The complete GRC platform for security & data protection
77 modules in seven pillars – consistently integrated so data is maintained only once and works together across all areas. Explore every module in detail.
Manage information security
Risk Register
A central register to capture, assess and link your risks to assets, people and processes.
Learn moreAudit Management
The complete audit lifecycle: planning, execution, findings, measures and follow-up.
Learn moreEmergency Kit
Builds an encrypted, signed emergency package with its own offline viewer from your ISMS data and keeps it ready on emergency laptops. It is opened with a printed key from the safe.
Learn moreEmergency Management (BCM)
Enterprise Business Continuity Management to ISO 22301, BSI 200-4, NIS2 and DORA – from BIA to war room.
Learn moreEffectiveness Assessment
Systematic assessment of your security controls’ effectiveness to ISO 27001 – with trend dashboards.
Learn moreWiBA – Path to Basic Protection
The 19 BSI WiBA checklists with 258 questions, answered in a guided flow: with fulfilment status, effort estimates, ownership and history. Every answer is credited towards IT-Grundschutz via the official mapping.
Learn moreKPI Cockpit
Define, configure and measure ISMS metrics with visual dashboards and trend analyses.
Learn moreCyber Risk Policy
A framework to define cyber risks, security objectives and policies with automated checks and findings.
Learn moreNIS2 file
Scope determination under Section 28, registration with the BSI under Sections 33 and 34, obligations catalogue under Sections 30 and 31, evidence cycle under Section 39, management duties under Section 38, supervisory correspondence under Sections 61 and 62, and reporting under Section 32.
Learn moreDORA
The requirements of Regulation (EU) 2022/2554 as auditable controls with gap analysis, plus the register of information on ICT third-party providers under Article 28(3), the three-stage reporting workflow and the testing programme up to TLPT.
Learn moreCRA Compliance
Conformity assessment under the EU Cyber Resilience Act: Annex I control catalog, reporting chain for the 24/72-hour deadlines and declaration of conformity, mapped to evidence from your existing modules.
Learn moreB3S Standards
Sector-specific security standards under § 39 BSIG: requirement catalogs per critical-infrastructure sector (hospital, statutory health/care insurance), scopes with SoA, automated as-is checks, RUN maturity and § 39 audit report.
Learn moreNIS2 Reporting
Reporting chain under § 32 BSIG / Art. 23 NIS2: early warning in 24 hours, notification in 72, interim and final report, with deadline alerts, per-stage export and a PDF reporting file.
Learn moreRule Chains
Thirteen triggers from the ISMS, SIEM, attack surface scanning, uptime monitoring and behaviour analytics, with condition checks, action and task creation, escalation stages and an execution log.
Learn moreChecklists
Flexible checklists with templates for ISO 27001, GDPR and BSI IT-Grundschutz – including progress and escalation.
Learn moreClassified Information Protection
Personnel classified protection under SÜG and physical protection under VSA/GHB in one solution.
Learn moreProject Registry
Systematic recording and classification of projects to TISAX (VDA ISA) and ISO/IEC 27001.
Learn moreFitSM
The complete FitSM-1 requirements catalog with 82 requirements, evidence mapping onto existing modules and automatic conformity assessment from actual data.
Learn moreLegal Register
Register of binding obligations from laws, regulations, official orders and contracts, with relevance assessment, owners, review cycle and obligations at clause level.
Learn moreAccessibility
Accessibility statement under the German BFSG and BITV 2.0 with a public page, automated quick test, guided WCAG 2.2 audit and barrier tracking through to resolution.
Learn moreAudit-proof data protection
Video surveillance
Installations and cameras with their field of view, a selectable legal basis, purpose limitation following the German data protection authorities’ guidance, and evidence that audio recording is irreversibly disabled.
Learn moreCloud Services Registry
Cloud services in use with service definition, data location, subcontractors, evidence with review dates and exit arrangements. The OPS.2.2 requirements can be transferred per service into the implementation plan.
Learn morePolicy Management
Manage policies centrally, assign them precisely and document acknowledgements in a legally sound way.
Learn moreDocument Management
Central DMS for all business-critical documents – with versioning, search and audit trail.
Learn moreDeletion Concept
Automated, audit-proof deletion of personal data with seamless deletion evidence.
