CISO Assistant

GRC can be tough:
let CISO Assistant do the heavy lifting for you

Cyber security program management can be challenging regardless of the size of your company. CISO Assistant one-stop-shop approach provides a pragmatic way to handle the complexity of GRC (Governance, Risk and Compliance) and make the tools work for you instead of the other way around.

CISO Assistant Octopus

Use cases

Discover how CISO Assistant can help for various use cases, providing a pragmatic approach to drive your cyber security program.

Multi-Framework Compliance
150+ frameworks, one platform

Description

Organizations face an ever-growing landscape of regulations and standards — NIS2, DORA, ISO 27001, SOC 2, GDPR and more. Managing them in silos means duplicated effort, inconsistent controls, and audit fatigue. The challenge is not just compliance, but doing it efficiently across all frameworks at once.

Benefits

CISO Assistant ships with over 150 built-in frameworks and lets you create custom ones. Its automatic mapping engine links your security controls to requirements across all frameworks at once — assess once, comply everywhere. Preconfigured compliance journeys, customizable reports, and DORA ROI reporting make it easy to demonstrate progress to auditors, regulators, and the board.

Risk-Driven Security Program
From assessment to treatment

Description

Risk assessment is the foundation of any security program, yet most teams still rely on scattered spreadsheets and manual processes. Keeping risk registers current, aligning them with evolving threats, and tracking treatment plans across the organization becomes unsustainable as complexity grows.

Benefits

CISO Assistant supports ISO 27005 and EBIOS RM methodologies natively, with built-in cyber risk quantification (CRQ) and business impact analysis (BIA). Manage multiple risk assessments per project, track treatment plans with assigned owners and deadlines, and leverage threat and control libraries to build on previous work. Everything stays connected — from risk scenarios to remediation actions — giving you a live, actionable view of your security posture.

Audit & Evidence Management
Continuous proof, zero scramble

Description

When audit season arrives, teams scramble to collect evidence, chase stakeholders, and compile findings under tight deadlines. Between internal audits, penetration tests, and external certifications, the volume of findings to track and evidence to maintain grows exponentially.

Benefits

CISO Assistant lets you run audit campaigns, collect and manage evidence continuously, and track findings from pentests, audits, and assessments in one place. Build homologation files, maintain a complete audit log, and set up automatic reminders so evidence stays fresh. Process owners document their controls once and refresh evidence on schedule — no more last-minute fire drills.

Third-Party Risk Management
Assess, monitor, report

Description

Your security posture extends well beyond your own perimeter. Suppliers, partners, and service providers introduce risks that are hard to track with ad-hoc questionnaires and email threads. Regulatory pressure — NIS2, DORA — now demands structured third-party risk management.

Benefits

CISO Assistant provides a dedicated third-party management module to assess, track, and report on supplier and partner risk. Leverage built-in or custom frameworks to run structured evaluations, assign owners, and monitor remediation over time. Combined with customizable dashboards and automated notifications, you maintain continuous visibility over your extended attack surface.

GRC at Scale
Govern, collaborate, report

Description

As organizations grow, GRC activities fragment across departments, tools, and methodologies. Without a unified platform, CISOs lose visibility, teams duplicate work, and reporting becomes a manual exercise that consumes more time than the security work itself.

Benefits

CISO Assistant is built for multi-team, multi-project governance. Flexible RBAC and SSO (SAML & OIDC) ensure the right people access the right scope. Collaboration features with task assignment, automatic notifications, and periodic task management keep everyone aligned. Integrated analytics, customizable KPIs, and dashboards give CISOs a real-time aggregated view — from individual project status to organization-wide security posture.

AI-Augmented GRC
Your models, your data

Description

AI is transforming how security teams work, but GRC data is sensitive by nature — risk assessments, audit findings, compliance gaps. Sending this data to public AI services is a non-starter for most organizations. The question is not whether to use AI, but how to do it without compromising confidentiality.

Benefits

CISO Assistant integrates AI natively through MCP (Model Context Protocol) and an embedded AI chat that works with your own models. Get intelligent suggestions for risk scoring, control mapping, and gap analysis — all processed within your environment. Whether deployed on-premises or in your private cloud, your GRC data never leaves your perimeter and is never used to train external models.

