For engineering teams & CTOs

Compliance evidence
where the code is.

devguard connects natively to GitHub, GitLab, Jira and Slack, so from an action it creates and tracks a ticket in those tools and syncs the status back. Your team keeps the work in one place instead of being pulled out of engineering to chase it. Swiss-hosted, German and English, on-prem possible.

Book a conversation
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
Straight talk

What’s live, and what’s next.

Automated read-only checks now cover AWS, Azure, GCP and 50 more tools, next to the native link to the code, ticket and chat systems your team already uses. A CLI agent is on the roadmap, announced when it ships.

What’s live, and what’s next.
Capabilitydevguard
Live today
Native integrations with GitHub, GitLab, Jira & Slack
Create and track a ticket from an action, status synced back
Coverage, policies, audits, reviews and ten reports
Optional AI assistant for retrieval and Q&A
Deeper evidence automation from your cloud
What’s coming
More of the systems your team runs, connected

Everything marked live ships today. We’ll be straight about what’s still coming, rather than promise automatic everything up front.

Remediation where the work is

From an action to a
tracked ticket.

From an action, devguard creates a ticket in GitHub, GitLab or Jira, or sends a Slack message, then syncs the status back as your team works it. The remediation happens where your team already is, and devguard keeps the trail.

app.devguard.ch / actions
live
Remediate finding · access review
Tickets created and status synced back
JiraSEC-114 · created from actionin progress
GitHubacme-api · issue #482open
Slack#security · message sentnotified
The ISMS, run in one place

How the ISMS lives in your stack.

Connect the systems your team already works in, then run the ISMS in devguard: coverage per framework, versioned policies, reviews, audits and the reports you hand over.

Coverage

See the gaps before the auditor does

Control coverage per framework moves from unknown to partial to full as you map each control to the policies, assets and risks that satisfy it. An open gap is visible months out, not the week before the audit.

Coverage per framework, unknown to full
Gaps surfaced by control, not found late
app.devguard.ch / coverage
63 / 93 controls
68%
controls covered
ISO 2700184%
SOC 271%
GDPR49%
Policies

Versioned policies with a real approval trail

Author your policies in devguard, then move each one draft, needs-approval, published, with the full version history kept. The auditor sees the policy and the approval that stands behind it, not a file with an unknown edit history.

Draft to needs-approval to published
Full version history per policy
app.devguard.ch / policies
12 published
PolicyVerStatus
Access control policyv2.1Published
Data retention policyv1.3Published
Encryption policyv0.9Needs approval
Reviews

Reviews that don’t slip

Asset, risk and vendor reviews each run draft to in-progress to completed, with findings and the next review date set on completion. A deadlines view surfaces what’s due early, so reviews don’t pile up before the audit.

Asset, risk and vendor reviews tracked
Deadlines surfaced early, clear owners
app.devguard.ch / deadlines
3 upcoming
Next: access review · in 5 days
JUL03Access reviewin 5 days
JUL21Risk review · Q3in 3 weeks
AUG14Vendor reassessmentin 6 weeks
Audits

Findings tracked to closure

Log audit findings with their root cause and the corrective measure, each with its own deadline, and carry every non-conformity through to closed. The state of an internal audit is something you can show, not reconstruct from chat history.

Root cause and corrective measure per finding
Non-conformities carried to closed
app.devguard.ch / audits
internal audit
ISO 27001 internal audit · Q2
Access controlsA.5.15
Backup & recoveryA.8.13
Use of cryptographyreviewing
Supplier securityA.5.19
3 findings carried to closure
Reports

Ten reports you can hand over

Generate the documents an auditor expects as PDFs, including the Statement of Applicability, plus audit, risk, asset, vendor, policy and review reports — produced from the live workspace, not assembled by hand the night before.

Statement of Applicability as a report
Ten PDF report types, from live data
app.devguard.ch / reports
10 report types
Generated as PDF, on demand
Statement of ApplicabilityPDF
Risk assessment reportPDF
Vendor risk reportPDF
+ audit, asset, policy and review reports
What makes us different

Four things we mean literally.

Not a metrics wall (we're early; we won't invent numbers). The differentiators we can stand behind today:

01

Action turns into a tracked ticket

From an action, devguard creates and tracks a ticket in GitHub, GitLab or Jira, or sends a Slack message, then syncs the status back, so the work happens where your team already is, not in a separate tracker nobody updates.

