One incident.
One disciplined response.
Breaches, cyber incidents, AI serious incidents, whistleblower cases and legal holds all land in one workspace, then follow the same repeatable operating structure every time. Regulatory notifications are handled as a governed step in that structure, not a separate fire drill.

Five kinds of incident, one front door
This is the shared data model at work. An incident is recorded once, in a collaborative workspace, and the domains that need it can see it. No parallel logs, no reconciling one team's record against another.
Data breach
GDPR personal-data breaches
Cyber incident
NIS2 and DORA events
AI serious incident
EU AI Act Article 73
Whistleblower case
EU Whistleblower Directive
Legal hold
Preservation obligations
The core of the Incident Centre
A repeatable operating structure
When an incident hits, the difference between control and chaos is structure. Every incident follows the same disciplined path, so nothing depends on individual heroics and the record is complete because it is captured as the incident happens.
- 1
Detected
Raised once, scope and severity triaged at the outset.
- 2
Investigating
The timeline, situation reports and decisions are captured live.
- 3
Contained
Serious incidents escalate cleanly into crisis management.
- 4
Resolved
Actions and outcomes recorded against the same record.
- 5
Post-incident review
A structured after-action review feeds lessons back in.
Captured live
The timeline, situation reports and decisions are recorded as they happen, so the record is built in real time rather than reconstructed from memory afterwards.
Escalates cleanly
Serious incidents move into crisis management on the same record, so a major event never means starting a separate, parallel process.
AI removes the blank page
An assistant proposes the initial scope and triage, drafts the investigation report from the captured timeline, and produces a board-ready summary for review.
One governed step
Notifications, handled as a governed step
Because the platform knows the incident's scope and your regulatory sources, the notification duties that apply surface with their deadlines inside the same workflow. Compliance is one output of running the incident well, not a separate scramble. The deadline engine computes the exact clock for each obligation, including the hard cases.
GDPR
Article 33
72 hours from the moment you become aware of the breach.
From awarenessNIS2
Chained reports
A 24-hour early warning, a 72-hour notification and a one-month final report, with the final report anchored off the notification as the law requires.
ChainedDORA
Dual clock
4 hours from classification or 24 hours from awareness, whichever binds first, plus chained intermediate and final reports.
Dual-clockCRA
Remediation clock
Early warning, notification and the 14-day clock anchored on the availability of a remediation, not on awareness.
Anchored on remediationEU AI Act
Article 73
Immediately, and no later than 15 days in the general case, 10 days on a death, and 2 days for a widespread or critical-infrastructure incident. The engine picks the most urgent tier the incident satisfies.
Condition-tieredEvery clause carries its citation
Each deadline-bearing obligation records its primary law citation, so the reason a clock exists is one click away.
Authoritative only after review
A clause becomes authoritative once a subject-matter expert has checked it against the official legal text. Until then it is marked unverified.
What runs underneath the structure
The disciplined path every incident follows is backed by real modules, not a diagram.
One incident register, every domain
A single register spans data protection, cybersecurity, AI governance, whistleblowing and legal holds, so nothing is scoped, tracked or reported twice.
Crisis escalation on the same record
A serious incident escalates into crisis management without leaving its own record, carrying the timeline and decisions with it rather than starting over.
The regulatory deadline engine
GDPR, NIS2, DORA, the CRA and the EU AI Act clocks are computed from the incident scope and your adopted regulations, not tracked by hand on a spreadsheet.
Authority directory and templates
Notification templates and the authorities that receive them are matched to the obligation automatically, so a notification is drafted against the right recipient the first time.
Public intake portal
Anyone, staff or an external reporter, can raise an incident through a branded portal that lands directly in triage, with no separate inbox to check.
Post-incident review and lessons learned
A structured after-action review closes every incident, so what was learned feeds back into the next one instead of leaving with the person who handled it.
Run every incident the same disciplined way
Give incident response a repeatable structure, capture the record as it happens, and let the applicable notifications and their deadlines follow from running the incident well.