Open Source & Sovereign
Full control, zero lock-in

Description

Vendor lock-in, opaque SaaS platforms, and data residency concerns are real barriers for security-conscious organizations. Many GRC tools force you into rigid pricing, proprietary formats, and cloud-only deployments that conflict with sovereignty requirements.

Benefits

CISO Assistant is open source at its core, with a free community edition and a Pro edition available in SaaS or on-premises. Available in 23+ languages, it adapts to global teams. Full API, CLI, and n8n integration enable automation and fit into your existing toolchain. Import and export your data freely — you own it, always. Whether you're a consultant managing multiple clients or an enterprise with strict data sovereignty needs, CISO Assistant gives you full control over your GRC platform.

Simple and flexible pricing

Check out the pricing page for more details

FAQ

How does the pricing work?

You need seats only for contributors (editors); readers are free up to 100 readers. Beyond that, reach out to the team for a readers' license package.
Both Pro SaaS and Pro on-premises also offer unlimited-seat options if you'd rather not count contributor seats.

Can I move my data between environments?

Yes, with built in data export and import capabilities, you can move your data between different instances, both cloud or on-premises.

What is the support model?

The standard support plan covers business hours over a business week. Pro subscriptions include priority support; for critical systems requiring more than that, reach out to the team to discuss the options.

I need custom features.

Custom features are available on the Pro plan, based on quotation. Any customization is covered by the Pro support plan.

I need help setting up GRC practices.

In addition to CISO Assistant tooling, you can reach out to the team to get a quotation for a GRC acceleration package that includes coaching sessions and interviews to set up GRC practices for your organization.

I have highly sensitive data.

Our cloud instance is deployed on EU infrastructure, following the best practices and standards for cloud security. The on-premises setup is also an option for use cases involving critical information. More details are available on our security page.

Can I use AI features, and where does my data go?

CISO Assistant includes a local AI engine, available in both the Community edition and the Pro plan: you bring your own model, and it runs in your own environment or in your dedicated cloud instance, so your data stays within your perimeter.
A managed model option for the SaaS version is currently being developed.

How long can I keep the trial instance?

30 days.

Is the community edition free forever?

Yes.

I'm an integrator looking to rebrand the solution for my customers.

We have a white label program that we can discuss.

I'm a solo consultant and don't want to pay for each one of my customers.

You only pay contributor seats since readers are free.

I would like to contribute.

This is possible, check the contributions guide on our GitHub.

What is the OSS license?

AGPLv3.

I already have a lot of risks assessments, can I import them at once?

Yes. As long as they share the same structured format in CSV or Excel, the data import wizard in the pro version will pick them up. The API is also available in every edition if you prefer to script the migration.

What are the prerequisites to install CISO Assistant?

CISO Assistant consists of a few docker images. You can install it on your laptop, desktop, or server. If it can run Excel, it can run CISO Assistant :). Once you install Docker and Docker Compose, follow the instructions on GitHub. Kubernetes (via our Helm chart) and the other installation flavours are documented in the Docs section.

What are the supported languages?

CISO Assistant is available in more than 25 languages, thanks to a very active community worldwide. Check out the GitHub page to learn more about the existing and upcoming ones.

What are the premium features that are specific to PRO plan?

Check out the /compare page to see exactly what the PRO plan stacks on top of the Community edition, feature by feature.

What are the supported frameworks?

CISO Assistant ships with more than 150 cyber security frameworks, standards and regulations, and the library keeps growing. If you notice that one is missing, reach out to the team through Discord or the contact form. If it's an open and free standard or regulation, we will add it for free.

What does contributor/seats count mean on the PRO plan?

A contributor is a user with write permission who will input or change data, including a review, comment, or approval. This is what we use to define the pro seats, allowing us to ensure that readers are free.
Both SaaS and On-premises plans have unlimited options if you don't want to count the contributor seats.

Can I add a custom/internal framework?

Yes. Libraries load directly from an Excel file — no manual conversion to YAML needed — from the Governance → Library page, and any validation error is reported during the import. The tools directory in the repository documents the expected format and provides example files.
A library can describe a framework, a threat catalog, a set of reference controls, or a custom risk matrix. We also provide express consultancy options for complex or large framework integrations.

Which SSO protocols are supported, and do I need a paid plan?

CISO Assistant supports SSO with both SAML and OIDC, in the Community edition and the Pro plan alike. Only SCIM provisioning — automatic user creation and removal from your identity provider's groups — is specific to Pro.