02

Native to GitHub, GitLab, Jira & Slack

Native integrations with the four tools your team already works in; nothing new to adopt to keep remediation moving.

03

Swiss-hosted, on-prem possible, no lock-in

You control where your data sits, in German and English. Export records to CSV and reports to PDF whenever you ask.

04

What’s live is really live

Evidence flows from the tools you connect, and your policies stay yours to write. Automated read-only checks across 50+ tools ship today; a CLI agent stays on the roadmap, announced only when it ships.

Two ways to start

Set it up, or we move you in.

Connect your tools and run the ISMS yourself, or have us move your existing one across first. No number on the page — the right price depends on your setup, and we work it out together.

Set up and run yourself
  • Connect GitHub, GitLab, Jira and Slack
  • Map controls, author policies, run reviews and audits
  • Generate the ten reports, including the Statement of Applicability
  • Export records to CSV and reports to PDF, any time
Or we move you across first
  • We migrate your existing ISMS into devguard by hand
  • Fixed scope, fixed date, founder-run
  • We wire up your GitHub, GitLab, Jira and Slack links
  • Nothing switches until you’ve verified it side by side
Residency your customers can check.

Hosted in Switzerland by default, on-prem possible, German and English throughout — so when a customer asks where their compliance evidence sits, you have a precise answer. Export records to CSV and reports to PDF, any time.

See the full feature comparison

How we start

We move your existing ISMS across, by hand.

No empty workspace to fill from scratch. Wherever your ISMS lives today, in spreadsheets, Confluence or another tool, we migrate it into devguard ourselves on a fixed scope and a fixed date. We connect your GitHub, GitLab, Jira and Slack integrations, and nothing is switched over until you’ve checked it side by side. Then you run from there, and you can export records to CSV and reports to PDF whenever you want.

01 · Fixed scope

We scope the move together

We agree exactly what the first migration covers, which frameworks, which integrations, how much evidence, so there’s no open-ended engagement.

02 · Founder-run

We migrate and connect the integrations

The founder moves your ISMS in and connects GitHub, GitLab, Jira and Slack so an action can create and track a ticket in the right tool, on an agreed schedule.

03 · You verify, then run

Nothing switches until you sign off

You check the auditor-facing trail side by side. When you’re satisfied, the workspace is live and your team runs it from there.

Book a conversation
Engineering FAQ

The questions a CTO actually asks.

Which systems does devguard integrate with?

GitHub, GitLab, Jira and Slack natively, plus automated read-only checks across 50+ tools, from AWS and Okta to Stripe. From an action, devguard creates and tracks a ticket in those tools or sends a Slack message, then syncs the status back; check results attach to the controls they support.

How is evidence collected?

Evidence flows two ways: the code, ticket and chat systems you connect keep the ISMS current as work happens, and automated read-only checks across AWS, Azure, GCP and 50 more tools turn configuration into evidence on your controls. A CLI agent and CI auto-capture are on the roadmap.

Is the AI generating our policies?

No. The AI assistant is optional and does retrieval and Q&A over your existing ISMS — it helps you find and reason about what’s already there. It does not write your policies for you, because auditors see through generated policy text and so should you.

Where does the data live, and can it run on-prem?

Hosted in Switzerland by default, in German and English. On-prem is possible, so your compliance evidence stays where you need it, which matters when a customer asks where their data sits.

What happens to our data if we leave?

No lock-in by design. You can export your records to CSV and generate reports as PDFs at any time. Moving in never means you can’t move out.

We’re mid-certification — does this fit our pipeline?

Yes. You map controls to coverage per framework, back each one with the policies, assets and risks it requires, and generate the Statement of Applicability and the other reports an auditor expects. If your ISMS already lives somewhere else, we move it across by hand first so you’re not rebuilding it during the certification run.

Let’s talk about putting evidence where the code is.

A 15-minute conversation, engineer to engineer — not a sales demo. How your team works today, which of GitHub, GitLab, Jira and Slack you’d connect, and where devguard fits, including what’s live now and what’s on the roadmap.

Book a conversation
Sign in
Start for free
Book a conversationStart for free