Built for every size of organisation

The same platform serves a five-person team on the free plan and an organisation with hundreds of users on Enterprise. Nothing is rebuilt when you grow: frameworks, registers, evidence and history stay in the workspace, and the plan only changes what is unlocked.

ProEnterprise
UsersUp to 5Up to 999
Frameworks5All 11
Activity log25,000 events50,000 events
PDF audit trailYour company nameWhite-label: logo, subtitle, footer, signing officer
ReadinessPreview of the gapsPrepare for Audit with full score
IntegrationsExcel / CSV exportPlus REST API, signed webhooks, bulk import
SupportEmailPriority, named implementation specialist, yearly business review

Identity, roles and security

  • Single sign-on with Google or Microsoft (Entra ID work accounts) via OpenID Connect with PKCE, state and nonce, or a one-time email code.
  • Roles: one owner, admins who manage registers and settings, members who work on their assigned controls and read the registers, and external auditors with their own time-limited, read-only login.
  • Sessions: every request is checked against current membership and scoped to your workspace; "sign out everywhere" revokes all sessions.
  • Hosting: application data and backups in the EU; workspace records encrypted at rest with AES-256-GCM at the application layer; no analytics pixels or third-party trackers in the portal.
  • Activity log of every state-changing action, including actions by Dazr support, with search, filters and export; 50,000 events on Enterprise.

Audit and assurance

  • Auditor management: invite external auditors for 1-60 days with email-code verification, revoke at any time, and let them comment on controls.
  • Prepare for Audit: 34 workspace checks plus checks per framework, with a readiness score on the dashboard.
  • White-label PDF audit trail with your logo, subtitle, footer text and signing officer.
  • Risk register with inherent and residual heatmap, treatment and signed acceptance.
  • Gated trust page: publish security answers and let customers request access to the sensitive ones.
  • Public breach-report portal for staff and third parties, with an approval queue into the incident register.

Eleven frameworks in one workspace

ISO 27001:2022, GDPR, NIS2, NEN 7510, DORA, EU AI Act, ISO 27701, ISO 22301, SOC 2, BIO and PCI DSS run side by side, each as its own set of recurring controls. The Statement of Applicability excludes controls that do not apply from controls and coverage. Policies can be linked to controls of several frameworks at once, for example an incident response policy to ISO 27001 A.5.24-A.5.26 and NIS2 Art. 23. Dazr does not map controls between frameworks automatically.

Integration and data

  • REST API (read-only, Bearer keys): workspace, readiness, controls, risks, incidents, vendors, assets and activity; 240 requests a minute and 60,000 a day per key.
  • Webhooks: up to 10 endpoints, HMAC-SHA256 signed, for control, risk, incident, intake and vendor events.
  • Bulk import of vendors, assets and incidents from Excel or CSV, with column mapping and a preview.
  • Custom recurrence: set your own review interval per control.
  • Export every register to Excel or CSV at any time.

Custom: built for you on request

Custom is priced on request, on a contract, and adds, on request, work by the Dazr team: dashboards and reports around your own KPIs, integrations with systems such as ticketing, HR or BI, and your own framework templates next to the eleven built in. Scope and price are agreed per request. sales@dazr.eu