Is multi-factor authentication available?

Yes, in both editions, with TOTP applications and hardware security keys. Personal access tokens are issued from an authenticated session, so an account protected by MFA stays protected when you use the API.

Can I see who changed what?

Yes. The audit log records changes across the platform, and you can open any object to review its own history without digging through global logs. It is part of the Pro plan.

How do I report a security issue?

Write to security@intuitem.com. Significant vulnerabilities and their fixes are communicated through release notes and advisories on our public repository, so both cloud and on-premises users are informed.

Where is my data hosted?

Our cloud instances run in France, across two independent providers (Scaleway and OVH), with a secondary region in the Netherlands for disaster recovery. Each customer gets a dedicated, isolated instance with its own storage volumes. For specific needs, the hosting location can be agreed with you.
Hosting, isolation, backup and retention details are documented on our security page.

Is intuitem certified?

Our security program is aligned with NIST CSF and OWASP ASVS, and we rely on ISO 27001 certified hosting providers. ISO 27001 certification for our own ISMS is targeted for Q4 2026. An independent penetration test is run every year and the report is published.
The full security assurance plan is on our security page.

Can I deploy on Kubernetes?

Yes, through our Helm chart. The config builder in the repository also generates a tailored docker-compose file for self-hosting, and the Docs cover the other installation flavours.

Which database does CISO Assistant use?

SQLite by default, which is enough to get started quickly. PostgreSQL is supported and recommended for production deployments.

Can I store attachments on S3 or Azure Blob?

Yes. The filesystem is used by default, and you can switch to an S3 bucket (including S3-compatible services such as MinIO) or an Azure Blob container. Kubernetes deployments can authenticate through IRSA on EKS or an Azure managed identity, without static credentials.

What should I do to run it safely in production?

Pin image versions rather than tracking the main branch, set DJANGO_DEBUG to false, expose only what you need behind a reverse proxy with a valid certificate, use an encrypted volume for the database, and keep secrets in environment variables. The containers run as a non-root user by default. Full guidance is in the repository README and the Docs.

Can I automate CISO Assistant?

Yes, it was built API-first. Everything the interface does is available through the REST API, and a CLI is provided for automation. Create a personal access token from your user profile and send it in the Authorization header — note that the scheme is "Token", not "Bearer". Interactive API documentation is available in development mode.

Do you support MCP?

Yes. CISO Assistant ships with MCP support, so you can connect an AI assistant or agent that speaks the Model Context Protocol and query or drive your GRC data from there.

Which integrations are available?

Jira and ServiceNow for ticketing and asset synchronization, Kafka for event streaming, and outgoing webhooks for everything else. The REST API and the CLI cover the cases where no dedicated connector exists.

Can I assess one scope against several frameworks at once?

Yes, and this is the whole point of the decoupling principle: compliance is separated from the security controls that implement it, so a control you have already documented can serve several frameworks. Automatic mapping and the mapping explorer let you reuse a past assessment against a new standard instead of starting over.

Do you support EBIOS RM?

Yes, through a dedicated EBIOS RM module, alongside the standard risk assessment workflow.

Can I quantify risk in financial terms?

Yes. A cyber risk quantification module complements the qualitative risk matrices, so you can express exposure in monetary terms alongside the usual likelihood and impact scales.

How does third-party risk management work?

You build a questionnaire and customize it to the vendor and the level of scrutiny you need, then trigger it. The vendor signs in to CISO Assistant, answers directly, and you review their responses in the platform — no spreadsheets going back and forth by email. A vendor due diligence baseline is included to start from.

Can I keep my GDPR records of processing in CISO Assistant?

Yes, there is a dedicated GDPR processings module, with export and import so you can bring an existing register in or hand it over.

Can I share our compliance status with customers?

Yes. Portals and a trust center let you publish a curated view of your posture to an external audience, without giving them access to the platform itself.

Where is the roadmap, and how do I request something?

The public roadmap is linked from our GitHub repository. For a feature idea or a missing framework, reach the team on Discord or through the contact form — if it is an open standard, we will add it free of charge.

Reach out to us

Have questions or need assistance shaping your needs and projects? Feel free to contact the team using the form below. We're here to help!

  • Email

    contact@intuitem.com

  • Call

    +33 6 63 06 83 31

  • Chat

    intuitem - community