Reports

Ten reports,
straight from your workspace.

Generate ten report types as PDFs from your live workspace — the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports. Export to PDF and hand it to whoever needs it, an auditor or your board. Access follows your workspace roles.

Start for freeBook a conversation
++++
app.devguard.ch / reports
Shared · 6
Posture
Posture
86%
audit ready
Export
PDFCSV
Security Posture · June 2026
Executive summary
Shared with
EAExternal auditorRead-only
BDBoardSummary
STSecurity teamFull access
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Generate, download, hand over.

Every report is built from your live data, downloaded as a PDF, and handed to whoever needs it.

01

Generate from the live workspace

Pick a report and it’s built from your current data — controls, audits, risks, assets, vendors and reviews as they stand right now, not a stale copy you maintained on the side.

The SoA and ten reports

Ten report types generate from the live workspace, including the Statement of Applicability, with controls selected, their status and justification, so the document an auditor expects is one click, not a rebuild.

02

Download as a PDF

Export any report as a polished PDF with one Download PDF button, ready to hand over. The same workspace data, in a document the reader can open anywhere.

03

Hand it to whoever needs it

Hand the PDF to an auditor or your board. Who can generate and read reports is set by workspace role: owners and admins manage everything, members have read access.

Why it’s built this way

Generated, never maintained by hand.

Four choices behind how reports work here — each one you can check, not an adjective.

01

Generated from live data

Each report is built from your current workspace, so it reflects today’s controls, risks and findings, not a snapshot.

02

Ten report types, including the SoA

The Statement of Applicability plus audit, risk, asset, vendor, policy and review reports generate from the same data.

03

Download as a PDF

Each report generates as a formatted PDF with one Download PDF button, ready to hand over.

04

Access follows your workspace roles

Owners and admins generate and download any report, members have read access. You hand the PDF to whoever needs it.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where reports draw from.

A report is only as current as what it’s built on — your controls, your coverage, your audits and your risks, all in the same workspace.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

The Statement of Applicability reports on your control set.

coverage86%

Coverage

Report posture and gaps as they stand right now.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Export an audit and its findings as a PDF.

2.0SCORE

Risks

Report risk assessments and treatment in one document.

FAQ

The questions evaluators ask.

Which reports can I generate?

Ten types, all from your live workspace: the Statement of Applicability, an audit report, risk and risk-review reports, asset and asset-review reports, vendor and vendor-review reports, an access-review report and a policy report. Each is built from current data, not a separate copy.

Is the Statement of Applicability included?

Yes. The SoA generates from your control set, covering which controls are selected for a framework, their implementation status and the justification, as a PDF you can hand to an auditor, built from the workspace rather than maintained on the side.

Can I control who sees what?

Access follows your workspace roles. Owners and admins generate and download any report, members have read access. You generate a report as a PDF and hand it to whoever needs it, an auditor or your board.

How is this different from building the report in a spreadsheet or another GRC tool?

A hand-built report is out of date the moment the data moves, and you rebuild it before every audit. Here, each report, including the SoA, is generated from the live workspace and downloaded as a PDF you hand to whoever needs it. You generate it, you don’t maintain it.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Reports export to PDF, and your underlying data is yours via the API at any time, with no lock-in.

Hand over the report straight from the workspace.

Generate the Statement of Applicability and nine more report types from your live data, export to PDF, and hand it to whoever needs it — without maintaining a single document by hand.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free