Registers, roles, audit trails, review workflows, and reporting - built specifically around ISO/IEC 27001, not bolted on afterward.
Each register comes with ownership, classification, scheduled reviews, and a complete history - no add-ons required.
A single, current catalogue of everything that needs protecting - hardware, software, data, people, and services - with clear ownership.
Hardware, software, data, people, and services in one searchable inventory.
Every asset has a named owner and a classification level.
Confidentiality, Integrity, and Availability rated Low / Medium / High per asset.
3, 6, or 12-month review cycles configured per asset or asset type.
Non-destructive history - every edit is recorded, nothing is overwritten.
Excel/CSV export plus search and filters across every field.
Catalogue risks against your assets, score them consistently, and track treatment through to closure.
Category, threat, and vulnerability captured for every risk.
Consistent Low / Medium / High / Critical scoring across the register.
Accept, Mitigate, Transfer, or Avoid - tracked with an owner and plan.
Before-and-after view of risk once treatment is applied.
Open → In Treatment → Closed, visible at a glance.
Every risk ties back to the asset(s) it affects.
A module must be enabled for your organisation and a user must be individually granted access before they can see it.
| Role | What they can do |
|---|---|
| ISMS Administrator | Owns the ISMS day-to-day - manages registers, assigns record ownership, runs reviews, and grants Standard Users access to specific modules and records. |
| Standard User | Works within the modules and records they've been granted - updating assets, risks, or actions they own, without visibility into the rest of the system. |
Every change is captured permanently, so your evidence trail is exactly what an auditor expects to see - no gaps, no silent edits.
Old value → new value, captured for every field on every record.
Know exactly who changed what, and when.
History entries can't be edited or deleted — not even by System Administrators.
Search history across Asset, Risk, and every future register from one place.
Configure once, and let the platform chase the follow-through.
Set review cycles per record - 3, 6, or 12 months.
Owners are reminded automatically as a review date approaches.
Overdue items escalate to administrators so nothing sits idle.
Recording a review outcome automatically sets the next review date.
Raise tickets with priority and attachments, and follow threaded updates through to resolution.
Filterable views across registers so admins can see status, ownership, and risk exposure at a glance.
Purpose-built reports for upcoming and overdue reviews, ready to export ahead of an audit.
Three more registers are planned next.
Log, triage, and close out security incidents with a full record trail.
Annex A.5.24–A.5.28Track third-party risk, contracts, and supplier due diligence.
Annex A.5.19–A.5.22Centralise policy versions, approvals, and review cycles.
Clause 5.2 / A.5.1Create an account, enable Asset and Risk Registers, and invite your team today.