Learn moreData Classification
Automatic detection and classification of sensitive data in mailboxes and other sources.
Learn moreWhistleblower System
Anonymous reporting portal with full case management under HinSchG and EU Directive 2019/1937.
Learn moreContract Management
Contracts with requirements, obligations, SLA definitions and deadlines, checked daily and linked to IT systems, processes and the record of processing activities.
Learn moreCookie Scan
Scans your website with a real browser before and after consent, detects cookies, tracking and consent banners, and delivers the data for your cookie declaration.
Learn moreFull transparency over your IT
IT Asset Management
Seamless inventory of hardware, software and licenses with automatic discovery and lifecycle control.
Learn moreAttack Surface Management
Automatic discovery and monitoring of your external and internal attack surface – including shadow IT, data leaks and the email and DNS hardening of your domains.
Learn moreData centre compliance
The data centre as a delimited legal object with derived connected load, a dated scope judgement, a metrics year for PUE, ERF, REF, CER and WUE, the 31 March reporting file and classification under EN 50600.
Learn moreDCIM
Data Center Infrastructure Management with interactive rack builder and floor plans, power, cooling and network simulation, live device status, structured cabling, integrated IPAM, electrical distribution boards with DIN rail layouts and a walkable 3D digital twin. From the meter cabinet to the outside plant.
Learn moreNetwork Topology
Visual topology designer for creating and managing network diagrams by drag-and-drop.
Learn moreLicense Management
Professional software asset and license management with compliance engine, auto-reconciliation and FinOps analytics.
Learn moreCertificate Management
Certificate Lifecycle Management with a central inventory of all TLS/SSL certificates and timely expiry alerts.
Learn moreUptime Monitoring
HTTP, TCP, ping and heartbeat in four states, with content checks, itemised response-time measurement, maintenance windows and rule chain integration.
Learn moreIT Service Management
IT Service Management along ITIL 4: incidents, problems, changes and releases with SLA control, escalations, approvals, satisfaction surveys, inbound email and a self-service portal.
Learn moreVirtualization
VMware vCenter/ESXi, Hyper-V, Proxmox and Nutanix AHV automatically in your inventory: the isidaten agent detects clusters, hosts and VMs and keeps them current without manual upkeep.
Learn moreContainer Inventory
Inventory Kubernetes clusters and Docker hosts automatically: the isidaten agent captures nodes, images and running workloads as assets, with no manual work.
Learn moreMirth Connect
Document HL7 interfaces from Mirth Connect automatically: reads the channels via REST API into the interface register. For hospitals and critical infrastructure.
Learn morePrint Management
Brings printers and MFPs including page counters and consumables from YSoft SafeQ and evaluates print volume and costs per cost center.
Learn moreClient Management
Roll out software, updates and operating systems through your own agent: package catalog, fleet patch level, per-update approval and ring-based rollout with soak time and an abort threshold.
Learn moreDomain Management
Domain inventory with registrar and contract, term and notice period, cost and owners, plus review before expiry and a cockpit that shows the gaps.
Learn morePhysical Access
Locking systems, access areas with protection needs, authorisation groups with review dates, and per-person authorisations with medium, reason, expiry and withdrawal.
Learn moreRollout Management
Deployment of hardware, operating systems and software in waves, with an on-site view for technicians, handover protocol and success verification from your existing connectors.
Learn moreDetect threats & respond
Forensics & evidence handling
Investigations with a work order, legal basis and purpose limitation, evidence admitted only with a hash and witnesses, every handover an immutable link in the chain of custody.
Learn moreCryptography inventory
The register of algorithms in use, key lengths, modes of operation and locations, assessed against BSI TR-02102 and CNSA 2.0, with the question of what must be replaced by when.
Learn moreVulnerability Management
CSAF-based vulnerability management that maps vendor advisories to your assets and prioritizes them.
Learn moreSIEM Integration
Receives events via syslog, webhook or API, normalizes them to OCSF, enriches them with local reference data and MITRE ATT&CK mapping, and turns critical events into managed incidents.
Learn moreFirewall Management
Documents firewall rules, reconciles the live state of your devices automatically and uncovers shadow and redundant rules.
