Policies

Every policy version,
with its approval.

Write a policy, map it to the controls it satisfies, and have an approver sign it off. Each approval freezes a new version with the approver, the date, a changelog and a snapshot of what was covered at the time, so the binder you hand an auditor matches what was actually approved, not a document someone edited after the fact.

Start for freeBook a conversation
Maps toISO/IEC 27001SOC 2GDPRNIST CSFPCI DSS
++++
app.devguard.ch / policies
12 enforced
Policies enforced
Policies enforced
86%
of estate
Enforced12
In review01
Draft03
Access Control Policy
v1.3Enforced
access_control {
require mfa = true
max_session = 8h
review_cycle = 12mo
}
Maps to controls
ISO 27001 · A.5.15
ISO 27001 · A.5.16
SOC 2 · CC6.1
Linked evidence
iam-policy.json
mfa-config.png
Enforced across 142 assets · last rolled out 3 days ago
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Draft, approve, version.

A policy moves from draft to approved, and every approval is recorded as its own version you can go back to.

01

Write it and map it

Create a policy in one place and link it to the controls it satisfies across your frameworks. The same policy can answer ISO 27001 A.5.15 and SOC 2 CC6.1 at once, instead of living as a separate document per standard.

02

Send it for approval

Assign the approver role for each policy and move it to needs-approval. Approving it captures a full snapshot, the approver, the timestamp and a changelog, and publishes that version.

An approval trail, not a file

Each approved version is frozen with who approved it, when, what changed and which controls it covered at that moment, so you can show an auditor the exact version that was in force on any date.

03

Revise without losing history

When a policy changes, it goes back to draft and the next approval creates the next version. Earlier versions stay intact and readable, so the full history of what you required, and when, is always there.

Why it’s built this way

Built for the auditor’s question.

Four choices behind how policies work here, each one something you can check.

01

Semantic versions, not “final v2 (3)”

Every approved policy carries a version number like 1.2.1, and approving a change mints the next version automatically.

02

Each version records who approved it

The approver, the approval date and a changelog are stored with every version, alongside a snapshot of the controls it covered at the time.

03

One policy answers many controls

A policy links to the controls it satisfies across frameworks, so a single access-control policy can map to ISO 27001 and SOC 2 at once.

04

Old versions stay readable

Superseded versions aren’t overwritten or deleted, so the version that was in force on any past date is still there to open.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where policies connect.

Policies don’t live alone. Each one maps to the controls it satisfies, rolls into your coverage, and shows up in the audits that test it, all in the same workspace.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Map each policy to the controls it satisfies.

coverage86%

Coverage

See how published policies roll up into coverage.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Show the approved version in force at the audit.

drafting…

AI assistant

Draft a policy for a control, then review and insert.

FAQ

The questions evaluators ask.

Are policies versioned?

Yes. Every policy carries a semantic version like 1.2.1, and each approval creates a new, frozen version with the approver, the date and a changelog. Earlier versions stay intact, so you can open the exact version that was in force at any point.

Who can approve a policy, and is that recorded?

Each policy has an assigned approver role. When it’s approved, the approver and the timestamp are stored on that version, so every published policy carries a record of who signed it off and when.

Can one policy cover more than one framework?

Yes. A policy links to the controls it satisfies, and a single control can map across frameworks. So one access-control policy can answer ISO 27001 A.5.15 and SOC 2 CC6.1 at the same time, instead of being copied per standard.

How is this different from a spreadsheet or another GRC tool?

In a shared drive, a policy is one file that gets edited in place, so “what was approved, and when” is a guess. Here, each approval freezes a numbered version with the approver, the date, a changelog and the controls it covered, and links the policy to the frameworks it satisfies, so the history is the record rather than something you reconstruct before an audit.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your policies and their full version history are yours and exportable at any time, so there’s no lock-in.

Keep every policy version, with its approval attached.

Version your policies, map them to the controls they satisfy, and record who approved what, and when, so the policy you show an auditor is the one that was actually in force.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free