Acuna is the multi-framework GRC platform built by GRC practitioners for the people who run the program, not just the audit. One interconnected system covers the full compliance lifecycle.
Comply: map requirements across frameworks and surface every requirement with no measure behind it. Implement: turn requirements into owned measures, controls, assets, processes and responsibilities.
Operate: run risks, treatment plans, objectives, documents, tasks and the annual plan day to day.
Assure: prove it works with KPIs, evidence, audits, findings, corrective actions and time bound exceptions. 50+ frameworks run side by side, including ISO 27001, SOC 2, GDPR, Swiss FADP, NIS2, DORA, ISO 9001, ISO/IEC 42001 and the EU AI Act. Cross framework mapping means one measure satisfies many requirements and evidence is reused instead of recollected.
Modules:
- Acuna Core for the compliance lifecycle.
- RBAC for fully customizable roles and data visibility.
- Evaluations for point in time assessments, secure external answer portals and group wide compliance oversight.
- Supplier Shield for third party risk management, questionnaire campaigns and daily OSINT supplier grading.
- Data Privacy Module for ROPA, data flows, DPIAs, DPAs, TIAs, DSARs and personal data breach management.
- Acuna AI Governance for AI system inventory, EU AI Act classification and human oversight.
- Aiko, the AI reasoning layer, answers questions on your own data and suggests mappings, controls, tasks and KPIs.
Flat platform pricing, no per seat games. Data can be hosted in Switzerland, across Europe or in the United States so you control fully where you data lives.
Integrations with Microsoft Entra ID, Microsoft 365, Azure, AWS and GitHub, plus a KPI measurements API.
Built for CISOs, DPOs, heads of compliance, risk teams, vCISOs and MSSPs running multi framework programs in regulated industries.