustration":1822,"media":17,"meta":1823,"navigation":19,"path":1824,"period":17,"persona":21,"rawbody":1825,"regulations":1826,"relatedPages":1827,"seo":1828,"shippedAt":1507,"slug":1829,"status":28,"stem":1830,"summary":1831,"theme":31,"updatedAt":17,"__hash__":1832},"roadmap_en\u002Fen\u002Froadmap\u002Fprojets-plans-d-action.md","Projects and action plans",{"type":8,"value":1771,"toc":1816},[1772,1774,1777,1779,1811,1813],[39,1773,42],{"id":41},[44,1775,1776],{},"Follow-up actions after a vendor assessment get lost in spreadsheets and messages. Nobody knows who owes what, or by when.",[39,1778,50],{"id":49},[52,1780,1781,1787,1793,1799,1805],{},[55,1782,1783,1786],{},[58,1784,1785],{},"One place"," for your internal projects and the action plans that come out of assessments.",[55,1788,1789,1792],{},[58,1790,1791],{},"Board view"," with tasks, owners, priorities and comments.",[55,1794,1795,1798],{},[58,1796,1797],{},"Connected to the rest of your setup",": vendors, scopes, risks, incidents and exemptions linked to each project.",[55,1800,1801,1804],{},[58,1802,1803],{},"Privacy tracking",": personal data involved, impact assessment status and retention period on each project.",[55,1806,1807,1810],{},[58,1808,1809],{},"Role-based access",": everyone sees and edits only what concerns them.",[39,1812,83],{"id":82},[44,1814,1815],{},"Security, compliance and procurement teams who need to turn assessment findings into actions tracked through to closure.",{"title":11,"searchDepth":12,"depth":12,"links":1817},[1818,1819,1820],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"board",{},"\u002Fen\u002Froadmap\u002Fprojets-plans-d-action","---\nslug: projets-plans-d-action\ntitle: Projects and action plans\nsummary: Track your projects and the action plans coming out of vendor assessments in one place, with tasks, owners and priorities.\nstatus: shipped\nshippedAt: '2026-09-24'\ntheme: plateforme\nillustration: board\n---\n\n### The problem\n\nFollow-up actions after a vendor assessment get lost in spreadsheets and messages. Nobody knows who owes what, or by when.\n\n### What changes\n\n- **One place** for your internal projects and the action plans that come out of assessments.\n- **Board view** with tasks, owners, priorities and comments.\n- **Connected to the rest of your setup**: vendors, scopes, risks, incidents and exemptions linked to each project.\n- **Privacy tracking**: personal data involved, impact assessment status and retention period on each project.\n- **Role-based access**: everyone sees and edits only what concerns them.\n\n### Who it's for\n\nSecurity, compliance and procurement teams who need to turn assessment findings into actions tracked through to closure.\n",[],[],{"title":1769,"description":11},"projets-plans-d-action","en\u002Froadmap\u002Fprojets-plans-d-action","Track your projects and the action plans coming out of vendor assessments in one place, with tasks, owners and priorities.","ADLvOo1HnLh78lpzA3AdNUGQWT9j2sYl4nOeF9767BQ",{"id":1834,"title":1835,"body":1836,"connectors":1881,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":1882,"navigation":19,"path":1883,"period":17,"persona":21,"rawbody":1884,"regulations":1885,"relatedPages":1886,"seo":1887,"shippedAt":1888,"slug":1889,"status":28,"stem":1890,"summary":1891,"theme":365,"updatedAt":17,"__hash__":1892},"roadmap_en\u002Fen\u002Froadmap\u002Fquestionnaires-securite.md","Security questionnaires",{"type":8,"value":1837,"toc":1876},[1838,1840,1843,1845,1871,1873],[39,1839,42],{"id":41},[44,1841,1842],{},"Each assessment starts from a different spreadsheet that is hard to compare across vendors.",[39,1844,50],{"id":49},[52,1846,1847,1853,1859,1865],{},[55,1848,1849,1852],{},[58,1850,1851],{},"Section-based editor"," to compose your own questionnaires.",[55,1854,1855,1858],{},[58,1856,1857],{},"Import of an existing questionnaire"," instead of retyping it.",[55,1860,1861,1864],{},[58,1862,1863],{},"AI-assisted answers"," and comments exchanged with the vendor.",[55,1866,1867,1870],{},[58,1868,1869],{},"Printing and tracking"," of answers to keep a record.",[39,1872,83],{"id":82},[44,1874,1875],{},"Security, compliance and procurement teams assessing their vendors.",{"title":11,"searchDepth":12,"depth":12,"links":1877},[1878,1879,1880],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Fquestionnaires-securite","---\nslug: questionnaires-securite\ntitle: Security questionnaires\nsummary: Build questionnaires section by section, import them from a file and send them to your vendors to answer.\nstatus: shipped\nshippedAt: '2025-03-23'\ntheme: evaluations\n---\n\n### The problem\n\nEach assessment starts from a different spreadsheet that is hard to compare across vendors.\n\n### What changes\n\n- **Section-based editor** to compose your own questionnaires.\n- **Import of an existing questionnaire** instead of retyping it.\n- **AI-assisted answers** and comments exchanged with the vendor.