Records

Every document filed,
every version intact

Board minutes, management reviews, submitted access requests, pen-test results — the paperwork an ISMS actually generates lives here. Every record belongs to a category that supplies its template, cadence and owner, and marking one final cuts an immutable version, so what was signed off stays exactly as it was signed off.

Start for freeBook a conversation
++++
app.devguard.ch / records
v3 final
Categories
Meeting minutes12
Access requests08
Pen-test results03
Mgmt reviews06
Template + cadence per category
Management review · June
RE-014Final
Versions
v1
Initial review minutes
Jan 12
v2
Q1 follow-ups closed
Mar 30
Scope + KPI update
Jun 24immutable
Marking a record Final cuts an immutable version — editing reopens it
Every framework
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • Swiss nFADP
How it works

Categorized, written, committed

A category defines the kind of document, you write it in an editor built for prose, and finalizing commits an immutable version.

01

A category defines the kind of document

Meeting minutes, access requests, whistleblower reports, management reviews — each category supplies the template, cadence, owner and linked items its records inherit. File a record into a category and the structure is already decided.

02

Write it like a document, not a form

The editor keeps headings, lists, tables, images and references to your collections, and drops the section structure and control-mapping a policy needs. A record moves through draft, in progress and final by hand — no approver gate where the work doesn’t need one.

A third thing besides policies and evidence

A policy states the rules and is gated by an approver. Evidence is body-less proof on a control. A record is the authored, dated document in between — each identified by a short code like RE-001, so “where are the March minutes?” has a one-line answer.

03

Final cuts an immutable version

Marking a record final snapshots its title, content and files into an append-only version — v1, then v2. Editing reopens the record as in progress while every committed version stays untouched, so the audit trail of what was approved when writes itself.

Why it’s built this way

Documents with a lifecycle, not a folder

Four choices behind how records work here — each one something you can check, not an adjective.

01

A third thing, not a policy variant

A policy is section-structured, control-mapped and approver-gated. Evidence is body-less proof. A record is an authored, dated document — devguard keeps the three apart so each stays simple.

02

Categories carry the defaults

A category defines the kind of document and supplies the template, cadence, owner and linked items its records inherit — file a record and the structure is already there.

03

Final means immutable

Marking a record final cuts an append-only version — v1, v2, v3. Editing reopens the record while every committed version stays exactly as it was signed off.

04

No approver theater

Records move through draft, in progress and final by hand — anyone with write permission can move them. There’s no approval chain where the work doesn’t need one.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where records sit in the ISMS

Records are the documents between the rules and the proof — connected to the policies, evidence, audits and deadlines around them.

policyv1.3
access_control {
require mfa = true
}

Policies

The rules you set — records are the documents you produce.

342
artifacts captured
linked to controls

Evidence

Proof attached to a control — records carry the writing.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Management reviews and minutes, ready when the auditor asks.

JUN
ISO review
in 3 days

Deadlines

A record’s due date lands on the same calendar.

FAQ

The questions evaluators ask.

How are records different from policies and evidence?

A policy is a section-structured document that maps to controls and is gated by an approver. Evidence is body-less proof attached to a control. A record is an authored, dated document that belongs to a category — board minutes, a management review, a submitted access request, a pen-test result. It’s a third thing, kept deliberately separate.

What happens when I mark a record final?

Finalizing snapshots the record’s title, content and attached files into an immutable version — v1, then v2, and so on. Editing a final record reopens it as in progress while the committed version stays untouched; finalizing again cuts the next version, optionally with a short changelog.

Can I bring in the records we already have — years of reviews and minutes?

Yes. Upload the documents you already have as records — file each into its category and mark it final to cut v1. Nothing has to be re-authored, and later versions build on top of what you imported.

How is this different from a shared drive or a wiki?

A folder of documents has no notion of category, cadence, status or versions — you find out a management review is missing when the auditor asks for it. Here every record has a category that defines what should exist and how often, a status you can read at a glance, and immutable versions that prove what was signed off when.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Records and their versions are yours and exportable in full at any time, with no lock-in.

What the auditor asks for, already filed

File the minutes, reviews and reports your ISMS produces into categories with a cadence and an owner, and let finalizing cut the immutable version that proves what was signed off.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free