Platform

Everything your ISMS needs, in one place.

Registers, roles, audit trails, review workflows, and reporting - built specifically around ISO/IEC 27001, not bolted on afterward.

Registers

Two registers, live today.

Each register comes with ownership, classification, scheduled reviews, and a complete history - no add-ons required.

Live

Asset Register

A single, current catalogue of everything that needs protecting - hardware, software, data, people, and services - with clear ownership.

Full asset catalogue

Hardware, software, data, people, and services in one searchable inventory.

Ownership & classification

Every asset has a named owner and a classification level.

CIA ratings

Confidentiality, Integrity, and Availability rated Low / Medium / High per asset.

Scheduled reviews

3, 6, or 12-month review cycles configured per asset or asset type.

Full change history

Non-destructive history - every edit is recorded, nothing is overwritten.

Export & filters

Excel/CSV export plus search and filters across every field.

Live

Risk Register

Catalogue risks against your assets, score them consistently, and track treatment through to closure.

Risk catalogue

Category, threat, and vulnerability captured for every risk.

Likelihood × impact scoring

Consistent Low / Medium / High / Critical scoring across the register.

Treatment tracking

Accept, Mitigate, Transfer, or Avoid - tracked with an owner and plan.

Residual risk comparison

Before-and-after view of risk once treatment is applied.

Status flow

Open → In Treatment → Closed, visible at a glance.

Linked to assets

Every risk ties back to the asset(s) it affects.

Access & roles

A two-layer access model, down to the record.

A module must be enabled for your organisation and a user must be individually granted access before they can see it.

Role What they can do
ISMS Administrator Owns the ISMS day-to-day - manages registers, assigns record ownership, runs reviews, and grants Standard Users access to specific modules and records.
Standard User Works within the modules and records they've been granted - updating assets, risks, or actions they own, without visibility into the rest of the system.
Auditability

A record history that even admins can't rewrite.

Every change is captured permanently, so your evidence trail is exactly what an auditor expects to see - no gaps, no silent edits.

Field-level change detail

Old value → new value, captured for every field on every record.

Actor + timestamp on every entry

Know exactly who changed what, and when.

Immutable history

History entries can't be edited or deleted — not even by System Administrators.

Cross-register audit log

Search history across Asset, Risk, and every future register from one place.

Field: Owner
Field: CIA Rating
Field: Status
Field: Classification
Review workflows

Reviews that run themselves - until you need to step in.

Configure once, and let the platform chase the follow-through.

Configurable cycles

Set review cycles per record - 3, 6, or 12 months.

Automated reminders

Owners are reminded automatically as a review date approaches.

Overdue escalation

Overdue items escalate to administrators so nothing sits idle.

Outcome capture

Recording a review outcome automatically sets the next review date.

Support & reporting

Visibility for your team, help when you need it.

In-app ticketing

Raise tickets with priority and attachments, and follow threaded updates through to resolution.

OpenIn ProgressClosed

Dashboards & reporting

Filterable views across registers so admins can see status, ownership, and risk exposure at a glance.

Review reports

Purpose-built reports for upcoming and overdue reviews, ready to export ahead of an audit.

What's next

The platform is built to grow with your ISMS.

Three more registers are planned next.

Incident Register

Coming soon

Log, triage, and close out security incidents with a full record trail.

Annex A.5.24–A.5.28

Supplier Register

Coming soon

Track third-party risk, contracts, and supplier due diligence.

Annex A.5.19–A.5.22

Policy Register

Coming soon

Centralise policy versions, approvals, and review cycles.

Clause 5.2 / A.5.1

See ISO 360 Plus on your own data.

Create an account, enable Asset and Risk Registers, and invite your team today.