\n- **Printing and tracking** of answers to keep a record.\n\n### Who it's for\n\nSecurity, compliance and procurement teams assessing their vendors.\n",[],[],{"title":1835,"description":11},"2025-03-23","questionnaires-securite","en\u002Froadmap\u002Fquestionnaires-securite","Build questionnaires section by section, import them from a file and send them to your vendors to answer.","-n3oHKSAX76FhqaHc2dHQtRN63AsLo_m8znb5kBL3ww",{"id":1894,"title":1895,"body":1896,"connectors":1941,"description":11,"extension":15,"featured":16,"illustration":1942,"media":17,"meta":1943,"navigation":19,"path":1944,"period":17,"persona":21,"rawbody":1945,"regulations":1946,"relatedPages":1947,"seo":1948,"shippedAt":1949,"slug":1950,"status":28,"stem":1951,"summary":1952,"theme":109,"updatedAt":17,"__hash__":1953},"roadmap_en\u002Fen\u002Froadmap\u002Freferentiels-et-exigences.md","Frameworks and compliance requirements",{"type":8,"value":1897,"toc":1936},[1898,1900,1903,1905,1931,1933],[39,1899,42],{"id":41},[44,1901,1902],{},"Knowing where you stand against a framework means cross-checking dozens of documents.",[39,1904,50],{"id":49},[52,1906,1907,1913,1919,1925],{},[55,1908,1909,1912],{},[58,1910,1911],{},"Unified view",": measure register and tasks in one place.",[55,1914,1915,1918],{},[58,1916,1917],{},"Gap analysis"," with suggested measures to activate.",[55,1920,1921,1924],{},[58,1922,1923],{},"Proofs counted"," for each requirement.",[55,1926,1927,1930],{},[58,1928,1929],{},"New frameworks"," added regularly, including EASA Part-IS.",[39,1932,83],{"id":82},[44,1934,1935],{},"Compliance leads and CISOs preparing for a certification or an audit.",{"title":11,"searchDepth":12,"depth":12,"links":1937},[1938,1939,1940],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"frameworks",{},"\u002Fen\u002Froadmap\u002Freferentiels-et-exigences","---\nslug: referentiels-et-exigences\ntitle: Frameworks and compliance requirements\nsummary: Follow the requirements of your frameworks, spot gaps and activate suggested measures, with the number of linked proofs.\nstatus: shipped\nshippedAt: '2026-06-12'\ntheme: conformite\nillustration: frameworks\n---\n\n### The problem\n\nKnowing where you stand against a framework means cross-checking dozens of documents.\n\n### What changes\n\n- **Unified view**: measure register and tasks in one place.\n- **Gap analysis** with suggested measures to activate.\n- **Proofs counted** for each requirement.\n- **New frameworks** added regularly, including EASA Part-IS.\n\n### Who it's for\n\nCompliance leads and CISOs preparing for a certification or an audit.\n",[],[],{"title":1895,"description":11},"2026-06-12","referentiels-et-exigences","en\u002Froadmap\u002Freferentiels-et-exigences","Follow the requirements of your frameworks, spot gaps and activate suggested measures, with the number of linked proofs.","WZgRArVqos7W2iv82SCRam3Ge3I_WHLyBwmBaDs5u0A",{"id":1955,"title":1956,"body":1957,"connectors":2002,"description":11,"extension":15,"featured":16,"illustration":2003,"media":17,"meta":2004,"navigation":19,"path":2005,"period":17,"persona":21,"rawbody":2006,"regulations":2007,"relatedPages":2008,"seo":2009,"shippedAt":928,"slug":2010,"status":28,"stem":2011,"summary":2012,"theme":109,"updatedAt":17,"__hash__":2013},"roadmap_en\u002Fen\u002Froadmap\u002Fregistre-des-risques.md","Risk register",{"type":8,"value":1958,"toc":1997},[1959,1961,1964,1966,1992,1994],[39,1960,42],{"id":41},[44,1962,1963],{},"Risks are scattered across spreadsheets and meeting notes, with no shared scoring method.",[39,1965,50],{"id":49},[52,1967,1968,1974,1980,1986],{},[55,1969,1970,1973],{},[58,1971,1972],{},"Guided creation",", step by step.",[55,1975,1976,1979],{},[58,1977,1978],{},"Configurable methodology"," at organization level.",[55,1981,1982,1985],{},[58,1983,1984],{},"Tracked treatment",": measures, owners and status.",[55,1987,1988,1991],{},[58,1989,1990],{},"Links"," to the related vendors, incidents and projects.",[39,1993,83],{"id":82},[44,1995,1996],{},"CISOs, risk managers and compliance leadership.",{"title":11,"searchDepth":12,"depth":12,"links":1998},[1999,2000,2001],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"risk",{},"\u002Fen\u002Froadmap\u002Fregistre-des-risques","---\nslug: registre-des-risques\ntitle: Risk register\nsummary: Record, score and treat your risks in one place, with guided creation and your own scoring methodology.\nstatus: shipped\nshippedAt: '2026-04-21'\ntheme: conformite\nillustration: risk\n---\n\n### The problem\n\nRisks are scattered across spreadsheets and meeting notes, with no shared scoring method.\n\n### What changes\n\n- **Guided creation**, step by step.\n- **Configurable methodology** at organization level.\n- **Tracked treatment**: measures, owners and status.\n- **Links** to the related vendors, incidents and projects.\n\n### Who it's for\n\nCISOs, risk managers and compliance leadership.