Registers, roles, audit trails, review workflows, and reporting - built specifically around ISO/IEC 27001, not bolted on afterward.
Each register comes with ownership, classification, scheduled reviews, and a complete history - no add-ons required.
A single, current catalogue of everything that needs protecting - hardware, software, data, people, and services - with clear ownership.
Hardware, software, data, people, and services in one searchable inventory.
Every asset has a named owner and a classification level.
Confidentiality, Integrity, and Availability rated Low / Medium / High per asset.
3, 6, or 12-month review cycles configured per asset or asset type.
Non-destructive history - every edit is recorded, nothing is overwritten.
Excel/CSV export plus search and filters across every field.
Catalogue risks against your assets, score them consistently, and track treatment through to closure.
Category, threat, and vulnerability captured for every risk.
Consistent Low / Medium / High / Critical scoring across the register.
Accept, Mitigate, Transfer, or Avoid - tracked with an owner and plan.
Before-and-after view of risk once treatment is applied.
Open → In Treatment → Closed, visible at a glance.
Every risk ties back to the asset(s) it affects.
Capture, triage, and close out information security incidents with a full audit trail from first report to resolution.
Capture type, severity, discovery date, and affected assets in one record.
Classify incidents Low / Medium / High / Critical for consistent triage.
Open → Investigating → Contained → Closed, visible at a glance.
Document root cause and link corrective actions through to closure.
Every update timestamped and attributed - nothing is overwritten.
Every incident ties back to the assets and risks it affects.
Track supplier risk, due diligence, and contractual security requirements in one place.
A central record of every supplier, with contact and contract details.
Rate suppliers Low / Medium / High based on data access and criticality.
Record onboarding checks, certifications, and review dates.
Track clauses, SLAs, and security commitments per supplier.
Periodic reassessment cycles configured per supplier.
Every supplier ties back to the assets and risks it touches.
A module must be enabled for your organisation and a user must be individually granted access before they can see it.
| Role | What they can do |
|---|---|
| ISMS Administrator | Owns the ISMS day-to-day - manages registers, assigns record ownership, runs reviews, and grants Standard Users access to specific modules and records. |
| Standard User | Works within the modules and records they've been granted - updating assets, risks, or actions they own, without visibility into the rest of the system. |
Every change is captured permanently, so your evidence trail is exactly what an auditor expects to see - no gaps, no silent edits.
Old value → new value, captured for every field on every record.
Know exactly who changed what, and when.
History entries can't be edited or deleted — not even by System Administrators.
Search history across Asset, Risk, and every future register from one place.
Configure once, and let the platform chase the follow-through.
Set review cycles per record - 3, 6, or 12 months.
Owners are reminded automatically as a review date approaches.
Overdue items escalate to administrators so nothing sits idle.
Recording a review outcome automatically sets the next review date.
Raise tickets with priority and attachments, and follow threaded updates through to resolution.
Filterable views across registers so admins can see status, ownership, and risk exposure at a glance.
Purpose-built reports for upcoming and overdue reviews, ready to export ahead of an audit.
Two more registers are planned next.
Centralise policy versions, approvals, and review cycles.
Clause 5.2 / A.5.1Track applicable controls and justification in one living document.
Clause 6.1.3(d)Create an account, enable Asset and Risk Registers, and invite your team today.