GRC Platform

One integrated workspace for multi-framework compliance.

Comply, Implement, Operate, and Assure: four panes that cover the full compliance lifecycle at one organization-based price.

ISO 27001SOC 2NIS2DORAGDPRNIST CSF50+ total

What Acuna does

Acuna is a GRC platform with four integrated panes: Comply, Implement, Operate, and Assure. It covers multi-framework requirement mapping, control ownership, recurring task execution, and audit-readiness evidence management in a single organization-priced subscription.

One lifecycle. Four focused panes.

Each pane has a clear job. Together they replace the spreadsheets, email threads, and point tools that fragment most compliance programs.

P01

Comply: Map requirements across frameworks without duplicate effort

  • 50+ frameworks plus custom YAML/CSV imports
  • Cross-framework mapping with curated reference measures
  • AI mapping suggestions with confidence scoring
Learn about Comply ›
P02

Implement: Turn requirements into owned, operational controls

  • Control library with ownership, status, and evidence links
  • Process and third-party registers tied to controls
  • Bulk updates for owners, maturity, scope, and relationships
Learn about Implement ›
P03

Operate: Run recurring compliance execution day-to-day

  • Task engine with table and Kanban execution views
  • Recurring task health rolls up into control posture
  • Objectives, risk treatment plans, and linked action tracking
Learn about Operate ›
P04

Assure: Prove readiness with evidence and continuous monitoring

  • Evidence lifecycle: Draft, Submitted, Approved, Expired
  • Audit-readiness view to surface control evidence gaps early
  • KPI engine with manual, computed, connector, and API sources
Learn about Assure ›

Extend your program with purpose-built modules.

Each module connects to your controls, evidence, and tasks. No separate logins. No re-keying data.

M01

Supplier Shield · TPRM

Assess and monitor every supplier against DORA, NIS2, and ISO 27001 controls. Continuous OSINT scoring, automated assessment campaigns, and a regulator-ready audit trail, fully integrated into your GRC workspace.

M02

Data Privacy Management

Register processing activities, run DPIA workflows, map your data, and track privacy compliance tasks, all in one connected module.

M03Soon

Acuna AI Governance

The complete management system around what ISO/IEC 42001 and the EU AI Act demand: a register of every AI system, risk classification, and human oversight.

M04

Evaluations

Point-in-time assessments across your frameworks, with findings, exceptions, and remediation tracked through to closure.

M05

RBAC · Access control

Roles, permissions, and data visibility scoped by module, object, and tag, with least-privilege access and a full audit trail.

M06

Breach and sanction

Grade every vendor's security continuously across nine domains, and get alerted the moment a supplier's posture drops or a breach is reported.

M07

Aiko+ · AI assistant

Ask your compliance programme a question in plain language and get an answer grounded in your own data. Aiko+ drafts evaluations and mappings; your team confirms every one.

M08

D&B Credit Score

Add a vendor's financial health to their risk profile: payment behaviour, failure prediction, and a business credit rating from Dun & Bradstreet.

M09Soon

Trust Center

A public-facing page that shares your security posture, certifications, and subprocessor list with prospects and customers.

Your entire GRC program. One workspace.

Talk to the Acuna team and see the platform working on your frameworks, team structure, and compliance scope.

Acuna GRC Platform: Comply, Implement, Operate, Assure | Acuna