\n",[],[],{"title":1956,"description":11},"registre-des-risques","en\u002Froadmap\u002Fregistre-des-risques","Record, score and treat your risks in one place, with guided creation and your own scoring methodology.","TmWVAL0735NZ38jcHK2HbJ7VeXA4zXINmJlCmZwkTI0",{"id":2015,"title":2016,"body":2017,"connectors":2061,"description":11,"extension":15,"featured":16,"illustration":2062,"media":17,"meta":2063,"navigation":19,"path":2064,"period":17,"persona":21,"rawbody":2065,"regulations":2066,"relatedPages":2067,"seo":2068,"shippedAt":2069,"slug":2070,"status":28,"stem":2071,"summary":2072,"theme":171,"updatedAt":17,"__hash__":2073},"roadmap_en\u002Fen\u002Froadmap\u002Fregistre-fournisseurs.md","Vendor register",{"type":8,"value":2018,"toc":2056},[2019,2021,2024,2026,2051,2053],[39,2020,42],{"id":41},[44,2022,2023],{},"The vendor list lives in several files, with no owner and no history.",[39,2025,50],{"id":49},[52,2027,2028,2034,2039,2045],{},[55,2029,2030,2033],{},[58,2031,2032],{},"Complete record",": contacts, services, contract, business and security owners.",[55,2035,2036,2038],{},[58,2037,1972],{}," with company lookup by name or registration number.",[55,2040,2041,2044],{},[58,2042,2043],{},"Notes, tags and export"," to organize things your way.",[55,2046,2047,2050],{},[58,2048,2049],{},"Overview"," of action plans and ongoing assessments.",[39,2052,83],{"id":82},[44,2054,2055],{},"Procurement leads, CISOs and third-party risk managers.",{"title":11,"searchDepth":12,"depth":12,"links":2057},[2058,2059,2060],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"vendors",{},"\u002Fen\u002Froadmap\u002Fregistre-fournisseurs","---\nslug: registre-fournisseurs\ntitle: Vendor register\nsummary: Keep all your vendors in one place, with contacts, services, criticality and assessment history.\nstatus: shipped\nshippedAt: '2025-03-27'\ntheme: cartographie\nillustration: vendors\n---\n\n### The problem\n\nThe vendor list lives in several files, with no owner and no history.\n\n### What changes\n\n- **Complete record**: contacts, services, contract, business and security owners.\n- **Guided creation** with company lookup by name or registration number.\n- **Notes, tags and export** to organize things your way.\n- **Overview** of action plans and ongoing assessments.\n\n### Who it's for\n\nProcurement leads, CISOs and third-party risk managers.\n",[],[],{"title":2016,"description":11},"2025-03-27","registre-fournisseurs","en\u002Froadmap\u002Fregistre-fournisseurs","Keep all your vendors in one place, with contacts, services, criticality and assessment history.","QRCtQaeGbLpSCQP2e9LJrbfNkyosokiMFq7kp56FRlM",{"id":2075,"title":2076,"body":2077,"connectors":2081,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":2082,"navigation":19,"path":2083,"period":503,"persona":21,"rawbody":2084,"regulations":2085,"relatedPages":2086,"seo":2088,"shippedAt":17,"slug":2089,"status":106,"stem":2090,"summary":2091,"theme":109,"updatedAt":17,"__hash__":2092},"roadmap_en\u002Fen\u002Froadmap\u002Fregistre-information-dora.md","DORA register of information",{"type":8,"value":2078,"toc":2079},[],{"title":11,"searchDepth":12,"depth":12,"links":2080},[],[],{},"\u002Fen\u002Froadmap\u002Fregistre-information-dora","---\nslug: registre-information-dora\ntitle: DORA register of information\nsummary: Generate the register of information required by DORA straight from your vendor registry and mapping.\nstatus: planned\nperiod: '2026-Q4'\ntheme: conformite\nregulations: [dora]\nrelatedPages: [logiciel-conformite-dora-iso27001, dora]\n---\n",[101],[2087,101],"logiciel-conformite-dora-iso27001",{"title":2076,"description":11},"registre-information-dora","en\u002Froadmap\u002Fregistre-information-dora","Generate the register of information required by DORA straight from your vendor registry and mapping.","AOWTcmTG2SRVIngdSwxcZ3KmRUNRlX_n39IWxJa5Ku8",{"id":2094,"title":2095,"body":2096,"connectors":2141,"description":11,"extension":15,"featured":16,"illustration":2142,"media":17,"meta":2143,"navigation":19,"path":2144,"period":17,"persona":21,"rawbody":2145,"regulations":2146,"relatedPages":2148,"seo":2149,"shippedAt":2150,"slug":2151,"status":28,"stem":2152,"summary":2153,"theme":109,"updatedAt":17,"__hash__":2154},"roadmap_en\u002Fen\u002Froadmap\u002Fregistre-rgpd-violations.md","Processing register and data breach register",{"type":8,"value":2097,"toc":2136},[2098,2100,2103,2105,2131,2133],[39,2099,42],{"id":41},[44,2101,2102],{},"The processing register and the breach register often live in spreadsheets, far from the vendors that actually handle the data. When an incident hits, nobody can quickly tell who is affected or what to notify.",[39,2104,50],{"id":49},[52,2106,2107,2113,2119,2125],{},[55,2108,2109,2112],{},[58,2110,2111],{},"Processing register",": each processing activity is documented in the platform and linked to the vendors involved, both