Risqore
Multi-tenant GRC for consultancies, MSSPs & vCISOs

Run your entire compliance
portfolio from one command center.

Risqore is the GRC platform built for advisory firms. Manage ISO 27001, SOC 2, NIS2, DORA and 9 more frameworks across every client — risk, controls, evidence, audits, AI and a white-label client portal — without a single spreadsheet.

Start your free trial →Explore the platform

Free trial · No credit card · Cancel anytime

risqore.com/partner/board
24
Active clients
87%
Avg. posture
13
Open findings
6
Audits this quarter
Northwind Ltd
ISO 27001 · SOC 2
92%
Helios Bank
DORA · NIS2
78%
Acme Health
HIPAA · ISO 27001
64%

13 frameworks built in · unlimited per client · cross-mapped

ISO 27001SOC 2NIS2DORAGDPRNCA ECCPCI DSSISO 22301ISO 9001HIPAATISAXCyber EssentialsSAMA

Managing many clients on spreadsheets doesn’t scale

If any of this sounds familiar, you’ve outgrown the old way.

Every client in a different file

Versions drift, evidence goes missing, and nobody trusts the master copy.

Audit season is a scramble

Days lost hunting for the screenshot, the policy version, the sign-off.

You can’t grow past a handful

Each new client means more manual work — so you stop saying yes.

The Risqore difference

One platform for your whole book of business

One portfolio

Every client in its own isolated, branded workspace — managed from a single command center.

Answer once

Cross-framework control mapping means evidence and answers carry across ISO, SOC 2, NIS2 and more.

Prove it fast

Trust Center, audit-ready exports and continuous monitoring keep posture defensible in real time.

Built for the people who run compliance for others

If you carry more than one organisation’s posture, Risqore is for you.

Consultancies
GRC & ISO consultancies

Run every engagement from one console — onboard a client, pick frameworks, and deliver a certifiable programme without rebuilding spreadsheets each time.

MSSP / MSP
Managed security providers

Add compliance to your managed services. Give each customer a branded portal and prove posture continuously, not once a year.

vCISO
vCISOs & advisory firms

Carry risk, controls and board-ready reporting across your whole book of clients — and show value every month.

In-house
Multi-entity compliance teams

Manage subsidiaries, regions or business units as isolated workspaces under one corporate roof.

The complete GRC platform — nothing bolted on

From first control to signed audit, every capability your practice needs is built in.

Compliance core

One control library that satisfies every framework you run.

  • Unlimited frameworks per client (13 built in)
  • Single control library across all frameworks
  • Automatic cross-framework control mapping
  • Statement of Applicability (SoA)
  • Evidence vault with ownership & status
  • Gap analysis & control recommendations
  • Certificate lifecycle & renewals
Risk management

Quantify, treat and monitor risk — with a posture that rolls up.

  • Risk register (inherent & residual scoring)
  • Interactive risk heatmap
  • Key Risk Indicators (KRIs)
  • Maturity assessments
  • Treatment & remediation plans
Audit & operations

Everything that turns a programme into evidence on the day.

  • Internal & external audits
  • Auditor portal & interview mode
  • Findings & corrective action plans (CAPs)
  • Remediation tracking
  • Incident & issue management
  • Tasks & workflows
  • User access reviews (UAR)
  • Regulatory obligations register
  • Business continuity (BCM)
  • Assets & sites inventory
Third-party & privacy

Manage the risk you do not directly control.

  • Vendor / supplier risk register
  • Supplier security questionnaires
  • Portfolio third-party risk dashboard
  • Privacy register (GDPR records of processing)
Sky — AI assistant

An expert co-pilot grounded in each client’s own data.

  • Draft policies from a prompt
  • Summarise gaps & next actions
  • Recommend the right evidence
  • Answer framework & control questions
  • Speeds up onboarding and audit prep
Client experience

Surfaces your clients actually see — under your brand.

  • White-label client portal
  • Trust Center — NDA-gated, shareable
  • Policy attestations & acknowledgements
  • Branded, audit-ready report exports
Portfolio command center

Run the whole book of business from one screen.

  • Cross-client board & work queue
  • Audit-readiness reports
  • Executive briefings & ROI dashboard
  • Live regulatory feed
  • Portfolio-wide posture at a glance
Platform & enterprise

Built multi-tenant and secure from the ground up.

  • Strict per-client data isolation
  • White-label branding & custom domain
  • SSO (Google / Microsoft)
  • REST API & webhooks
  • CSV import / export
  • Full audit trail & role-based access
  • 30-day data retention safety net

Live in three steps

1
Spin up a workspace

Create a branded, isolated workspace per client in seconds and switch on the frameworks they need.

