The DGRC platform
Governance, Risk & Compliance
DGRC is your comprehensive platform for effectively managing your cybersecurity and data protection program, in accordance with recognized standards (ISO 27001, NIST, LPD, etc.) or your own management system.
Key features
Dashboard & KPIs
View the status of your security and compliance program in real time with customizable key performance indicators.
- Tracking overdue tasks and activities
- Overview of critical risks
- Excel exports and imports possible
Cyber risk analysis & compliance
Identify, assess, and address your risks in a structured way with our integrated risk analysis engine.
- Customizable risk matrix
- Documented treatment plans
- Assigned managers and validators
- Complete history of changes
Activity management: managers, validators & monitoring
Each activity has a manager and a validator. Document, track, and measure progress with clear statuses.
- Assignment of managers and validators
- Status: To do, In progress, Completed, Overdue
- Documentation and attachments
Security & compliance of the platform
Hébergement en Suisse
Vos données sont hébergées exclusivement en Suisse dans des data centers de haute disponibilité et sécurité. La plateforme peut également être hébergée au sein de votre infrastructure.
Développée par société suisse certifiée ISO 27001
DGRC est développée et maintenue par une entreprise suisse certifiée ISO 27001, garantissant les plus hauts standards de sécurité dès la conception.
Accès sécurisés par double authentification
Protection de votre compte par authentification à deux facteurs (2FA).
Regular penetration testing
The platform undergoes regular penetration testing by independent experts to proactively identify and correct any potential vulnerabilities.
End-to-end encryption
All data is encrypted in transit and at rest, ensuring its confidentiality at all times.
Daily automatic backups
Your data is backed up automatically every day.
Why choose DGRC
Flexible & Customizable
Adapt the platform to your standards (ISO 27001, NIST, LPD, Cyber-Safe) or create your own management system.
Quick start with preconfigured examples
Avoid starting from scratch and save valuable time: The platform can be delivered with several examples already integrated: lists of safety activities, risk analyses, objectives, etc.
Mastery of your management system
Centralize and control the management of your management system.
Support from industry experts
Get support from security engineers and data protection lawyers who manage multiple management systems themselves.
FAQ
DGRC platform
Why use DGRC instead of Excel?
Excel quickly reaches its limits as your program becomes more structured: multiple files circulating, diverging versions, no tracking of who changed what, and manual follow-ups for every deadline. DGRC centralizes everything in one place: assigned owners and approvers, clear progress statuses, a complete change history, and a real-time dashboard. You gain reliability, traceability, and peace of mind — exactly what ISO 27001 or Cyber-Safe auditors expect, and probably what you expect too.
How does DGRC help me monitor my security program?
The platform provides a dashboard with customizable key indicators that give you a real-time view of the status of your program. At a glance, you can see overdue tasks and activities, critical risks requiring attention, and overall progress. Data can be imported from and exported to Excel as needed, and vice versa.
How does risk analysis work in DGRC?
DGRC includes a structured risk analysis engine. You can identify, assess, and treat your current and residual risks, document your treatment plans, assign owners and approvers, and maintain a complete history of changes. This ensures that every decision remains traceable and justifiable.
How does the platform facilitate task and responsibility tracking?
Each activity has a clearly identified owner and approver. You can track progress through explicit statuses (to do, in progress, completed, overdue) and attach documentation and supporting evidence directly to activities. Everyone knows what they need to do, and nothing falls through the cracks.
Do I have to build everything from scratch?
No. The platform can be delivered with pre-built examples: security activity lists, risk analyses, objectives, and more. You start from a concrete foundation that you can adapt to your specific context, saving you valuable time during setup. You also benefit from the support of security engineers and data protection lawyers who manage several management systems themselves.