ways.",[55,2114,2115,2118],{},[58,2116,2117],{},"Breach register",": every incident is logged with its history and severity level.",[55,2120,2121,2124],{},[58,2122,2123],{},"Guided notification",": preparing the notification to the authority happens step by step.",[55,2126,2127,2130],{},[58,2128,2129],{},"Declared sub-processors",": the data processing agreement and downstream sub-processors show on the vendor record.",[39,2132,83],{"id":82},[44,2134,2135],{},"DPOs and legal teams, working with security and procurement.",{"title":11,"searchDepth":12,"depth":12,"links":2137},[2138,2139,2140],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"gdpr",{},"\u002Fen\u002Froadmap\u002Fregistre-rgpd-violations","---\nslug: registre-rgpd-violations\ntitle: Processing register and data breach register\nsummary: Keep your GDPR processing register and your breach register in the platform, linked to your vendors, with authority notification guided step by step.\nstatus: shipped\nshippedAt: '2026-07-08'\ntheme: conformite\nillustration: gdpr\nregulations: [rgpd]\n---\n\n### The problem\n\nThe processing register and the breach register often live in spreadsheets, far from the vendors that actually handle the data. When an incident hits, nobody can quickly tell who is affected or what to notify.\n\n### What changes\n\n- **Processing register**: each processing activity is documented in the platform and linked to the vendors involved, both ways.\n- **Breach register**: every incident is logged with its history and severity level.\n- **Guided notification**: preparing the notification to the authority happens step by step.\n- **Declared sub-processors**: the data processing agreement and downstream sub-processors show on the vendor record.\n\n### Who it's for\n\nDPOs and legal teams, working with security and procurement.\n",[2147],"rgpd",[],{"title":2095,"description":11},"2026-07-08","registre-rgpd-violations","en\u002Froadmap\u002Fregistre-rgpd-violations","Keep your GDPR processing register and your breach register in the platform, linked to your vendors, with authority notification guided step by step.","_ZaSK0eaK-G_wF4LWhTNVfkZZaGR9WfigNs6ixWPo8I",{"id":2156,"title":2157,"body":2158,"connectors":2208,"description":11,"extension":15,"featured":16,"illustration":2142,"media":17,"meta":2209,"navigation":19,"path":2210,"period":97,"persona":21,"rawbody":2211,"regulations":2212,"relatedPages":2213,"seo":2214,"shippedAt":17,"slug":2215,"status":106,"stem":2216,"summary":2217,"theme":109,"updatedAt":17,"__hash__":2218},"roadmap_en\u002Fen\u002Froadmap\u002Frgpd-avance.md","GDPR: DPIA, data subject requests and retention",{"type":8,"value":2159,"toc":2203},[2160,2162,2165,2167,2199,2201],[39,2161,42],{"id":41},[44,2163,2164],{},"The record of processing activities often lives on its own, disconnected from the vendors and tools actually in use. The result: forgotten subprocessors, invisible transfers outside the EU and impact assessments that are hard to keep current.",[39,2166,50],{"id":49},[52,2168,2169,2175,2181,2187,2193],{},[55,2170,2171,2174],{},[58,2172,2173],{},"A data map that reflects reality",": processing activities, applications, subprocessors and hosting countries in one place.",[55,2176,2177,2180],{},[58,2178,2179],{},"Guided impact assessments",": from the first screening to the DPO's opinion.",[55,2182,2183,2186],{},[58,2184,2185],{},"Transfers outside the EU spotted",": with their assessment prepared.",[55,2188,2189,2192],{},[58,2190,2191],{},"Data subject requests tracked",": public form, deadlines and template replies.",[55,2194,2195,2198],{},[58,2196,2197],{},"Inconsistencies flagged",": when a vendor's answer contradicts your record.",[39,2200,83],{"id":82},[44,2202,2135],{},{"title":11,"searchDepth":12,"depth":12,"links":2204},[2205,2206,2207],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Frgpd-avance","---\nslug: rgpd-avance\ntitle: \"GDPR: DPIA, data subject requests and retention\"\nsummary: \"Impact assessment workflow, data subject request register with deadlines, retention policies and a data map that flags transfers outside the EU.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: conformite\nregulations: [rgpd]\nillustration: gdpr\n---\n\n### The problem\n\nThe record of processing activities often lives on its own, disconnected from the vendors and tools actually in use. The result: forgotten subprocessors, invisible transfers outside the EU and impact assessments that are hard to keep current.\n\n### What changes\n\n- **A data map that reflects reality**: processing activities, applications, subprocessors and hosting countries in one place.\n- **Guided impact assessments**: from the first screening to the DPO's opinion.\n- **Transfers outside the EU spotted**: with their assessment prepared.\n- **Data subject requests tracked**: public form, deadlines and template replies.\n- **Inconsistencies flagged**: when a vendor's answer contradicts your record.