Six modules on one graph of obligations, controls, risks and evidence. Use one, or run your whole programme on it — with our lawyers keeping the regulatory content current.
Integrations pull configurations, access reviews and change records straight from source systems. Your people review exceptions; the platform does the collecting.
Security posture Sample
TLS 1.2+ in transit, AES-256 at rest, with per-tenant keys available.
SAML/OIDC SSO, SCIM provisioning and least-privilege roles.
Deploy where your regulation or policy requires data to stay.
Every change to an obligation, control or piece of evidence is logged.
REST API and webhooks for anything that doesn't have a connector yet.
Backups, tested restores and documented recovery objectives.
Something else on your mind? Ask a specialist.
Your team owns it. ENKAYT Horizon flags relevant regulatory changes and, on advisory plans, our lawyers propose updates for your approval.
Yes. Policies can be imported from Word, PDF or SharePoint and are versioned from the point of import.
Common international frameworks such as ISO/IEC 27001:2022, SOC 2, PCI DSS v4.0 and NIST CSF 2.0 are provided as starting libraries, alongside local regulatory mappings maintained by our team.
Yes, through time-limited audit workspaces with read-only access to the requested evidence.
Yes. Scales, matrices and appetite statements are configured to your methodology during implementation.
Yes. A configurable request portal can be embedded on your website, with identity verification steps you define.
No. Suppliers use the portal free of charge with limited, scoped access.
Summaries may be drafted with AI assistance and are reviewed by our legal team before publication on advisory plans. Each summary links to the original source.
Bring one framework and a sample of controls. In a 45-minute demo we'll show them mapped, owned and evidenced.