AI-Assisted Compliance Platform
EU Data Residency

Compliance that
traces itself.

CertAstra connects every risk to the controls, policies, and evidence that prove it's handled continuously, not once a year. Built for ISO 27001, SOC 2, GDPR, NIS2, the EU AI Act, ISO 9001, EU MDR, and Cyber Resilience Act.

Or schedule a personal demo →

14-day free trial    No credit card required    Cancel anytime

the actual data model not a mockup

8 frameworks, live today: ISO 27001:2022 SOC 2 Type II GDPR NIS2 EU AI Act ISO 9001 EU MDR CRA
0Compliance frameworks supported
0Controls across all frameworks
0Audit questions included
0Free trial, no card required

Built for the people who own security, risk & compliance

Owner Admin Auditor Auditee Viewer
🇪🇺 EU-hosted — Helsinki & Nuremberg
TLS 1.3 encrypted
GDPR Art. 44 compliant
Tenant-isolated

One framework becomes six spreadsheets.
Six becomes chaos.

A single ISO 27001 control needs a policy, an evidence file, an owner, and a review date. Multiply that by 93 controls in one framework then by every other framework you're also expected to run and compliance stops being a security practice. It becomes a tracking problem.

Untracked, disconnected, manual

One connected system

Risk, controls, policies, and evidence —
one connected system.

Every risk in your register links to the controls that mitigate it. Every control links to the policy that governs it and the evidence that proves it. Change one, and you can see exactly what else it touches instead of updating five documents by hand. Explore a step below.

Risk
Register
Controls
Policies
Evidence
Framework
Compliance

A risk drives which controls exist. Each control is backed by a policy and proven by evidence.

app.certastra.com/risk-register

risk register - scored, matrixed, and linked to controls

AI Security & Compliance

A copilot that knows your organization

CertAstra's AI drafts answers to security questionnaires, runs gap analysis against any framework, and generates compliance documentation grounded in your organization's own context, not a generic template.

  • AI-suggested answers for security questionnaires
  • Framework-specific gap analysis
  • AI-generated compliance documents
  • Every output flagged for human review before it counts as evidence
"Do you encrypt data at rest?" — Suggested answer: Yes, AES-256 at rest and TLS 1.3 in transit, based on your infrastructure profile.
Needs human review
Gap analysis — ISO 27001:2022: 3 controls missing evidence, 1 policy out of date.
Continuous Compliance

Your posture doesn't go stale between audits

Emerging-threat intelligence is matched to your organization's own profile, and relevance is re-scored the instant your profile changes — not once a year, during a scramble before an audit.

  • Emerging threats matched to your organization
  • Instant relevance re-scoring on profile changes
  • Live readiness view, not a static snapshot
app.certastra.com/emerging-threats
CertAstra emerging threats list with severity badges, matched to the organization's profile
Evidence & Automation

Evidence that's linked, versioned, and never silently expired

Upload evidence directly against a control, track it through submission and review, and see expirations coming instead of finding out during the audit.

  • Version history and a full review workflow
  • Direct control linkage not a loose file folder
  • Expiration tracking with advance visibility
access-control-policy_v3.pdfApproved
pen-test-report_2026.pdfIn review
vendor-dpa_acme.pdfExpiring soon
Risk Management

A risk register that actually drives your controls

Configure your own risk matrix and methodology, log risks against real assets, and link each one straight to the controls mitigating it so risk management and control implementation stay in sync instead of living in separate documents.

  • Configurable risk matrix & methodology
  • Risk-to-control linkage
  • Corrective actions & findings tracked to resolution
app.certastra.com/risk-register
CertAstra 5×5 risk matrix heatmap scored by likelihood and impact
Multi-Framework

Manage every framework from the same workspace

Import ISO 27001, SOC 2, GDPR, NIS2, the EU AI Act, ISO 9001, EU MDR or Cyber Resilience Act — all eight are live today and keep your Statement of Applicability alongside them, without switching tools.

  • 8 frameworks, ready to import today
  • Statement of Applicability built in
  • 281 controls, 815 questions, already mapped

A compliance copilot, not a chatbot.

Ask what a control needs, and CertAstra works the problem the way an auditor would.