\n\n### Who it's for\n\nDPOs and legal teams, working with security and procurement.\n",[2147],[],{"title":2157,"description":11},"rgpd-avance","en\u002Froadmap\u002Frgpd-avance","Impact assessment workflow, data subject request register with deadlines, retention policies and a data map that flags transfers outside the EU.","R-U0JPsEiepce2tK8A0Eqi2pZZfFwYYLj09yzZirUwU",{"id":2220,"title":2221,"body":2222,"connectors":2267,"description":11,"extension":15,"featured":16,"illustration":2003,"media":17,"meta":2268,"navigation":19,"path":2269,"period":97,"persona":21,"rawbody":2270,"regulations":2271,"relatedPages":2272,"seo":2273,"shippedAt":17,"slug":2274,"status":106,"stem":2275,"summary":2276,"theme":109,"updatedAt":17,"__hash__":2277},"roadmap_en\u002Fen\u002Froadmap\u002Frisque-avance.md","Advanced risk management",{"type":8,"value":2223,"toc":2262},[2224,2226,2229,2231,2257,2259],[39,2225,42],{"id":41},[44,2227,2228],{},"A risk register updated once a year doesn't steer anything. You need to know what level of risk is acceptable, and see quickly when you drift from it.",[39,2230,50],{"id":49},[52,2232,2233,2239,2245,2251],{},[55,2234,2235,2238],{},[58,2236,2237],{},"Your risk appetite, made explicit",": by category, with an alert as soon as a risk goes beyond it.",[55,2240,2241,2244],{},[58,2242,2243],{},"Indicators that stay alive",": each risk tracked by indicators that update automatically.",[55,2246,2247,2250],{},[58,2248,2249],{},"Suggested risks",": drawn from vendor assessments, compliance gaps and external monitoring.",[55,2252,2253,2256],{},[58,2254,2255],{},"Clear reporting",": before and after treatment, and the trend over time for management.",[39,2258,83],{"id":82},[44,2260,2261],{},"Risk managers, CISOs and risk committees.",{"title":11,"searchDepth":12,"depth":12,"links":2263},[2264,2265,2266],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],{},"\u002Fen\u002Froadmap\u002Frisque-avance","---\nslug: risque-avance\ntitle: \"Advanced risk management\"\nsummary: \"Risk appetite, risk indicators tracked over time, risks suggested from your assessments and monitoring, then the full EBIOS RM method.\"\nstatus: planned\nperiod: '2027-Q2'\ntheme: conformite\nregulations: [iso-27001]\nillustration: risk\nrelatedPages: [gestion-risque-fournisseur]\n---\n\n### The problem\n\nA risk register updated once a year doesn't steer anything. You need to know what level of risk is acceptable, and see quickly when you drift from it.\n\n### What changes\n\n- **Your risk appetite, made explicit**: by category, with an alert as soon as a risk goes beyond it.\n- **Indicators that stay alive**: each risk tracked by indicators that update automatically.\n- **Suggested risks**: drawn from vendor assessments, compliance gaps and external monitoring.\n- **Clear reporting**: before and after treatment, and the trend over time for management.\n\n### Who it's for\n\nRisk managers, CISOs and risk committees.\n",[102],[359],{"title":2221,"description":11},"risque-avance","en\u002Froadmap\u002Frisque-avance","Risk appetite, risk indicators tracked over time, risks suggested from your assessments and monitoring, then the full EBIOS RM method.","CQt7zbepIrrUtlVyOQaA5wvgcx9FcD3sT9H2BCbm-Ns",{"id":2279,"title":2280,"body":2281,"connectors":2326,"description":11,"extension":15,"featured":16,"illustration":2327,"media":17,"meta":2328,"navigation":19,"path":2329,"period":17,"persona":21,"rawbody":2330,"regulations":2331,"relatedPages":2332,"seo":2333,"shippedAt":17,"slug":2334,"status":281,"stem":2335,"summary":2336,"theme":171,"updatedAt":17,"__hash__":2337},"roadmap_en\u002Fen\u002Froadmap\u002Fsurface-d-attaque-exposee.md","Exposed attack surface",{"type":8,"value":2282,"toc":2321},[2283,2285,2288,2290,2316,2318],[39,2284,42],{"id":41},[44,2286,2287],{},"You can only protect what you know. Between forgotten subdomains, services exposed by mistake and fragile email configurations, the surface visible from the Internet often exceeds what teams have in mind.",[39,2289,50],{"id":49},[52,2291,2292,2298,2304,2310],{},[55,2293,2294,2297],{},[58,2295,2296],{},"Automatically discovered inventory",": exposed domains and assets listed in one place.",[55,2299,2300,2303],{},[58,2301,2302],{},"Scans limited to your assets",": a scan only runs once you have verified that you own the domain.",[55,2305,2306,2309],{},[58,2307,2308],{},"Live progress",": discovery and scans update on screen without a reload.",[55,2311,2312,2315],{},[58,2313,2314],{},"Readable reports",": findings, including email security, are presented clearly.",[39,2317,83],{"id":82},[44,2319,2320],{},"CISOs and security teams who need to demonstrate control over their exposure (NIS2, art. 21).",{"title":11,"searchDepth":12,"depth":12,"links":2322},[2323,2324,2325],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"attack-surface",{},"\u002Fen\u002Froadmap\u002Fsurface-d-attaque-exposee","---\nslug: surface-d-attaque-exposee\ntitle: Exposed attack surface\nsummary: Discover the domains and assets your organization exposes on the Internet, verify you own them, and follow scan progress live.