Learn moreSecurity Automation
Automates security tasks via the OSCAL framework – with catalogs, profiles and SSPs per NIST.
Learn moreSecurity Configuration Management
Assesses endpoints daily against 28 bundled hardening benchmarks (DISA STIG, CIS, ANSSI BP-028, BSI, PCI DSS) and creates measures in the ISMS.
Learn moreDeception – Early Warning
Decoy systems with emulated services, breadcrumbs scattered across real workstations and honeytoken accounts in Active Directory. Every access is an early warning with triage, allowlist and alerting.
Learn moreUEBA
Behavior analytics for identities and entities on top of SIEM events, with privacy governance built in: activation lock until a documented legal basis exists, works-agreement profiles and pseudonymization with audited re-identification.
Learn moreContainment Actions
Host isolation, account lockout and session termination straight from the incident or from a rule chain. Every action passes a second-person approval, is logged and sets the containment timestamp on the incident.
Learn moreRemote Support
Remote access is requested, approved under the four-eyes principle, tied to a purpose and a ticket, time-limited and logged without gaps. The transmission itself stays with Intune, SSH or MeshCentral.
Learn morePCI DSS
PCI DSS requirement catalog with conformity assessment, management of the cardholder data environment and the quarterly ASV scans including finding assessment, attestations and due-date reminders.
Learn moreCSPM – Cloud Configuration
Continuous checks of Entra ID, Azure, AWS, Google Cloud and OTC for misconfigurations. Every violation becomes a finding with severity, evidence and remediation guidance, mapped to BSI C5 and further frameworks, with a posture score per account and its history.
Learn morePeople as the first line of defense
E-Learning
Digital training on information security & data protection with learning paths, deadlines and automatic audit evidence.
Learn morePhishing Simulation
Phishing simulations by email and SMS from your own platform, with automatic training assignment, one-click report button and a threat inbox for genuine suspicious mail.
Learn moreHuman Risk
The Human Security Index condenses knowledge, behaviour and security culture into a single figure from 0 to 100, with a minimum group size and co-determination-bound release.
Learn moreGamification
18 point triggers from course completion to a closed compliance gap, 33 badges, ten levels, four tiers, challenges, a streak calendar and leaderboards with cohorts.
Learn moreProcesses & suppliers under control
Supplier Management
Third-party risk management with CRR rating, criticality assessment and a cockpit for all external organizations.
Learn moreSupplier Questionnaires
Questionnaires with automatic scoring, knockout criteria and a public portal where suppliers respond themselves.
Learn moreQuality Management
ISO 9001 QMS as an integrative layer over your existing modules – with a standard-mapping cockpit and auditor export.
Learn moreProcess Modelling
Visual business processes with BPMN elements and swim lanes whose steps can be linked to IT systems, software and the people responsible.
Learn moreOccupational Safety
Occupational safety management to ISO 45001 with risk assessment, DGUV catalog and measures by the STOP principle.
Learn moreFire Safety
Organizational fire safety: register of fire safety installations with inspection deadlines and history, digital fire safety log with PDF export, fire safety regulations A/B/C, escape and rescue plans plus the fire marshal quota per site.
Learn moreThe foundation of the platform
AI Access (MCP)
Model Context Protocol server that securely exposes your GRC data to AI assistants.
Learn moreTrust Center
Public security & compliance page that makes your live compliance data shareable.
Learn moreData Hub
Secure, bundled data integration for on-premise systems with encrypted SaaS connectivity.
Learn moreData Migration
Import from verinice, i-doit, otris, Matrix42, AssetPanda and Kopexa into isidaten – with preview, idempotency and rollback.
Learn moreTeam Chat
Secure internal communication in structured channels – right from incidents and measures.
Learn moreAgent Management
Manages the isidaten agents and their scheduled scans: cron intervals, releases, updates and scan errors in one place.
Learn moreAI Management
Central governance of all AI functions: provider integrations with connection test, AI users, function assignments, permissions, de-identification and activity logs.
Learn moreMobile App
Device-bound sign-in for the isidaten iOS app with QR pairing and revocation, plus the mobile API for tasks, tickets, reports, assets and inspections.
Learn moreConnectors & open API
Connect existing systems and let data flow in automatically instead of maintaining it twice.
Ready to simplify your compliance?
Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.