Insights
Welcome.
Set up your workspace
Seven short steps. Your progress is saved, so you can stop at any time.
What needs you now
Controls
Your assigned tasks come first. Use the filter to switch between scopes.
Frameworks
Turn on a framework and we seed its full control list as scheduled review tasks. Disable to remove all.
Statement of Applicability
For every control, record whether it applies to you, why, and how far it is implemented (ISO/IEC 27001:2022 clause 6.1.3 d). Excluded controls drop out of task lists, coverage, reminders and readiness.
Approved versions
Prepare for Audit
A live checklist of what an auditor asks for, computed from your workspace. Fill in any missing facts inline. Each item maps to a real-world question on a real-world audit.
Risk register
Identify, score and track mitigation of information-security risks. Score = likelihood × impact (max 25).
Heat map
By status
Click a status to filter the list.
All risks
Click a risk to open it.
Policies
Write, approve and publish your security policies, and track who has read them. ISO 27001 A.5.1 asks for policies that are approved by management, published and acknowledged by staff.
Incidents
Track what went wrong and how you handled it. Severity, timeline, who you notified, what you fixed.
Incidents per month, by severity
Vendors & sub-processors
Track every third party that touches your data: their DPA, their SOC 2 / ISO 27001, when each was last reviewed, and when it expires. ISO 27001 Annex A.5.19 and GDPR Article 28 both expect this register.
Asset inventory
Servers, laptops, SaaS apps, repositories - the things in scope for your audit. Every framework asks for this; here is one canonical list with owners and criticality.
Business processes
The processes your organisation runs on, with the controls, risks, systems, vendors and processing activities behind each one. Auditors use this to see that what matters most is actually covered.
Processing activities
Your record of processing activities (GDPR Art. 30): what personal data you process, why, on which legal basis, who receives it and how long you keep it. Export it as a PDF when a supervisory authority asks for it.
Data protection impact assessments
DPIAs for high-risk processing (GDPR Art. 35): describe the processing, weigh necessity, assess the risks to people, record the measures, the DPO's advice and the approval.
API & webhooks
Plug Dazr Compliance into your existing ITSM, SIEM or chat. Read tasks, risks and incidents via the REST API; receive webhooks when state changes.
API key
Send this as a Bearer token to /api/compliance-public. The key is read-only: it can read tasks, risks, incidents, vendors, assets and the activity log, but cannot change anything. Treat it like a password and rotate it the moment it leaks.
Webhooks
We POST a JSON event to each URL when something happens. Every webhook gets its own signing secret: verify the X-Dazr-Signature header (HMAC-SHA256 of "timestamp.body"). Delivery is best-effort: 5-second timeout, no retries. Payload and signature docs
API reference
Read-only REST. Send Authorization: Bearer dzc_... on every request to https://compliance.dazr.eu/api/compliance-public. Full reference, query parameters and copy-paste examples on the API documentation page
GET?action=meGET?action=readinessGET?action=list-tasks · framework= status= assignee= updatedSince=updatedSince for incremental sync.GET?action=get-task&id=...GET?action=list-risks · status= minScore=minScore=17 for criticals.GET?action=get-risk&id=...GET?action=list-incidents · status= severity= reportedOnly=trueGET?action=get-incident&id=...GET?action=list-vendorsGET?action=list-assetsGET?action=list-activity&limit=100{ error, detail } with the appropriate HTTP status. The API documentation page has the full error code list and worked examples.
Activity log
Every action that happened in this workspace, newest first. Used by you and by an external auditor as part of the audit trail.
Events per day
Import & export
Bring data in from spreadsheets, or take a snapshot out for review, backup, or to hand to your auditor. Excel and CSV both work.
Export
Pick what you want and the format. Excel puts every register on its own sheet; CSV gives one file per register, bundled in a ZIP when you pick more than one.
Import
Upload a spreadsheet, map columns to platform fields, fix any required fields with a default, and submit. We'll skip any row missing required values rather than fail the whole batch.
Members
Invite people from your team. Pending invites count toward your seat limit until accepted or revoked.
Invite a teammate
They get an email with an invite link. They open it and sign in with that same address to join. The link is valid for 14 days.
Team
Owners can promote admins; admins can manage tasks and members. Members can complete their own tasks.
Auditors
Invite an external auditor for a fixed period. They get read-only access to your tasks, evidence and history. They can leave comments. Access expires automatically.
Invite an auditor
Sets up a time-boxed session of up to 60 days. We email them a private link that only works after they confirm a code sent to that address. You see the link once, right after creating it.
Active sessions
Revoke any time. Members can see auditor comments on tasks.
Trust page
Answer the standard NIS2, ISO 27001 and GDPR supplier questions once, then share one link with customers instead of filling in yet another questionnaire.
Profile & settings
You're signed in as . Compliance Portal is passwordless; sign in with the 6-digit code we email.
Your Dazr Identity
Your name, avatar, sign-in devices, address and organisations are managed in Dazr Identity, the one account for every Dazr product. Settings below apply to this workspace only.
Language
Sets the language for the entire portal: navigation, page titles, help articles, tour cards and prompts. Changes apply immediately.
Account
The email is the unique identifier we use for sign-in and assignments. To change it, sign out and sign in with the new address (you'll get a fresh workspace; existing assignments stay attached to the old address).
Notifications
All reminders go to your sign-in email. Toggle each type independently; changes save automatically.
NIS2 incident classification
Which provider types from Implementing Regulation (EU) 2024/2690 apply to your organisation? The incident form uses this to ask the right questions and test the sector thresholds. Leave all unticked to use the general criteria only.
Danger zone
Leaving the workspace removes your access. The owner or an admin can re-invite you any time.
Subscription
Self-serve up to Enterprise, billed monthly via Mollie. VAT is calculated from your billing country and VAT number and shown on every invoice. Custom is the only tier that needs a contract.
Free
- 1 user, 1 framework (ISO 27001, GDPR or NIS2)
- Tasks and evidence
- Incident register with GDPR and NIS2 clocks
- NIS2 significant-incident checker
- Compliance dashboard
- Activity log: 2,000 events
- Everything in Free, plus:
- 2 frameworks, 1 user
- Risk register and Statement of Applicability
- Policies with versions and approval
- Custom tasks
- Evidence validity and expiry alerts
- Excel / CSV export
- Audit-trail PDF (Dazr-branded)
- Activity log: 5,000 events
- Everything in Basic, plus:
- 5 frameworks (incl. ISO 27701, ISO 22301, SOC 2), up to 5 users
- External auditor access
- Policy acknowledgement tracking
- GDPR RoPA + DPIA registers
- Vendor & asset registers
- Public trust page
- PDF with your company name
- Activity log: 25,000 events
- Everything in Pro, plus:
- All 11 frameworks, up to 999 users
- Prepare for Audit and readiness score
- Public breach-report portal
- Gated trust page with access requests
- REST API + webhooks, bulk import
- White-label PDF, custom recurrence
Show moreShow fewer
- Named implementation specialist
- Yearly business review
- Custom dashboards and integrations on request
- Priority support
- Activity log: 50,000 events
Billing details
Required before checkout. We use this on your invoices.
Save your company once in Dazr Identity and pick it here next time. Add an organisation
These details aren't in your Dazr Identity organisations yet. Add to Dazr Identity
PDF branding
How your audit-trail PDF exports look.
Recent payments
Processed by Mollie, our European payment provider. Download a VAT invoice for every paid payment.
Comments