\nstatus: in_progress\ntheme: cartographie\nillustration: attack-surface\nregulations: [nis2]\n---\n\n### The problem\n\nYou can only protect what you know. Between forgotten subdomains, services exposed by mistake and fragile email configurations, the surface visible from the Internet often exceeds what teams have in mind.\n\n### What changes\n\n- **Automatically discovered inventory**: exposed domains and assets listed in one place.\n- **Scans limited to your assets**: a scan only runs once you have verified that you own the domain.\n- **Live progress**: discovery and scans update on screen without a reload.\n- **Readable reports**: findings, including email security, are presented clearly.\n\n### Who it's for\n\nCISOs and security teams who need to demonstrate control over their exposure (NIS2, art. 21).\n",[100],[],{"title":2280,"description":11},"surface-d-attaque-exposee","en\u002Froadmap\u002Fsurface-d-attaque-exposee","Discover the domains and assets your organization exposes on the Internet, verify you own them, and follow scan progress live.","nYkBhrjzfzLQYJbavOKwemHRai3g16b4MuEIf_GfCcM",{"id":2339,"title":2340,"body":2341,"connectors":2345,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":2346,"navigation":19,"path":2347,"period":17,"persona":21,"rawbody":2348,"regulations":2349,"relatedPages":2350,"seo":2351,"shippedAt":17,"slug":2352,"status":362,"stem":2353,"summary":2354,"theme":365,"updatedAt":17,"__hash__":2355},"roadmap_en\u002Fen\u002Froadmap\u002Fsurveillance-externe-continue.md","Continuous external vendor monitoring",{"type":8,"value":2342,"toc":2343},[],{"title":11,"searchDepth":12,"depth":12,"links":2344},[],[],{},"\u002Fen\u002Froadmap\u002Fsurveillance-externe-continue","---\nslug: surveillance-externe-continue\ntitle: Continuous external vendor monitoring\nsummary: Complement self-declared assessments with external signals continuously observed on your vendors' exposed surface.\nstatus: exploring\ntheme: evaluations\nregulations: [nis2]\n---\n",[100],[],{"title":2340,"description":11},"surveillance-externe-continue","en\u002Froadmap\u002Fsurveillance-externe-continue","Complement self-declared assessments with external signals continuously observed on your vendors' exposed surface.","dZANEo43RW9bG3jzoFbj8k_4NBPyxzpEPJ2MBNcmhMo",{"id":2357,"title":2358,"body":2359,"connectors":2363,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":2364,"navigation":19,"path":2365,"period":17,"persona":21,"rawbody":2366,"regulations":2367,"relatedPages":2368,"seo":2369,"shippedAt":261,"slug":2370,"status":28,"stem":2371,"summary":2372,"theme":31,"updatedAt":17,"__hash__":2373},"roadmap_en\u002Fen\u002Froadmap\u002Ftableau-de-bord-ciso.md","CISO dashboard",{"type":8,"value":2360,"toc":2361},[],{"title":11,"searchDepth":12,"depth":12,"links":2362},[],[],{},"\u002Fen\u002Froadmap\u002Ftableau-de-bord-ciso","---\nslug: tableau-de-bord-ciso\ntitle: CISO dashboard\nsummary: Key indicators, peer-benchmarked scores and critical vendors up front, to read your posture at a glance.\nstatus: shipped\nshippedAt: '2026-07-01'\ntheme: plateforme\n---\n",[],[],{"title":2358,"description":11},"tableau-de-bord-ciso","en\u002Froadmap\u002Ftableau-de-bord-ciso","Key indicators, peer-benchmarked scores and critical vendors up front, to read your posture at a glance.","7E7BVcdGRmy2qj8sTNDJzTJUM5XvQpUfqteh3DEfqqE",{"id":2375,"title":2376,"body":2377,"connectors":2428,"description":11,"extension":15,"featured":19,"illustration":2429,"media":17,"meta":2430,"navigation":19,"path":2431,"period":503,"persona":21,"rawbody":2432,"regulations":2433,"relatedPages":2434,"seo":2435,"shippedAt":17,"slug":2436,"status":106,"stem":2437,"summary":2438,"theme":31,"updatedAt":17,"__hash__":2439},"roadmap_en\u002Fen\u002Froadmap\u002Ftableaux-de-bord-personnalises.md","Custom dashboards",{"type":8,"value":2378,"toc":2423},[2379,2381,2384,2386,2418,2420],[39,2380,42],{"id":41},[44,2382,2383],{},"The CISO, the DPO, procurement and the executive committee don't ask the same questions. Yet they all want the same thing: to know whether things are getting better, and where to act first.",[39,2385,50],{"id":49},[52,2387,2388,2394,2400,2406,2412],{},[55,2389,2390,2393],{},[58,2391,2392],{},"Your indicators, your dashboard",": build it in a few clicks from ready-made widgets.",[55,2395,2396,2399],{},[58,2397,2398],{},"Trends over time",": every indicator shows where it's heading, not just today's value.",[55,2401,2402,2405],{},[58,2403,2404],{},"Templates for every role",": CISO, DPO, procurement, executive committee, NIS2. Use them as they are or adapt them.",[55,2407,2408,2411],{},[58,2409,2410],{},"From number to action",": one click on an indicator opens the list of items behind it.",[55,2413,2414,2417],{},[58,2415,2416],{},"Reports that send themselves",": PDF export and scheduled delivery to management.",[39,2419,83],{"id":82},[44,2421,2422],{},"CISOs, DPOs, procurement leads and executives who steer third-party risk and compliance.",{"title":11,"searchDepth":12,"depth":12,"links":2424},[2425,2426,2427],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"dashboards",{},"\u002Fen\u002Froadmap\u002Ftableaux-de-bord-personnalises","---\nslug: tableaux-de-bord-personnalises\ntitle: \"Custom dashboards\"\nsummary: \"Build your own dashboards with historical indicators, targets and ready-made templates (CISO, DPO, Procurement, executive, NIS2), then export them or schedule delivery.