devguard - Your Compliance Platform
PlatformSolutionsFrameworksDevelopersPricing
devguard

One workspace for your whole ISMS — Swiss-hosted, one control set, mapped to every framework you run.

All systems operational
Product
PlatformFeaturesSolutionsFrameworksPricing
Developers
API & CLIIntegrationsDocumentationChangelogSwiss hosting
Company
AboutBlogCompare
© 2026 devguard AG. All rights reserved.
Terms of servicePrivacy policySite noticeTrust centerLLM info
Swiss Made Software
Comments

The discussion lives
next to the decision.

Every control, risk, policy, vendor, incident and audit carries a Comments tab, so the argument about a decision sits on the thing it was about instead of in someone’s inbox. Mention a colleague and they get a notification and an email, replies go one level deep so a conversation still reads in order months later, and the item’s history shows who joined it and when.

++++
app.devguard.ch / risks / RSK-014
3 comments
Discussed on
Risks24
Controls18
Vendors11
Audits06
Mentions reach people by email
Supplier outage · residual risk
RSK-014
AK
A. Klein2 days ago
Vendor renewed on a new sub-processor list, so the residual score no longer matches @m-rossi can you confirm before the review?
MR
M. Rossi1 day agoreply
Confirmed. Treating rather than accepting — action ACT-042 is open with a Q3 due date
TS
T. Schmid4 hours ago
Read-only on this one, but noting it for the management review
Anyone who can read the record can join the thread — every post, edit and delete lands in the audit log
Every framework
How it works

In place, one reply deep, logged.

A comment sits on the item it is about, replies go one level deep, and every change to a comment is written to that item’s history.

01

Every item has a Comments tab.

Controls, risks, treatment actions, policies, vendors, evidence, incidents, audits, records and your collections all carry a Comments tab on their detail view, 28 kinds of item in all. Frameworks are the deliberate exception, because a centralized framework is shared across every tenant.

02

Conversations that still read in order.

Reply to a comment and the answer nests under it. You cannot reply to a reply, so a conversation stays two levels and reads top to bottom. Comments carry bold, italic, underline and lists, and you can edit or delete your own. An edited comment is marked as edited, and deleting one that has replies leaves a placeholder so the answers underneath keep their context.

03

Mention the person who needs to answer.

Type @ and pick a colleague, up to ten in one comment. They get an in-app notification and an email, as does the author of a comment you reply to. Each person sets the cadence per category in their notification settings: as it happens, one weekly digest, or off.

Read access is enough to ask a question.

Comments follow the visibility of the item they sit on, and writing one needs read permission rather than update permission. So the person who can see a risk but not change it can still ask what a treatment decision was based on, and the answer stays on the risk.

Why it’s built this way

Built to still make sense in a year.

Four choices behind how comments work here — each one something you can check, not an adjective.

01

On 28 kinds of item across the platform.

Controls, risks, treatment actions, threat and vulnerability classes, reviews of every kind, assets, policies, vendors, questionnaires, evidence, actions, tasks, incidents, audits, records and the six collections each carry a Comments tab. Frameworks are deliberately left out, because a centralized framework is shared across every tenant.

02

One reply deep, on purpose.

You reply to a comment, and that is as far as it goes. Nesting stops at one level so a conversation reads top to bottom, and deleting a comment that has replies leaves a placeholder rather than orphaning the answers under it.

03

Read permission is enough to ask.

Visibility follows the item, and commenting needs read permission rather than update permission. Someone who can only read a risk can still ask about it, which is how the question reaches the owner instead of going into a side channel.

04

Comment activity lands in the item’s history.

Creating, editing and deleting a comment each write an entry against the item, so the history shows who joined the discussion and when. The comment body itself stays out of that entry, so the audit trail never becomes a second copy of the conversation.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

One module of the platform

Where comments show up.

A Comments tab rides along with the items you already work in, from controls and risks to policies and the audits that review them.

FAQ

The questions evaluators ask.

Which items can I comment on?

28 kinds, from controls, risks and treatment actions to policies, vendors, evidence, incidents, audits, records, questionnaires and the six collections. Frameworks are the deliberate exception: a centralized framework is shared across every tenant, so a discussion on it would not belong to one organization. Trainings, people and business roles have no Comments tab today.

Who can see a comment, and who can I mention?

Anyone who can read the item. Visibility follows it, and writing a comment needs read permission rather than update permission on purpose, so a person who can only read a risk can still ask a question about it. The mention picker offers only colleagues who can open that same item, and portal-only employees have no access to it, so they cannot be mentioned.

Can I search comments?

Comments stay out of global search. You look for the risk or the vendor, then read what was said about it, because a half-sentence surfaced away from the item it belongs to is worse than no result at all.

How is this different from a chat channel or an email thread?

Placement and permission. A chat message lives in a channel and an email lives in the inboxes of whoever was copied, so neither is reachable from the risk or the policy it was about. Here the discussion sits on that item, everyone who can read the item can read the discussion, and the item’s history records who joined it and when.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your comments are part of your data, yours and exportable in full at any time, with no lock-in.

Put the discussion where the decision lives.

Give every control, risk, policy and vendor a Comments tab of its own, mention the person who has the answer, and keep the reasoning next to the item instead of in an inbox nobody can open at audit time.

Start for free
Book a conversation
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
See the full feature comparison
ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Ask about a control on the control itself.

2.0SCORE

Risks

The reasoning behind a treatment decision, on the risk.

policyv1.3
access_control {
require mfa = true
}

Policies

Question a clause where the clause actually lives.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Findings and the back-and-forth about them, together.

Start for free
Book a conversation
Sign in
Start for free
Book a conversation
Start for free