For consultancies, vCISOs & MSPs

One workspace for every
client mandate.

devguard is where compliance consultancies, vCISOs and MSPs run their client ISMSs. Each client is its own isolated workspace, your methodology and your structure, with one login across all of them. Swiss-hosted, on-prem possible. We don’t consult and we don’t resell, so we never compete for your mandates.

Book a conversation
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
Straight talk

Where the line sits.

You run the mandates and keep the client relationship. devguard is the tooling underneath, and the first migration is work we do for you. Here’s exactly what’s self-serve and what the conversation adds — no number on the page, because the right per-client price depends on your mandate mix and we work it out together.

The workspace, self-serve
  • Run every client mandate, each its own isolated workspace
  • Coverage, policies, reviews, audits and ten report types
  • Your data exportable to CSV and PDF, any time, no lock-in
  • Swiss-hosted, German and English, on-prem possible
The conversation adds
  • We hand-migrate your first client’s ISMS into devguard
  • A fixed price and a fixed date for that first move
  • A per-client price worked out for your mandate mix
  • A direct line to the founder running the migration
Every client, separated and in reach

Each client isolated,
one login across all.

In devguard every client is its own workspace — its own data, members and frameworks kept fully separate, the isolation your clients expect. One login belongs to all your client workspaces, and you switch between them in a click, instead of juggling a tool per client.

cross-mandate overview · concept
In design
S
SaaS client
ISO 27001 · SOC 2
86%On track
M
Manufacturing client
ISO 27001
73%Review Aug
H
Healthcare client
ISO 27001 · GDPR
61%Review due
F
Fintech client
SOC 2 · PCI DSS
92%On track

The cross-mandate overview above is in design — a single view of every mandate, so you spot the client with a review due before they call. Today that’s real isolation plus one-click switching; the overview is where this is heading, and the first partners shape it.

Per mandate, the same loop

How a client runs in one workspace.

Set up each client on your own method, then keep them audit-ready through the same loop: coverage, policies, reviews, audits and the reports you hand over.

Coverage

See the gaps before the auditor does

Control coverage per framework moves from unknown to partial to full as you map each control to the policies, assets and risks that satisfy it. An open gap is visible months out, not the week before a surveillance audit.

Coverage per framework, per client
Gaps surfaced by control, not found late
app.devguard.ch / coverage
63 / 93 controls
68%
controls covered
ISO 2700184%
SOC 271%
GDPR49%
Policies

Versioned policies with a real approval trail

Author each client’s policies in devguard, then move them draft, needs-approval, published, with the version history kept. The auditor sees the policy and the approval that stands behind it, per mandate.

Draft to needs-approval to published
Full version history per policy
app.devguard.ch / policies
12 published
PolicyVerStatus
Access control policyv2.1Published
Data retention policyv1.3Published
Encryption policyv0.9Needs approval
Reviews

Review cycles that don’t slip

Asset, risk and vendor reviews each run draft to in-progress to completed, with findings, recommendations and the next review date set on completion. Deadlines surface early, so a review never sneaks up the week it’s due.

Asset, risk and vendor reviews tracked
Next review date set on completion
app.devguard.ch / deadlines
3 upcoming
Next: access review · in 5 days
JUL03Access reviewin 5 days
JUL21Risk review · Q3in 3 weeks
AUG14Vendor reassessmentin 6 weeks
Audits

Findings tracked to closure

Log audit findings with their root cause and the corrective measure, each with its own deadline, and carry every non-conformity through to closed. The state of an internal audit is something you can show, not reconstruct.

Root cause and corrective measure per finding
Non-conformities carried to closed
app.devguard.ch / audits
internal audit
ISO 27001 internal audit · Q2
Access controlsA.5.15
Backup & recoveryA.8.13
Use of cryptographyreviewing
Supplier securityA.5.19
3 findings carried to closure
Reports

Ten reports you can hand over

Generate the documents an auditor expects as PDFs — the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports. The artifact you hand over per client is produced from the live workspace, not assembled by hand the night before.

Statement of Applicability as a report
Ten PDF report types, per mandate
app.devguard.ch / reports
10 report types
Generated as PDF, on demand
Statement of ApplicabilityPDF
Risk assessment reportPDF
Vendor risk reportPDF
+ audit, asset, policy and review reports
What makes us different

Four things we mean literally.

Not a metrics wall (we're early; we won't invent numbers). The differentiators we can stand behind today:

01

Native, no bolt-ons, one clear price

The ISMS core is the product; training and device monitoring aren't a separate invoice.

02

Swiss-hosted, on-prem possible, no lock-in

You control where client data sits, and it exports in full whenever you ask.

03

Your methodology, every client in one workspace

Your structure and process stay yours; devguard is where the work lives, not a method imposed on you.

04

Not a competitor, not a reseller

No consulting arm, no certification services, nothing resold to your clients — by design and by capacity.

Residency your clients can check.

Hosted in Switzerland by default, on-prem possible, German and English throughout — so when a client asks where their compliance evidence sits, you have a precise answer. Your data exports in full, any time.

See the full feature comparison

How we start

We move your first client across, by hand.

No empty workspace handed over. Pick one low-stakes mandate. We migrate its existing ISMS into devguard ourselves, on a fixed scope and a fixed date, and nothing is switched over until you’ve checked it side by side. Then you run from there, and your data exports in full whenever you want it.

01 · Fixed scope

We scope the first client together

We agree exactly what the first migration covers, which frameworks and how much evidence, so there’s no open-ended engagement.

02 · Founder-run

We migrate it for you

The founder moves the ISMS from wherever it lives today, whether spreadsheets, Word or Confluence, on an agreed schedule, not a ticket queue.

03 · You verify, then run

Nothing switches until you sign off

You check the auditor-facing trail side by side. When you’re satisfied, the mandate is live and you run it from there.

Book a conversation
Consultancy FAQ

The questions principals actually ask.

Do you compete with me, or go after my clients?

No. devguard has no consulting arm and sells no certification services, by design and by capacity, and that won’t change. We don’t resell to your clients either. You stay the expert your client hired; devguard is where your delivery work lives.

Can each client stay fully separated from the others?

Yes. Each client is its own workspace, with its own data, members and frameworks kept separate, so nothing leaks between mandates. One login belongs to all of them and you switch between them in a click.

Is it priced per client or one flat fee?

Per client, with a one-time setup fee for the hand-migration. There’s no published number because the right one depends on your mandate mix, so we work it out together in the conversation. Once it’s set, it isn’t re-negotiated against you later.

What reports can I hand an auditor?

Ten PDF report types generated from the live workspace, including the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports. You produce them per client instead of assembling documents by hand before the audit.

Where does the data live, and can it run on-prem?

Hosted in Switzerland by default, in German and English. On-prem is possible, so client data residency stays under your control, which matters when your clients ask where their compliance evidence sits.

What happens to my data if I leave, and what does the migration involve?

No lock-in by design: your data, your clients’ policies and evidence are yours, exportable to CSV and PDF whenever you want. For the migration, we take one client’s existing ISMS, wherever it lives today, and move it into devguard ourselves at a fixed price on a fixed date. Nothing is switched over until you’ve reviewed it side by side and you’re satisfied the auditor-facing trail is intact.

Let’s talk about how you run your mandates.

A 20-minute conversation, peer to peer — not a sales demo. How your delivery works today, whether devguard fits, and what moving a first client would look like.

Book a conversation
Sign in
Start for free
Book a conversationStart for free