\"\nstatus: planned\nperiod: '2026-Q4'\ntheme: plateforme\nfeatured: true\nillustration: dashboards\n---\n\n### The problem\n\nThe CISO, the DPO, procurement and the executive committee don't ask the same questions. Yet they all want the same thing: to know whether things are getting better, and where to act first.\n\n### What changes\n\n- **Your indicators, your dashboard**: build it in a few clicks from ready-made widgets.\n- **Trends over time**: every indicator shows where it's heading, not just today's value.\n- **Templates for every role**: CISO, DPO, procurement, executive committee, NIS2. Use them as they are or adapt them.\n- **From number to action**: one click on an indicator opens the list of items behind it.\n- **Reports that send themselves**: PDF export and scheduled delivery to management.\n\n### Who it's for\n\nCISOs, DPOs, procurement leads and executives who steer third-party risk and compliance.\n",[],[],{"title":2376,"description":11},"tableaux-de-bord-personnalises","en\u002Froadmap\u002Ftableaux-de-bord-personnalises","Build your own dashboards with historical indicators, targets and ready-made templates (CISO, DPO, Procurement, executive, NIS2), then export them or schedule delivery.","yxzWUsD3U62sGmH7o-Yp7N2CsvBtyoWBGUi4PZvOOdU",{"id":2441,"title":2442,"body":2443,"connectors":2447,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":2448,"navigation":19,"path":2449,"period":17,"persona":21,"rawbody":2450,"regulations":2451,"relatedPages":2452,"seo":2453,"shippedAt":2454,"slug":2455,"status":28,"stem":2456,"summary":2457,"theme":31,"updatedAt":17,"__hash__":2458},"roadmap_en\u002Fen\u002Froadmap\u002Ftheme-clair-sombre-langues.md","Light or dark theme and multilingual interface",{"type":8,"value":2444,"toc":2445},[],{"title":11,"searchDepth":12,"depth":12,"links":2446},[],[],{},"\u002Fen\u002Froadmap\u002Ftheme-clair-sombre-langues","---\nslug: theme-clair-sombre-langues\ntitle: Light or dark theme and multilingual interface\nsummary: Pick the light, dark or system theme and work in your team's language.\nstatus: shipped\nshippedAt: '2024-08-23'\ntheme: plateforme\n---\n",[],[],{"title":2442,"description":11},"2024-08-23","theme-clair-sombre-langues","en\u002Froadmap\u002Ftheme-clair-sombre-langues","Pick the light, dark or system theme and work in your team's language.","fgfD--hV5TQmPoBJs5m-znU3_GXNPBk6zGnMJ9qbpsM",{"id":2460,"title":2461,"body":2462,"connectors":2513,"description":11,"extension":15,"featured":16,"illustration":2514,"media":17,"meta":2515,"navigation":19,"path":2516,"period":163,"persona":21,"rawbody":2517,"regulations":2518,"relatedPages":2519,"seo":2520,"shippedAt":17,"slug":2521,"status":106,"stem":2522,"summary":2523,"theme":365,"updatedAt":17,"__hash__":2524},"roadmap_en\u002Fen\u002Froadmap\u002Ftrust-center-evolue.md","Enhanced Trust Center",{"type":8,"value":2463,"toc":2508},[2464,2466,2469,2471,2503,2505],[39,2465,42],{"id":41},[44,2467,2468],{},"Clients and prospects keep asking the same questions and requesting the same documents. Each request goes through an email, an internal sign-off and a manual send.",[39,2470,50],{"id":49},[52,2472,2473,2479,2485,2491,2497],{},[55,2474,2475,2478],{},[58,2476,2477],{},"A security showcase in your colours",": certifications, controls in place, subprocessors and updates on a public page.",[55,2480,2481,2484],{},[58,2482,2483],{},"Documents under control",": open access, on request, or after accepting a non-disclosure agreement.",[55,2486,2487,2490],{},[58,2488,2489],{},"Requests handled in one click",": manual or automatic approval, time-limited access.",[55,2492,2493,2496],{},[58,2494,2495],{},"An FAQ that stays current",": fed by your approved answers.",[55,2498,2499,2502],{},[58,2500,2501],{},"Sales signals",": who visits your page, and which documents your prospects care about.",[39,2504,83],{"id":82},[44,2506,2507],{},"Software vendors and service providers who regularly answer security questionnaires.",{"title":11,"searchDepth":12,"depth":12,"links":2509},[2510,2511,2512],{"id":41,"depth":90,"text":42},{"id":49,"depth":90,"text":50},{"id":82,"depth":90,"text":83},[],"trust-center",{},"\u002Fen\u002Froadmap\u002Ftrust-center-evolue","---\nslug: trust-center-evolue\ntitle: \"Enhanced Trust Center\"\nsummary: \"Publish certifications, controls, subprocessors and FAQ, and share documents publicly, on request or under NDA. CISAPP customers get access in one click.