2
Map, collect & assess

Controls auto-map across frameworks. Collect evidence, run the risk register, and let Sky draft the heavy lifting.

3
Prove & report

Share a Trust Center, export audit-ready reports, and keep every client green with continuous monitoring.

What changes when you switch

Onboard a client in minutes

A branded workspace plus a ready framework in a few clicks — not a weekend of spreadsheet surgery.

Answer once, satisfy many

Cross-framework mapping carries one piece of evidence across ISO, SOC 2, NIS2 and the rest.

Walk into audits ready

A live evidence vault, control coverage and audit-readiness reports — no last-minute scramble.

Scale without hiring

Run dozens of clients from one command center instead of adding headcount per account.

Win more deals

Send prospects a Trust Center link instead of filling in another 100-row security questionnaire.

Your brand, everywhere

White-label portal, custom domain and branded reports — it’s your product, powered by Risqore.

White-label & multi-tenant

Your brand. Your domain. Your platform.

Every client portal carries your logo and colours. On Enterprise, run it on your own custom domain with SSO — so to your clients it’s entirely your product, with Risqore doing the heavy lifting underneath. Each tenant stays strictly isolated.

Secure and audit-ready by design

The guarantees your clients (and their auditors) expect — first-class, not add-ons.

Strict tenant isolation

Each client’s data is scoped and separated. Cross-tenant access is blocked at the data layer.

Full audit trail

Every meaningful action is logged — who did what, when, in which workspace.

Role-based access

Owner, member, auditor and client roles with least-privilege defaults; SSO on Enterprise.

30-day data retention

Soft-delete with a recovery window protects against accidental loss.

Four packages. Fully modular.

Start small and grow. Every tier includes the full GRC core — higher tiers unlock more clients, seats and capabilities.

Starter

For independent GRC consultants starting out

99/ mo
5 clients3 seats
  • Unlimited frameworks (ISO 27001, SOC 2, NIS2, DORA, NCA ECC …)
  • Controls, risk register & policies
  • Evidence vault & continuous monitoring
  • Audits, CAPs, incidents & tasks
  • Certificate lifecycle & cross-framework mapping
  • …and the full GRC core
Start free trial
Most popular
Advanced

For growing consultancies managing more clients

199/ mo
15 clients8 seats
  • Everything in Starter, plus:
  • Sky — AI assistant
  • Trust Center
Start free trial
Pro

Scale your practice with full platform access

399/ mo
40 clients20 seats
  • Everything in Advanced, plus:
  • White-label branding
  • REST API & webhooks
  • CSV import / export
Start free trial
Enterprise

Unlimited scale for large GRC firms

999/ mo
Unlimited clientsUnlimited seats
  • Everything in Pro, plus:
  • SSO (Google / Microsoft)
  • Custom domain
Talk to us

Prices in EUR, billed monthly. Annual billing saves 20%. Need something custom? Contact us.

Why teams switch to Risqore

vs. spreadsheets

No version chaos, no lost evidence, no audit trail gaps. Everything is mapped, owned, time-stamped and exportable.

vs. single-tenant GRC tools

Those are built for one company. Risqore is built for your whole portfolio — isolated clients, one console, your brand.

vs. hiring to scale

Headcount cost grows per client. Software does not. Take on more engagements without growing the team.

Questions, answered

Who is Risqore for?

GRC and ISO consultancies, MSSPs/MSPs, vCISOs and advisory firms — anyone managing compliance for multiple client organisations from one place. In-house teams use it to manage multiple entities or regions.

Which frameworks are supported?

ISO 27001, SOC 2, NIS2, DORA, GDPR, NCA ECC, PCI DSS, ISO 22301, ISO 9001, HIPAA, TISAX, Cyber Essentials and SAMA — with unlimited frameworks per client and automatic cross-mapping between them.

Is it really multi-tenant?

Yes. Every client lives in a strictly isolated workspace. Your team works across the whole portfolio; each client only ever sees their own data, under your brand.

Can I use my own brand?

On Pro and above you get white-label branding — your logo, colours and client portal. Enterprise adds a custom domain and SSO, so it’s fully your product.

What does the AI assistant do?

Sky drafts policies, summarises gaps, recommends evidence and answers framework questions — grounded in each client’s own data. It accelerates onboarding and audit prep.

How is my data secured?

Strict tenant isolation, role-based access, a full audit trail and a 30-day data-retention safety net on deletion. Authentication supports SSO on Enterprise.

How does billing work?

Pick a package below and start a free trial — no credit card. Subscriptions activate automatically after checkout. Upgrade, downgrade or cancel anytime.

Run your whole portfolio in one place

Start a free trial today — your first branded client workspace is minutes away.

Start free trial →Log in

Free trial · No credit card · Cancel anytime