Product

The complete GRC platform for security & data protection

77 modules in seven pillars – consistently integrated so data is maintained only once and works together across all areas. Explore every module in detail.

ISMS & Risk

Manage information security

Risk Register

A central register to capture, assess and link your risks to assets, people and processes.

Learn more

Audit Management

The complete audit lifecycle: planning, execution, findings, measures and follow-up.

Learn more

Emergency Kit

Builds an encrypted, signed emergency package with its own offline viewer from your ISMS data and keeps it ready on emergency laptops. It is opened with a printed key from the safe.

Learn more

Emergency Management (BCM)

Enterprise Business Continuity Management to ISO 22301, BSI 200-4, NIS2 and DORA – from BIA to war room.

Learn more

Effectiveness Assessment

Systematic assessment of your security controls’ effectiveness to ISO 27001 – with trend dashboards.

Learn more

WiBA – Path to Basic Protection

The 19 BSI WiBA checklists with 258 questions, answered in a guided flow: with fulfilment status, effort estimates, ownership and history. Every answer is credited towards IT-Grundschutz via the official mapping.

Learn more

KPI Cockpit

Define, configure and measure ISMS metrics with visual dashboards and trend analyses.

Learn more

Cyber Risk Policy

A framework to define cyber risks, security objectives and policies with automated checks and findings.

Learn more

NIS2 file

Scope determination under Section 28, registration with the BSI under Sections 33 and 34, obligations catalogue under Sections 30 and 31, evidence cycle under Section 39, management duties under Section 38, supervisory correspondence under Sections 61 and 62, and reporting under Section 32.

Learn more

DORA

The requirements of Regulation (EU) 2022/2554 as auditable controls with gap analysis, plus the register of information on ICT third-party providers under Article 28(3), the three-stage reporting workflow and the testing programme up to TLPT.

Learn more

CRA Compliance

Conformity assessment under the EU Cyber Resilience Act: Annex I control catalog, reporting chain for the 24/72-hour deadlines and declaration of conformity, mapped to evidence from your existing modules.

Learn more

B3S Standards

Sector-specific security standards under § 39 BSIG: requirement catalogs per critical-infrastructure sector (hospital, statutory health/care insurance), scopes with SoA, automated as-is checks, RUN maturity and § 39 audit report.

Learn more

NIS2 Reporting

Reporting chain under § 32 BSIG / Art. 23 NIS2: early warning in 24 hours, notification in 72, interim and final report, with deadline alerts, per-stage export and a PDF reporting file.

Learn more

Rule Chains

Thirteen triggers from the ISMS, SIEM, attack surface scanning, uptime monitoring and behaviour analytics, with condition checks, action and task creation, escalation stages and an execution log.

Learn more

Checklists

Flexible checklists with templates for ISO 27001, GDPR and BSI IT-Grundschutz – including progress and escalation.

Learn more

Classified Information Protection

Personnel classified protection under SÜG and physical protection under VSA/GHB in one solution.

Learn more

Project Registry

Systematic recording and classification of projects to TISAX (VDA ISA) and ISO/IEC 27001.

Learn more

FitSM

The complete FitSM-1 requirements catalog with 82 requirements, evidence mapping onto existing modules and automatic conformity assessment from actual data.

Learn more

Legal Register

Register of binding obligations from laws, regulations, official orders and contracts, with relevance assessment, owners, review cycle and obligations at clause level.

Learn more

Accessibility

Accessibility statement under the German BFSG and BITV 2.0 with a public page, automated quick test, guided WCAG 2.2 audit and barrier tracking through to resolution.

Learn more
Data Protection & GDPR

Audit-proof data protection

IT Asset & Network

Full transparency over your IT

IT Asset Management

Seamless inventory of hardware, software and licenses with automatic discovery and lifecycle control.

Learn more

Attack Surface Management

Automatic discovery and monitoring of your external and internal attack surface – including shadow IT, data leaks and the email and DNS hardening of your domains.

Learn more

Data centre compliance

The data centre as a delimited legal object with derived connected load, a dated scope judgement, a metrics year for PUE, ERF, REF, CER and WUE, the 31 March reporting file and classification under EN 50600.

Learn more

DCIM

Data Center Infrastructure Management with interactive rack builder and floor plans, power, cooling and network simulation, live device status, structured cabling, integrated IPAM, electrical distribution boards with DIN rail layouts and a walkable 3D digital twin. From the meter cabinet to the outside plant.