\"\nstatus: planned\nperiod: '2027-Q1'\ntheme: evaluations\nillustration: trust-center\nrelatedPages: [questionnaire-securite-fournisseur]\n---\n\n### The problem\n\nClients and prospects keep asking the same questions and requesting the same documents. Each request goes through an email, an internal sign-off and a manual send.\n\n### What changes\n\n- **A security showcase in your colours**: certifications, controls in place, subprocessors and updates on a public page.\n- **Documents under control**: open access, on request, or after accepting a non-disclosure agreement.\n- **Requests handled in one click**: manual or automatic approval, time-limited access.\n- **An FAQ that stays current**: fed by your approved answers.\n- **Sales signals**: who visits your page, and which documents your prospects care about.\n\n### Who it's for\n\nSoftware vendors and service providers who regularly answer security questionnaires.\n",[],[1184],{"title":2461,"description":11},"trust-center-evolue","en\u002Froadmap\u002Ftrust-center-evolue","Publish certifications, controls, subprocessors and FAQ, and share documents publicly, on request or under NDA. CISAPP customers get access in one click.","NGUBONErO6V3YrCfvocN0hOwPvZx4s6sXcxEbmUTVio",{"id":2526,"title":2527,"body":2528,"connectors":2532,"description":11,"extension":15,"featured":16,"illustration":17,"media":17,"meta":2533,"navigation":19,"path":2534,"period":17,"persona":21,"rawbody":2535,"regulations":2536,"relatedPages":2537,"seo":2538,"shippedAt":17,"slug":2539,"status":362,"stem":2540,"summary":2541,"theme":31,"updatedAt":17,"__hash__":2542},"roadmap_en\u002Fen\u002Froadmap\u002Fveille-ia.md","AI-assisted tailored monitoring",{"type":8,"value":2529,"toc":2530},[],{"title":11,"searchDepth":12,"depth":12,"links":2531},[],[],{},"\u002Fen\u002Froadmap\u002Fveille-ia","---\nslug: veille-ia\ntitle: \"AI-assisted tailored monitoring\"\nsummary: \"Cyber and regulatory monitoring filtered on your vendors, technologies and sector, with one-click actions.\"\nstatus: exploring\ntheme: plateforme\nrelatedPages: [cybersecurite-supply-chain]\n---\n",[],[167],{"title":2527,"description":11},"veille-ia","en\u002Froadmap\u002Fveille-ia","Cyber and regulatory monitoring filtered on your vendors, technologies and sector, with one-click actions.","3JMeAcvKdEy4-pmcNfKpIBEMV42kdJxXGuTteRsVex8",[2544,2548,2552,2556,2560,2564,2568,2572],{"label":2545,"to":2546,"description":2547},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":2549,"to":2550,"description":2551},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":2553,"to":2554,"description":2555},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":2557,"to":2558,"description":2559},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":2561,"to":2562,"description":2563},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":2565,"to":2566,"description":2567},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":2569,"to":2570,"description":2571},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":2573,"to":2574,"description":2575},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[2577,2581,2585,2589,2593,2597,2601],{"label":2578,"to":2579,"description":2580},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":2582,"to":2583,"description":2584},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":2586,"to":2587,"description":2588},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":2590,"to":2591,"description":2592},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":2594,"to":2595,"description":2596},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":2598,"to":2599,"description":2600},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":2602,"to":2603,"description":2604},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[2606,2610,2614,2618,2622,2626],{"label":2607,"to":2608,"description":2609},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":2611,"to":2612,"description":2613},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":2615,"to":2616,"description":2617},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":2619,"to":2620,"description":2621},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":2623,"to":2624,"description":2625},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":2627,"to":2628,"description":2629},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[2631,2635,2639],{"label":2632,"to":2633,"description":2634},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":2636,"to":2637,"description":2638},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":2640,"to":2641,"description":2642},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",1791391140152]