Capability pages

Risk managementLikelihood × impact on 5-point scales, inherent and residual scores, an interactive heatmap, mitigate / accept / transfer / avoid, acceptance with rationale and stamped approver, 200 revisions per risk.
Audit managementPro+. A read-only auditor portal with email-code verification, 1-60 day access and revocation; auditor comments and incident notes; Prepare for Audit (Enterprise); white-label PDF audit trail.
Reminders and monitoringDue-soon and weekly overdue emails, policy acknowledgement chasers, evidence and vendor expiry digests, daily coverage snapshots, signed webhooks and a REST API.
Business continuityISO 22301 as 25 recurring controls, continuity controls from ISO 27001, NIS2 and DORA, and an incident register with GDPR and NIS2 clocks.
ISMS and controlsEleven frameworks as recurring controls with owners, evidence and reminders; the Statement of Applicability; the process register and links between controls, risks and policies.
Privacy (RoPA and DPIA)Pro+. The GDPR Art. 30 record of processing activities, DPIA screening and the DPIA register, linked to vendors, assets and risks.
Incident managementGDPR 72-hour and NIS2 24h / 72h / one-month clocks, the significant-incident checker and, on Enterprise, a public breach-report portal.
Policy managementEight templates in three languages, versions and approval from Basic; acknowledgement per person and version from Pro.
Supplier managementPro+. Vendors with DPA and certificate links, review and contract-expiry dates, plus the asset inventory.
Trust pagePro+. 59 standard security questions answered once and shared by link; gated answers with access requests on Enterprise.
SecurityEU hosting, AES-256-GCM encryption of records, sign-in, roles, the activity log, the DPA and sub-processors.
Implementation and supportSelf-serve start, the help centre and, on Enterprise, a named implementation specialist and a yearly business review.

All capabilities and their plans

CapabilityWhat it includesPlan
FrameworksISO 27001:2022 (93 Annex A controls plus clauses 4-10), GDPR, NIS2, NEN 7510, DORA, EU AI Act, ISO 27701, ISO 22301, SOC 2, BIO, PCI DSS, run side by side in one workspace1 on Free, 2 on Basic, 5 on Pro, all 11 on Enterprise
Controls and evidenceRecurring controls with owner, due date, description, recommendation; evidence as notes, links and files; locked after completionAll plans
RemindersAssigned, due-soon and weekly overdue emailsAll plans
DashboardControls covered, coverage over time, what needs you nowAll plans
Incident registerGDPR 72-hour and NIS2 24h / 72h / one-month clocks, NIS2 significant-incident checker, timeline, root causeAll plans
Risk registerInherent and residual heatmap, treatment, signed acceptanceBasic and up
Statement of ApplicabilityApplicability and justification per control, approved versions, PDF and XLSXBasic and up
PoliciesVersions, approval workflow, PDF export, 8 starter templatesBasic and up
Evidence validity and expiry alertsValid-until dates per control and per file, daily digestBasic and up
Excel and CSV export; PDF audit trailEvery register; audit trail Dazr-branded on Basic, your name on Pro, white-label on EnterpriseBasic and up
Auditor accessEmail-code verified, 1-60 days, revocable, commentsPro+
Policy acknowledgementPer person and version, weekly reminders after the deadline, exportPro and Enterprise
GDPR registersArt. 30 records of processing and DPIAs, linked to vendors, assets and risks, with PDFsPro and Enterprise
Vendor and asset registersReview and contract-expiry alerts; owner, criticality and classificationPro and Enterprise
Trust pageAnswer security questionnaires once and share a link; gated access requests on EnterprisePro and Enterprise
Prepare for AuditReadiness checks and score per frameworkEnterprise
Public breach-report portalReporting without an account, domain allow-list, proof-of-work, approval queueEnterprise
REST API, webhooks, bulk importRead-only API, HMAC-signed webhooks, Excel/CSV import with column mappingEnterprise
Custom recurrenceYour own review interval per controlEnterprise
Custom dashboards, integrations and framework templatesBuilt and maintained by the Dazr team on requestCustom (on request)

Languages, sign-in and hosting

  • The portal is in English, Dutch, Italian, German, French, Spanish and Polish (light mode only), and so is this website.
  • Sign in with Google, Microsoft or a one-time email code, on every plan.
  • Application data and backups are stored in the EU. Workspace records are encrypted at rest with AES-256-GCM at the application layer.