Platform

Your whole ISMS,
in one workspace.

devguard runs your information security management system in a single workspace — frameworks, policies, risks, evidence, audits and the rest, all connected to each other. Each part is a module you can go deep on, and they share one set of controls underneath, so the work you do in one place shows up everywhere it matters.

Start for freeBook a conversation
++++
app.devguard.ch / dashboard
Audit Ready
ISMS Posture
Compliance posture
68%
compliant
Open risks61
High02
Medium16
Low43
Information Security Management System
34 / 93 controls
Security Governance Framework
ISO 27001 · 4.3
Leadership Commitment
ISO 27001 · 5.1
Risk Management Process
NIST · ID.RA-5
Policy Documentation
in progress
Continuous Improvement
ISO 27001 · 10.2
ISO 2700137%
SOC 252%
GDPR71%
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
The modules

Every part of your ISMS.

Twenty-four modules, one workspace — each a focused area you can open and go deep on, all reading from the same control set so nothing is maintained twice.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Map one control set and point every framework at it.

policyv1.3
access_control {
require mfa = true
}

Policies

Version and approve every policy, mapped to its controls.

coverage86%

Coverage

Track control coverage and surface gaps months early.

Management review
RE-014 · Meeting minutes
v1v2v3 · final

Records

The documents your ISMS produces, versioned when final.

AKCan we accept this one? @m-rossi
MRTreating it instead, see the action
on the record, not in a chat thread

Comments

Discussion attached to the item it’s about, logged.

Vehicle check · monthly
Warning triangle1
Headlights and signalsok
Defibrillator battery>80%
Submitted 07:42

Processes

Checklists and report forms, each run stored as a dated submission.

AKCEO
MRCISO
DPDPO

People

Members, roles and access, with the org chart auditors ask for.

2.0SCORE

Risks

Score, treat and review risks from one register.

AWAWSReviewed
CFCloudflareReviewed
StStripe

Vendors

Keep every third-party review on time.

1,284
assets tracked
+12 today

Assets

One inventory — the scope your controls map to.

HighINC-007
Phishing compromise
InvestigatingArt. 33 · 54h left

Incidents

From detection to closure, with the breach clock in view.

5 of 6 checks pass · 41 min ago

Device management

Every company laptop measured hourly against your baseline.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Run internal audits and carry findings to closure.

342
artifacts captured
linked to controls

Evidence

Proof mapped to the control it satisfies.

86%
Shared with
JDAKMR+3

Reports

Ten PDF reports, straight from the workspace.

Do you encrypt at rest?library
Is MFA enforced?library
94 approved answers reusable

Security questionnaires

Answer customer questionnaires from a reusable library.

ISO 27001 · certifiedSOC 2 · 84%
GET/api/trust/trust_a1B2c3…
public · rendered by your site

Trust Center

Publish your posture as an API your own site renders.

EventPR merged
ActionEvidence captured

Actions

Run an action on a schedule, or when you trigger it.

drafting…

AI assistant

An optional draft you review and own.

JUN
ISO review
in 3 days

Deadlines

Every review and renewal on one calendar.

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

One worklist for the work toward audit-ready.

ISO 27001audit-ready · Oct 24
W1W2W3W4W5

Roadmap

Open tasks on a timeline, planned toward a target date.

Security awareness · 22 min
I have completed this training14:52 / 22:00

Trainings

Assign trainings and record each completion by person.

JLemployee
Up next
Policyread and confirm
Training22 min · due in 9 days
Devicefix the screen lock

Employee portal

Where employees complete what is assigned to them, and nothing else.

Why it’s built this way

Four choices, not four adjectives.

What’s true across every module here — each one something you can check before you commit.

01

Native, one price, no bolt-ons

Every module runs inside devguard — no separate add-on to buy for one part of the work. One product, one set of controls, one price.

02

Swiss-hosted, yours to export, no lock-in

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours, exportable to CSV and PDF at any time.

03

Your methodology, across every mandate

Bring your own controls, custom frameworks and review cadence. devguard fits how you already run your ISMS instead of forcing one fixed process.

04

Honest about what it doesn’t do

It does the ISMS work, from frameworks and risk to evidence and audits, and is clear about its boundaries rather than implying coverage it doesn’t have.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

Run your whole ISMS from one workspace.

Bring your frameworks, policies, risks and evidence into one connected place, and maintain your control set once instead of rebuilding it before every audit.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free