Platform

Everything your ISMS needs, in one place.

Registers, roles, audit trails, review workflows, and reporting - built specifically around ISO/IEC 27001, not bolted on afterward.

Registers

Four registers, live today.

Each register comes with ownership, classification, scheduled reviews, and a complete history - no add-ons required.

Live

Asset Register

A single, current catalogue of everything that needs protecting - hardware, software, data, people, and services - with clear ownership.

Full asset catalogue

Hardware, software, data, people, and services in one searchable inventory.

Ownership & classification

Every asset has a named owner and a classification level.

CIA ratings

Confidentiality, Integrity, and Availability rated Low / Medium / High per asset.

Scheduled reviews

3, 6, or 12-month review cycles configured per asset or asset type.

Full change history

Non-destructive history - every edit is recorded, nothing is overwritten.

Export & filters

Excel/CSV export plus search and filters across every field.

Live

Risk Register

Catalogue risks against your assets, score them consistently, and track treatment through to closure.

Risk catalogue

Category, threat, and vulnerability captured for every risk.

Likelihood × impact scoring

Consistent Low / Medium / High / Critical scoring across the register.

Treatment tracking

Accept, Mitigate, Transfer, or Avoid - tracked with an owner and plan.

Residual risk comparison

Before-and-after view of risk once treatment is applied.

Status flow

Open → In Treatment → Closed, visible at a glance.

Linked to assets

Every risk ties back to the asset(s) it affects.

Live

Incident Register

Capture, triage, and close out information security incidents with a full audit trail from first report to resolution.

Incident logging

Capture type, severity, discovery date, and affected assets in one record.

Severity & impact scoring

Classify incidents Low / Medium / High / Critical for consistent triage.

Triage workflow

Open → Investigating → Contained → Closed, visible at a glance.

Root cause & corrective actions

Document root cause and link corrective actions through to closure.

Full audit trail

Every update timestamped and attributed - nothing is overwritten.

Linked to assets & risks

Every incident ties back to the assets and risks it affects.

Live

Supplier Register

Track supplier risk, due diligence, and contractual security requirements in one place.

Supplier catalogue

A central record of every supplier, with contact and contract details.

Risk scoring

Rate suppliers Low / Medium / High based on data access and criticality.

Due diligence tracking

Record onboarding checks, certifications, and review dates.

Contractual security requirements

Track clauses, SLAs, and security commitments per supplier.

Scheduled reviews

Periodic reassessment cycles configured per supplier.

Linked to assets & risks

Every supplier ties back to the assets and risks it touches.

Access & roles

A two-layer access model, down to the record.

A module must be enabled for your organisation and a user must be individually granted access before they can see it.

Role What they can do
ISMS Administrator Owns the ISMS day-to-day - manages registers, assigns record ownership, runs reviews, and grants Standard Users access to specific modules and records.
Standard User Works within the modules and records they've been granted - updating assets, risks, or actions they own, without visibility into the rest of the system.
Auditability

A record history that even admins can't rewrite.

Every change is captured permanently, so your evidence trail is exactly what an auditor expects to see - no gaps, no silent edits.

Field-level change detail

Old value → new value, captured for every field on every record.

Actor + timestamp on every entry

Know exactly who changed what, and when.

Immutable history

History entries can't be edited or deleted — not even by System Administrators.

Cross-register audit log

Search history across Asset, Risk, and every future register from one place.

Field: Owner
Field: CIA Rating
Field: Status
Field: Classification
Review workflows

Reviews that run themselves - until you need to step in.

Configure once, and let the platform chase the follow-through.

Configurable cycles

Set review cycles per record - 3, 6, or 12 months.

Automated reminders

Owners are reminded automatically as a review date approaches.

Overdue escalation

Overdue items escalate to administrators so nothing sits idle.

Outcome capture

Recording a review outcome automatically sets the next review date.

Support & reporting

Visibility for your team, help when you need it.

In-app ticketing

Raise tickets with priority and attachments, and follow threaded updates through to resolution.

OpenIn ProgressClosed

Dashboards & reporting

Filterable views across registers so admins can see status, ownership, and risk exposure at a glance.

Review reports

Purpose-built reports for upcoming and overdue reviews, ready to export ahead of an audit.

What's next

The platform is built to grow with your ISMS.

Two more registers are planned next.

Policy Register

Coming soon

Centralise policy versions, approvals, and review cycles.

Clause 5.2 / A.5.1

Statement of Applicability

Coming soon

Track applicable controls and justification in one living document.

Clause 6.1.3(d)

See ISO 360 Plus on your own data.

Create an account, enable Asset and Risk Registers, and invite your team today.