Run your entire compliance
portfolio from one command center.
Risqore is the GRC platform built for advisory firms. Manage ISO 27001, SOC 2, NIS2, DORA and 9 more frameworks across every client — risk, controls, evidence, audits, AI and a white-label client portal — without a single spreadsheet.
Free trial · No credit card · Cancel anytime
13 frameworks built in · unlimited per client · cross-mapped
Managing many clients on spreadsheets doesn’t scale
If any of this sounds familiar, you’ve outgrown the old way.
Versions drift, evidence goes missing, and nobody trusts the master copy.
Days lost hunting for the screenshot, the policy version, the sign-off.
Each new client means more manual work — so you stop saying yes.
One platform for your whole book of business
Every client in its own isolated, branded workspace — managed from a single command center.
Cross-framework control mapping means evidence and answers carry across ISO, SOC 2, NIS2 and more.
Trust Center, audit-ready exports and continuous monitoring keep posture defensible in real time.
Built for the people who run compliance for others
If you carry more than one organisation’s posture, Risqore is for you.
Run every engagement from one console — onboard a client, pick frameworks, and deliver a certifiable programme without rebuilding spreadsheets each time.
Add compliance to your managed services. Give each customer a branded portal and prove posture continuously, not once a year.
Carry risk, controls and board-ready reporting across your whole book of clients — and show value every month.
Manage subsidiaries, regions or business units as isolated workspaces under one corporate roof.
The complete GRC platform — nothing bolted on
From first control to signed audit, every capability your practice needs is built in.
One control library that satisfies every framework you run.
- ✓Unlimited frameworks per client (13 built in)
- ✓Single control library across all frameworks
- ✓Automatic cross-framework control mapping
- ✓Statement of Applicability (SoA)
- ✓Evidence vault with ownership & status
- ✓Gap analysis & control recommendations
- ✓Certificate lifecycle & renewals
Quantify, treat and monitor risk — with a posture that rolls up.
- ✓Risk register (inherent & residual scoring)
- ✓Interactive risk heatmap
- ✓Key Risk Indicators (KRIs)
- ✓Maturity assessments
- ✓Treatment & remediation plans
Everything that turns a programme into evidence on the day.
- ✓Internal & external audits
- ✓Auditor portal & interview mode
- ✓Findings & corrective action plans (CAPs)
- ✓Remediation tracking
- ✓Incident & issue management
- ✓Tasks & workflows
- ✓User access reviews (UAR)
- ✓Regulatory obligations register
- ✓Business continuity (BCM)
- ✓Assets & sites inventory
Manage the risk you do not directly control.
- ✓Vendor / supplier risk register
- ✓Supplier security questionnaires
- ✓Portfolio third-party risk dashboard
- ✓Privacy register (GDPR records of processing)
An expert co-pilot grounded in each client’s own data.
- ✓Draft policies from a prompt
- ✓Summarise gaps & next actions
- ✓Recommend the right evidence
- ✓Answer framework & control questions
- ✓Speeds up onboarding and audit prep
Surfaces your clients actually see — under your brand.
- ✓White-label client portal
- ✓Trust Center — NDA-gated, shareable
- ✓Policy attestations & acknowledgements
- ✓Branded, audit-ready report exports
Run the whole book of business from one screen.
- ✓Cross-client board & work queue
- ✓Audit-readiness reports
- ✓Executive briefings & ROI dashboard
- ✓Live regulatory feed
- ✓Portfolio-wide posture at a glance
Built multi-tenant and secure from the ground up.
- ✓Strict per-client data isolation
- ✓White-label branding & custom domain
- ✓SSO (Google / Microsoft)
- ✓REST API & webhooks
- ✓CSV import / export
- ✓Full audit trail & role-based access
- ✓30-day data retention safety net
Live in three steps
Create a branded, isolated workspace per client in seconds and switch on the frameworks they need.
