Actions

On your schedule,
the ticket opens itself.

Connect the tools your team already works in, and an action opens a GitHub, GitLab or Jira ticket, or sends a Slack message, from a template you write. It runs on a schedule you set, or when you trigger it by hand. You see every run, with a link to the ticket it created, and you can switch any action off.

Start for freeBook a conversation
++++
app.devguard.ch / workflows
8 active
248
runs this week
Active workflows
PR → evidence
Control drift alert
Vendor review due
Workflow · PR merged → evidence
event
PR merged
condition
Touches prod
action
Capture evidence
Recent runs
acme-app/web · #4821just nowCaptured
billing-svc · #119014m agoCaptured
prod-api · #33071h agoCaptured
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Connect, schedule, run.

An action is a template you write that creates a ticket or a message, set to run on a schedule or when you trigger it.

01

Connect a tool

Connect GitHub, GitLab, Jira or Slack. An action creates a ticket or sends a message in a tool you connect, not by scanning your cloud, so you always know what it did and where.

02

Write the template and set the schedule

Write the ticket or message the action sends, then set it to run on a schedule, like every quarter, or leave it to run when you trigger it by hand.

A template, then a schedule

An action is a template you write plus a schedule you set. It opens a GitHub, GitLab or Jira ticket, or sends a Slack message, so you know exactly what each run will create.

03

Run it, see the run

On its schedule or when you trigger it, the action creates the ticket or message, and the run shows up in the list with a link to it and the time it ran. Switch any action on or off without touching the others.

Why it’s built this way

Runs you can read, on your schedule.

Four choices behind how actions work here, each one something you can check, not an adjective.

01

Runs on your schedule

An action runs on a schedule you set, or when you trigger it by hand. Every trigger is one you defined, so nothing fires that you didn’t set up.

02

Creates a ticket or a message you can read

Each action opens a GitHub, GitLab or Jira ticket, or sends a Slack message, from a template you write. A run is never a black box; you see exactly what it created.

03

Each action toggles on its own

Actions are individually switchable, so you can turn one off without disabling the rest, and roll one out before you enable the next.

04

Every run links to the real ticket

Recent runs show the source, the time and a link to the ticket or message they created, so at audit you can show exactly what ran and where it landed.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where actions connect.

An action doesn’t act in isolation. It opens a ticket, moves a risk forward, hits a deadline or hands off to the assistant, all in the same workspace.

2.0SCORE

Risks

Let a finding open a risk and move it toward treatment.

JUN
ISO review
in 3 days

Deadlines

Turn a recurring action into a dated reminder with an owner.

342
artifacts captured
linked to controls

Evidence

Capture proof and attach it to the control it satisfies.

drafting…

AI assistant

Hand a summary or a draft to the assistant to review.

FAQ

The questions evaluators ask.

Do actions scan my cloud automatically?

No. Actions run on a schedule you set, or when you trigger them yourself. They create a ticket or send a Slack message in a tool you connect, like GitHub, GitLab, Jira and Slack. They do not scan your cloud accounts in the background, which is why you can see exactly what every run created.

What can an action actually do?

It opens a GitHub, GitLab or Jira ticket, or sends a Slack message, from a template you write. You set it to run on a schedule or trigger it by hand, and each run shows up in the list with a link to the ticket or message it created.

What’s the difference between a treatment action and an integration action?

A treatment action remediates a specific risk or finding and is tracked to closure in the register. An integration action creates a ticket or Slack message in a connected tool, on a schedule or when you run it. Both live in the same workspace; they’re just triggered differently.

How is this different from a spreadsheet or another GRC tool?

A spreadsheet won’t open a ticket for you, and many GRC tools react by scanning your cloud and surfacing alerts you then reconcile by hand. Here, an action runs on your schedule or when you trigger it, creates a ticket or message in a tool you connect, and lists the run with a link to it.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your actions and their run history are yours, exportable to CSV at any time, with no lock-in.

Let the ticket open on its own schedule.

Connect a tool, write the template, set the schedule, and let the action open the ticket or send the message, with every run listed so you can show exactly what it created.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free