01
Question
A questionnaire item or control comes in
02
Analysis
Grounded in your org's own context
03
Relevant Controls
Matched against the right framework
04
Evidence
Checked against what's on file
05
Gap
What's missing or out of date
06
Recommended Action
A concrete next step, not a summary
All AI output requires human review before it's submitted it's a draft, not a decision.

One control. Every framework it satisfies.

Map a control once, and CertAstra tracks every framework that shares the same requirement so you implement it once and demonstrate it everywhere it applies, instead of re-proving the same control separately for each framework.

Example control
Access Control Policy
ISO 27001:2022 SOC 2 Type II GDPR NIS2 ISO 9001

Illustrative example — your actual mappings depend on which frameworks you run

From first risk to audit-ready proof.

1
Discover
Log risks; get threats matched to your org automatically.
2
Assess
Run audits and questionnaires; score readiness by framework.
3
Remediate
Track findings and corrective actions to resolution.
4
Collect
Gather and version evidence directly against each control.
5
Monitor
Watch relevance and readiness update continuously.
6
Prove
Export reports, your SoA, and a verifiable compliance badge.

Managed like a project, or run like a system.

The traditional way
  • Spreadsheets and shared drives
  • Email chains to chase down evidence
  • Manual reminders and trackers that go stale
  • A scramble before every audit
The CertAstra way
  • One connected risk → control → evidence system
  • Evidence requested and tracked in-platform
  • Continuous relevance & readiness scoring
  • Audit-ready any day — not just audit week

Built the way a security buyer expects.

Encryption everywhere
TLS 1.3 in transit, encryption at rest.
Role-based access control
Owner, Admin, Auditor, Auditee, Viewer.
Full activity audit trail
Every action logged, on every record.
Tenant isolation
Your organization's data is never mixed with another's.
🇪🇺
EU-hosted infrastructure
Hetzner Cloud — Helsinki & Nuremberg.
We don't read your compliance data
It's yours — we operate the platform, not your content.

Built for the people who own the outcome.

CertAstra is built for the teams accountable for getting frameworks implemented and audits passed not just the auditors who show up once a year.

Simple, transparent pricing

Pricing tailored to your team and frameworks — talk to us.

Starter
Starter

For small organizations beginning their compliance journey

🇪🇺 EU-hosted · GDPR compliant
  • 1 compliance framework
  • Up to 3 team members
  • Evidence management
  • Audit workflows
  • Basic reports
  • Email support
Pro
Pro

For organizations actively preparing for certification

🇪🇺 EU-hosted · GDPR compliant
  • Unlimited compliance frameworks
  • Unlimited team members
  • Everything in Growth
  • Full AI evidence review
  • AI document generation
  • Compliance scoring
  • Dedicated support

Need a custom plan for your enterprise? Contact our team →

Frequently asked questions

All 7 frameworks are live today: ISO/IEC 27001:2022, SOC 2 Type II, GDPR, the NIS2 Directive, the EU AI Act, ISO 9001:2015, and EU MDR 2017/745 — with 281 controls and 815 audit questions between them. You can also create custom frameworks for internal standards.
There's no fixed timeline — it depends on how many frameworks and controls you're implementing and where you're starting from. CertAstra's job is to remove the tracking overhead, so the time you spend goes into actual implementation instead of maintaining spreadsheets.
Yes. CertAstra supports role-based collaboration with five roles: Owner, Admin, Auditor, Auditee, and Viewer. You can assign different team members to different controls and track progress in real time.
All data is encrypted in transit (TLS 1.3) and at rest. Our infrastructure is hosted in the EU (Hetzner, Germany/Finland). We are GDPR compliant and your data is never shared or sold.
Our AI assists with: answering questionnaire questions based on your company context, generating draft compliance documents, and identifying gaps against a selected framework. All AI output requires human review before it's submitted.
Yes. You can export audit reports as PDF, the Statement of Applicability as CSV, and AI-generated documents as Markdown. Your data is always yours.
Yes — all plans include a 14-day free trial with no credit card required. You get full access to all features, including AI assistance, during the trial.
Your data is retained for 30 days after cancellation, giving you time to export everything. After 30 days, all data is permanently deleted per our privacy policy.

Turn compliance from a recurring project
into a continuous capability.

Start free, or see it running on a real account.

14-day free trial · No credit card required