Learn more

Network Topology

Visual topology designer for creating and managing network diagrams by drag-and-drop.

Learn more

License Management

Professional software asset and license management with compliance engine, auto-reconciliation and FinOps analytics.

Learn more

Certificate Management

Certificate Lifecycle Management with a central inventory of all TLS/SSL certificates and timely expiry alerts.

Learn more

Uptime Monitoring

HTTP, TCP, ping and heartbeat in four states, with content checks, itemised response-time measurement, maintenance windows and rule chain integration.

Learn more

IT Service Management

IT Service Management along ITIL 4: incidents, problems, changes and releases with SLA control, escalations, approvals, satisfaction surveys, inbound email and a self-service portal.

Learn more

Virtualization

VMware vCenter/ESXi, Hyper-V, Proxmox and Nutanix AHV automatically in your inventory: the isidaten agent detects clusters, hosts and VMs and keeps them current without manual upkeep.

Learn more

Container Inventory

Inventory Kubernetes clusters and Docker hosts automatically: the isidaten agent captures nodes, images and running workloads as assets, with no manual work.

Learn more

Mirth Connect

Document HL7 interfaces from Mirth Connect automatically: reads the channels via REST API into the interface register. For hospitals and critical infrastructure.

Learn more

Print Management

Brings printers and MFPs including page counters and consumables from YSoft SafeQ and evaluates print volume and costs per cost center.

Learn more

Client Management

Roll out software, updates and operating systems through your own agent: package catalog, fleet patch level, per-update approval and ring-based rollout with soak time and an abort threshold.

Learn more

Domain Management

Domain inventory with registrar and contract, term and notice period, cost and owners, plus review before expiry and a cockpit that shows the gaps.

Learn more

Physical Access

Locking systems, access areas with protection needs, authorisation groups with review dates, and per-person authorisations with medium, reason, expiry and withdrawal.

Learn more

Rollout Management

Deployment of hardware, operating systems and software in waves, with an on-site view for technicians, handover protocol and success verification from your existing connectors.

Learn more
Security Operations

Detect threats & respond

Forensics & evidence handling

Investigations with a work order, legal basis and purpose limitation, evidence admitted only with a hash and witnesses, every handover an immutable link in the chain of custody.

Learn more

Cryptography inventory

The register of algorithms in use, key lengths, modes of operation and locations, assessed against BSI TR-02102 and CNSA 2.0, with the question of what must be replaced by when.

Learn more

Vulnerability Management

CSAF-based vulnerability management that maps vendor advisories to your assets and prioritizes them.

Learn more

SIEM Integration

Receives events via syslog, webhook or API, normalizes them to OCSF, enriches them with local reference data and MITRE ATT&CK mapping, and turns critical events into managed incidents.

Learn more

Firewall Management

Documents firewall rules, reconciles the live state of your devices automatically and uncovers shadow and redundant rules.

Learn more

Security Automation

Automates security tasks via the OSCAL framework – with catalogs, profiles and SSPs per NIST.

Learn more

Security Configuration Management

Assesses endpoints daily against 28 bundled hardening benchmarks (DISA STIG, CIS, ANSSI BP-028, BSI, PCI DSS) and creates measures in the ISMS.

Learn more

Deception – Early Warning

Decoy systems with emulated services, breadcrumbs scattered across real workstations and honeytoken accounts in Active Directory. Every access is an early warning with triage, allowlist and alerting.

Learn more

UEBA

Behavior analytics for identities and entities on top of SIEM events, with privacy governance built in: activation lock until a documented legal basis exists, works-agreement profiles and pseudonymization with audited re-identification.

Learn more

Containment Actions

Host isolation, account lockout and session termination straight from the incident or from a rule chain. Every action passes a second-person approval, is logged and sets the containment timestamp on the incident.

Learn more

Remote Support

Remote access is requested, approved under the four-eyes principle, tied to a purpose and a ticket, time-limited and logged without gaps. The transmission itself stays with Intune, SSH or MeshCentral.

Learn more

PCI DSS

PCI DSS requirement catalog with conformity assessment, management of the cardholder data environment and the quarterly ASV scans including finding assessment, attestations and due-date reminders.

Learn more

CSPM – Cloud Configuration

Continuous checks of Entra ID, Azure, AWS, Google Cloud and OTC for misconfigurations. Every violation becomes a finding with severity, evidence and remediation guidance, mapped to BSI C5 and further frameworks, with a posture score per account and its history.

Learn more

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.