devguard - Your Compliance Platform
PlatformSolutionsFrameworksDevelopersPricing
devguard

One workspace for your whole ISMS — Swiss-hosted, one control set, mapped to every framework you run.

All systems operational
Product
PlatformFeaturesSolutionsFrameworksPricing
Developers
API & CLIIntegrationsDocumentationChangelogSwiss hosting
Company
AboutBlogCompare
© 2026 devguard AG. All rights reserved.
Terms of servicePrivacy policySite noticeTrust centerLLM info
Swiss Made Software
Mandates

Every client in one portal,
each one its own tenant

You run compliance for other companies. A mandate owns those client organizations and gives your team one way into all of them: one portfolio to see where each client stands, one queue of what they need, and your own brand in front of every one. Available from five licences.

++++
app.devguard.ch / mandate / portfolio
6 clients · 8 licences
Portfolio
6
client organizations
On track04
Needs work02
Licences free02
Your brand, not ours
Every client, one view
ClientFrameworkCoverageOverdue
FLFenner Logistik AG
ISO 27001
92%
0
BMBrunner Medtech
ISO 27001 · GDPR
78%
3
HSHalden Software
SOC 2
64%
7
RTRietberg Treuhand
nFADP
41%
12
Read-only across the portfolio — you act inside the client you opened, in the role you hold there
Every framework
How it works

Attach the clients, work the portfolio, keep your brand

A mandate sits above the organizations you run and changes nothing about how each one works inside. You get the view across them, and the client keeps its own workspace.

01

Attach the clients you already run

Create a client organization from the mandate, or attach one that already exists and keeps everything it has. Each client takes a licence, and the mandate never absorbs the client: controls, evidence, policies, people and audit log stay where they are.

Your staff are carried into each client in the role they hold on the mandate, so nobody collects a second set of credentials and nobody is handed more access in a client than they have with you

02

See every client, work one at a time

The portfolio shows each client’s coverage, the frameworks it has adopted, what is overdue and what falls due soon, so the weekly question of which client needs you is answered on one screen. The task queue is grouped by organization rather than flattened, because the answer you need is what this client needs, not what is most urgent anywhere.

Build one client, repeat it

The template transfer copies a setup you have already built into the client you are starting. It belongs to the mandate rather than to any client’s settings, and only the clients you administer are offered on either side of it.

03

Put your brand in front of the client

Your logo and colours apply to every organization under the mandate, and your support address and help link replace ours inside them. Your client’s staff reach you rather than us, which is the arrangement you sold them.

Why it’s built this way

Built so a client stays a client’s

Four choices behind how mandates work here — each one something you can check, not an adjective

01

One way in, in the role you actually hold

Your staff are carried into every client organization in the role they hold on the mandate, whether that is owner, admin, member or auditor, so an auditor on your team reads a client and changes nothing. An employee is never carried in at all. There is no shared login and no second password list to keep.

02

Read across, act inside

The portfolio reads. Anything that changes a client happens inside that client, under that client’s own audit log, so a bulk push can never touch twenty tenants from a screen nobody audits. The client’s record stays the client’s record.

03

Each client is a tenant of its own

A client organization holds its own controls, evidence, people and audit log, isolated from every other client you run. Detaching one leaves it intact and standing on its own, which is what makes handing it back possible. A mandate that still has clients cannot be deleted.

04

Licences are the quantity, and you set it

You buy licences and attach a client to each one. Every licence is invoiced whether a client sits on it or not, so the number is yours to set, and lowering it takes effect at the end of the period rather than silently cutting a client off mid-month. Mandates start at five licences.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Every client’s data and evidence are exportable in full at any time, with no lock-in.

One module of the platform

Where mandates connect

The portfolio reads what each client’s own modules hold: its coverage per framework, its open tasks, the reports it hands an auditor, and who holds which role

FAQ

The questions practices ask

What is a mandate?

An account that owns the client organizations you run compliance for. Your consultancy, vCISO practice or MSP is the mandate; each client you look after is an organization under it, with its own controls, evidence and people. You work the portfolio from one portal instead of signing in and out of a dozen separate workspaces.

How many licences do I need to start?

Five. A mandate is for running compliance as a practice, and below five clients the ordinary organization switcher already does the job without the portal, the portfolio or the whitelabel. Above it, buy a licence per client and attach the client to it.

Do my clients see devguard or my own brand?

Yours. Your logo and colours go in front of every organization under the mandate, and your support address and help link replace ours there, because the people in a whitelabelled client need somewhere to go and our own help content names devguard throughout. You are their first line of support, and the product says so.

Can I reuse one client’s setup for the next?

Yes. Building a client once and repeating it is the job, so the transfer lives in the mandate rather than in any one client’s settings: pick the client you built, pick the client you are starting, and copy the setup across. Only clients you administer are offered on either side.

What happens when a client leaves?

You detach it and it keeps everything. Its controls, evidence, policies, people and audit log stay with the organization, which carries on as an ordinary devguard tenant your former client can run alone or hand to someone else. Nothing is held hostage, and the licence it occupied frees up.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Each client’s data is exportable in full at any time, by you or by them, with no lock-in.

Run every client from one portal

Attach the clients you already run, see where each one stands without signing in and out, copy a setup you built once into the next client, and put your own brand in front of all of them

Start for free
Book a conversation
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
ISO/IEC 27001
ISO/IEC 27002
SOC 2
SOC 1
GDPR
HIPAA
PCI DSS v4.0.1
NIST CSF 2.0
EU AI Act
NIS2 Directive
DORA
OWASP
ISO/IEC 42001
CIS Controls
Cloud Controls Matrix
ISO/IEC 27017 & 27018
ISO/IEC 27701
ISO 9001
ISO 14001
ISO 45001
Swiss nFADP
See what a mandate costs
coverage86%

Coverage

The number each client is judged on, per framework

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

One queue across every client, grouped by organization

86%
Shared with
JDAKMR+3

Reports

The documents a client hands its auditor

AKCEO
MRCISO
DPDPO

People

Who holds which role, in the mandate and in each client

Start for free
Book a conversation
Sign in
Start for free
Book a conversation
Start for free