Solutions

One ISMS workspace,
however you run compliance.

devguard is the native ISMS workspace for keeping an organisation audit-ready — coverage, versioned policies, reviews, audits and ten auditor reports, your method on top. Whether you run one company’s compliance, many clients’, or keep evidence next to the code, you start from the same workspace. Swiss-hosted, German and English, on-prem possible. Pick the path that sounds like you.

Book a conversation
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
Three ways in

Which one sounds like you?

The same workspace underneath, a different job on top. Pick the path that matches how you run compliance — each one is honest about exactly what devguard does and doesn’t do.

Consultancies, vCISOs & MSPs

You run compliance for other companies. Every client mandate in one workspace, each client isolated — we don’t consult and we don’t resell.

For consultancies

Certified companies

You hold or are earning a certificate. Stay audit-ready year-round — the gap list months out, not the week before.

For certified companies

Engineering teams & CTOs

Your evidence lives miles from your code. Bring it next to the work in GitHub, GitLab, Jira and Slack, connected through tools you control.

For engineering teams

More than one fits? Most conversations start that way. Pick the one closest to this week — the path only changes what we talk about first, not what you get.

What makes us different

Four things we mean literally.

Not a metrics wall (we're early; we won't invent numbers). The differentiators we can stand behind today:

01

Native, no bolt-ons, one clear price

The ISMS core is the product — coverage, policies, reviews, audits and reports in one workspace, not a separate invoice each.

02

Swiss-hosted, on-prem possible, no lock-in

You control where the data sits, in German and English, and it exports in full whenever you ask.

03

Your methodology, not a method imposed

Your structure and process stay yours; devguard is where the work lives, whether that’s one company or many clients.

04

What we connect, we connect for real

Evidence flows from the tools you connect, and your policies stay yours to write. We only claim the integrations we actually ship — today that includes automated read-only checks across your cloud and stack, every check listed in the open.

Residency you can answer for.

Hosted in Switzerland by default, on-prem possible, German and English throughout — so when a client, customer or auditor asks where the compliance evidence sits, you have a precise answer. Your data exports in full, any time.

See the full feature comparison

How we start

We move the first one across, by hand.

No empty workspace handed over. Whatever you’re moving, whether your own ISMS, a client’s, or an existing setup in spreadsheets, Confluence or another tool, we migrate the first one into devguard ourselves, on a fixed scope and a fixed date. Nothing is switched over until you’ve checked it side by side. Then you run from there, and your data exports in full whenever you want it.

01 · Fixed scope

We scope the first move together

We agree exactly what the first migration covers, which frameworks and how much evidence, so there’s no open-ended engagement.

02 · Founder-run

We migrate it for you

The founder moves the ISMS from wherever it lives today, whether another tool, spreadsheets, Word or Confluence, on an agreed schedule, not a ticket queue.

03 · You verify, then run

Nothing switches until you sign off

You check the auditor-facing trail side by side. When you’re satisfied it’s intact, you’re live and you run from there.

Book a conversation
Solutions FAQ

Before you pick a path.

Which path is me?

If you run compliance for other companies as a consultancy, vCISO or MSP, start with the consultancies path. If you hold or are earning a certificate for your own company, start with certified companies. If your priority is keeping evidence next to your code in GitHub, GitLab, Jira and Slack, start with engineering. They’re the same workspace seen through a different job — the page just leads with the one you’ll care about first.

What if I’m more than one of these?

Common, and fine — a CTO who also holds the certificate, or a consultancy whose own company is certified too. Pick the path that matches the job you’re solving first; nothing about the product changes between them. We’ll sort out the rest in the conversation.

How is devguard priced?

There’s no published number, because the right price depends on which path you’re on and your setup — per client for a consultancy, per organisation for a single company. We work it out together in the conversation, and once it’s set, it isn’t re-negotiated against you later.

Where does the data live, and is there lock-in?

Hosted in Switzerland by default, in German and English, with on-prem possible — so you have a precise answer when a client, customer or auditor asks where the evidence sits. No lock-in by design: your policies, evidence and history export in full at any time.

Do you do the work for us, or just hand over the software?

Both, in order. We hand-migrate the first ISMS into devguard ourselves, fixed scope, fixed date, founder-run, and nothing switches over until you’ve verified it side by side. After that you run the workspace yourself, and the migration is the on-ramp, not a consulting line we’re building.

Let’s talk about how you run compliance.

A short conversation, peer to peer — not a sales demo. Tell us how compliance works for you today, and we’ll be straight about whether devguard fits and what moving a first ISMS across would look like.

Book a conversation
Sign in
Start for free
Book a conversationStart for free