NEWdevguard CLI

Your Compliance Platform.
Always Audit Ready.

Run audits, policies, assets and risks from one workspace that stays audit-ready as you work. Start free in minutes — no sales call to get going.

Start for freeBook a conversation
ISO 27001
ISO 27001
SOC 2
SOC 2
GDPR
GDPR
HIPAA
HIPAA

Information Security Management System

0%

Security Governance Framework

Establish an ISMS with defined scope, roles, and objectives for security management

ISO/IEC 27001 > 4.3

Leadership Commitment

Senior management must support and demonstrate commitment to information security

ISO/IEC 27001 > 5.1

Risk Management Process

NIST CSF > ID.RA-5

Policy Documentation

SOC 2 > CC1.2

Continuous Improvement

ISO/IEC 27001 > 10.2

Internal Audit

ISO/IEC 27001 > 9.2
Every framework
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • Swiss nFADP
Who it’s for

However you run compliance

The same workspace, seen through your job. Whether you run compliance for many clients, hold a certificate of your own, or keep evidence next to the code — pick the path that sounds like this week.

Consultancies, vCISOs & MSPs

Every client mandate in one workspace, each client isolated — we don’t consult and we don’t resell

For consultancies

Certified companies

Stay audit-ready year-round — the gap list months out of the surveillance audit, not the week before

For certified companies

Engineering teams & CTOs

Bring evidence next to the work in GitHub, GitLab, Jira and Slack, connected through tools you control

For engineering teams

More than one fits? Most do. Pick the one closest to this week — the path only changes what we talk about first, not what you get.

The platform

One workspace,
every part of your ISMS.

The whole ISMS and GRC workload, from coverage and policies to risks, audits, evidence and reports, in one place, not twelve invoices. Each part links to the next, so the proof sits next to the control it satisfies.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Map one control set and point every framework at it.

policyv1.3
access_control {
require mfa = true
}

Policies

Version and approve every policy, mapped to its controls.

coverage86%

Coverage

Track control coverage and surface gaps months early.

Management review
RE-014 · Meeting minutes
v1v2v3 · final

Records

The documents your ISMS produces, versioned when final.

See all modules

Frameworks

Map once, comply everywhere.

Maintain one control set and point every standard at it. ISO 27001, SOC 2, GDPR, NIST CSF, PCI DSS and more reuse the controls and evidence you already keep. You map each control once, so the second framework costs a fraction of the first.

See full platform

Risk

61 Risks Occurred
High2
Medium16
Low43

ISO/IEC 27001:2022

34 Controls Completed
37%
34 Controls93 Total

Policies

28 Added
Approved18Down from 23
Needs Revision4Remaining

What you can do

Built for the everyday,
not just the audit.

The day-to-day an ISMS actually is — risks worked, policies kept current, evidence linked to its control, coverage watched.

Find risks that matter

Score issues by impact and work the high-impact few first.

Versioned policies

Author, approve and map every policy to the controls it satisfies.

CTO
Owner
Internal
Classification
Access Ticket
Description
Create Collection Run

Evidence by its control

Link proof to the control it satisfies, ready before the audit.

Controls
Last 30 Days
+1.6%
324
Controls Added
Total 61
+2.4%
Controls Completed
Total 26
-7.3%

Coverage at a glance

See what’s met and where the gaps are, across every framework.

Integrations

Connects to the tools your team already lives in.

Two-way sync with GitHub, GitLab, Jira and Slack keeps evidence and alerts next to the work, and automated read-only checks across 48 more tools turn configuration into evidence on your controls.

GitHubGitLabJira
EvidenceAuditSlack

And many more integrations

Why devguard

Four things we mean literally.

Not a metrics wall — we’re early and won’t invent numbers. The differentiators we can stand behind today:

01

Native, one price, no bolt-ons

Coverage, policies, risks, audits and reports are one product, not a separate invoice each — the ISMS core is the thing you pay for.

02

Swiss-hosted, on-prem possible, no lock-in

You control where the data sits, in German and English, and it exports in full whenever you ask.

About Swiss hosting
03

Your methodology, not a method imposed

Bring your own controls, custom frameworks and review cadence; devguard is where the work lives, whether that’s one company or many clients.

04

What we connect, we connect for real

Evidence flows from the tools you connect, and your policies stay yours to write. We only claim the integrations we actually ship — today that includes automated read-only checks across your cloud and stack, every check listed in the open.

How we start

We move the first one across, by hand.

No empty workspace handed over. We migrate your first ISMS into devguard ourselves, fixed scope, fixed date, founder-run, and nothing switches over until you’ve checked it side by side. Then you run from there, and your data exports in full whenever you want it.

01 · Fixed scope

We scope the first move together

We agree exactly what the first migration covers, which frameworks and how much evidence, so there’s no open-ended engagement.

02 · Founder-run

We migrate it for you

The founder moves the ISMS from wherever it lives today, whether another tool, spreadsheets, Word or Confluence, on an agreed schedule, not a ticket queue.

03 · You verify, then run

Nothing switches until you sign off

You check the auditor-facing trail side by side. When you’re satisfied it’s intact, you’re live and you run from there.

Book a conversation
Swiss made software

Swiss precision. Global compliance.

Built with the precision and reliability Switzerland is known for, and hosted here too. A strong fit for teams meeting strict European standards like ISO 27001 and GDPR — where data privacy isn't a nice-to-have.

Bring your whole ISMS into one workspace.

Map your controls once, reuse the evidence across every standard you hold, and keep an organisation audit-ready year-round. Start free, or book a short, peer-to-peer conversation and we’ll be straight about whether devguard fits.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free