Controls auto-map across frameworks. Collect evidence, run the risk register, and let Sky draft the heavy lifting.
Share a Trust Center, export audit-ready reports, and keep every client green with continuous monitoring.
What changes when you switch
A branded workspace plus a ready framework in a few clicks — not a weekend of spreadsheet surgery.
Cross-framework mapping carries one piece of evidence across ISO, SOC 2, NIS2 and the rest.
A live evidence vault, control coverage and audit-readiness reports — no last-minute scramble.
Run dozens of clients from one command center instead of adding headcount per account.
Send prospects a Trust Center link instead of filling in another 100-row security questionnaire.
White-label portal, custom domain and branded reports — it’s your product, powered by Risqore.
Your brand. Your domain. Your platform.
Every client portal carries your logo and colours. On Enterprise, run it on your own custom domain with SSO — so to your clients it’s entirely your product, with Risqore doing the heavy lifting underneath. Each tenant stays strictly isolated.
Secure and audit-ready by design
The guarantees your clients (and their auditors) expect — first-class, not add-ons.
Each client’s data is scoped and separated. Cross-tenant access is blocked at the data layer.
Every meaningful action is logged — who did what, when, in which workspace.
Owner, member, auditor and client roles with least-privilege defaults; SSO on Enterprise.
Soft-delete with a recovery window protects against accidental loss.
Four packages. Fully modular.
Start small and grow. Every tier includes the full GRC core — higher tiers unlock more clients, seats and capabilities.
For independent GRC consultants starting out
- ✓Unlimited frameworks (ISO 27001, SOC 2, NIS2, DORA, NCA ECC …)
- ✓Controls, risk register & policies
- ✓Evidence vault & continuous monitoring
- ✓Audits, CAPs, incidents & tasks
- ✓Certificate lifecycle & cross-framework mapping
- …and the full GRC core
For growing consultancies managing more clients
- Everything in Starter, plus:
- ✓Sky — AI assistant
- ✓Trust Center
Scale your practice with full platform access
- Everything in Advanced, plus:
- ✓White-label branding
- ✓REST API & webhooks
- ✓CSV import / export
Unlimited scale for large GRC firms
- Everything in Pro, plus:
- ✓SSO (Google / Microsoft)
- ✓Custom domain
Prices in EUR, billed monthly. Annual billing saves 20%. Need something custom? Contact us.
Why teams switch to Risqore
No version chaos, no lost evidence, no audit trail gaps. Everything is mapped, owned, time-stamped and exportable.
Those are built for one company. Risqore is built for your whole portfolio — isolated clients, one console, your brand.
Headcount cost grows per client. Software does not. Take on more engagements without growing the team.
Questions, answered
GRC and ISO consultancies, MSSPs/MSPs, vCISOs and advisory firms — anyone managing compliance for multiple client organisations from one place. In-house teams use it to manage multiple entities or regions.
ISO 27001, SOC 2, NIS2, DORA, GDPR, NCA ECC, PCI DSS, ISO 22301, ISO 9001, HIPAA, TISAX, Cyber Essentials and SAMA — with unlimited frameworks per client and automatic cross-mapping between them.
Yes. Every client lives in a strictly isolated workspace. Your team works across the whole portfolio; each client only ever sees their own data, under your brand.
On Pro and above you get white-label branding — your logo, colours and client portal. Enterprise adds a custom domain and SSO, so it’s fully your product.
Sky drafts policies, summarises gaps, recommends evidence and answers framework questions — grounded in each client’s own data. It accelerates onboarding and audit prep.
Strict tenant isolation, role-based access, a full audit trail and a 30-day data-retention safety net on deletion. Authentication supports SSO on Enterprise.
Pick a package below and start a free trial — no credit card. Subscriptions activate automatically after checkout. Upgrade, downgrade or cancel anytime.
Run your whole portfolio in one place
Start a free trial today — your first branded client workspace is minutes away.
Free trial · No credit card · Cancel anytime