Skip to main content

    One incident.
    One disciplined response.

    Breaches, cyber incidents, AI serious incidents, whistleblower cases and legal holds all land in one workspace, then follow the same repeatable operating structure every time. Regulatory notifications are handled as a governed step in that structure, not a separate fire drill.

    Get Started
    Incident Response Centre dashboard showing active incidents, pending and overdue regulatory notifications, and the per-domain breakdown

    Five kinds of incident, one front door

    This is the shared data model at work. An incident is recorded once, in a collaborative workspace, and the domains that need it can see it. No parallel logs, no reconciling one team's record against another.

    Data breach

    GDPR personal-data breaches

    Cyber incident

    NIS2 and DORA events

    AI serious incident

    EU AI Act Article 73

    Whistleblower case

    EU Whistleblower Directive

    Legal hold

    Preservation obligations

    The core of the Incident Centre

    A repeatable operating structure

    When an incident hits, the difference between control and chaos is structure. Every incident follows the same disciplined path, so nothing depends on individual heroics and the record is complete because it is captured as the incident happens.

    1. 1

      Detected

      Raised once, scope and severity triaged at the outset.

    2. 2

      Investigating

      The timeline, situation reports and decisions are captured live.

    3. 3

      Contained

      Serious incidents escalate cleanly into crisis management.

    4. 4

      Resolved

      Actions and outcomes recorded against the same record.

    5. 5

      Post-incident review

      A structured after-action review feeds lessons back in.

    Captured live

    The timeline, situation reports and decisions are recorded as they happen, so the record is built in real time rather than reconstructed from memory afterwards.

    Escalates cleanly

    Serious incidents move into crisis management on the same record, so a major event never means starting a separate, parallel process.

    AI removes the blank page

    An assistant proposes the initial scope and triage, drafts the investigation report from the captured timeline, and produces a board-ready summary for review.

    One governed step

    Notifications, handled as a governed step

    Because the platform knows the incident's scope and your regulatory sources, the notification duties that apply surface with their deadlines inside the same workflow. Compliance is one output of running the incident well, not a separate scramble. The deadline engine computes the exact clock for each obligation, including the hard cases.

    GDPR

    Article 33

    72 hours from the moment you become aware of the breach.

    From awareness

    NIS2

    Chained reports

    A 24-hour early warning, a 72-hour notification and a one-month final report, with the final report anchored off the notification as the law requires.

    Chained

    DORA

    Dual clock

    4 hours from classification or 24 hours from awareness, whichever binds first, plus chained intermediate and final reports.

    Dual-clock

    CRA

    Remediation clock

    Early warning, notification and the 14-day clock anchored on the availability of a remediation, not on awareness.

    Anchored on remediation

    EU AI Act

    Article 73

    Immediately, and no later than 15 days in the general case, 10 days on a death, and 2 days for a widespread or critical-infrastructure incident. The engine picks the most urgent tier the incident satisfies.

    Condition-tiered

    Every clause carries its citation

    Each deadline-bearing obligation records its primary law citation, so the reason a clock exists is one click away.

    Authoritative only after review

    A clause becomes authoritative once a subject-matter expert has checked it against the official legal text. Until then it is marked unverified.

    What runs underneath the structure

    The disciplined path every incident follows is backed by real modules, not a diagram.

    One incident register, every domain

    A single register spans data protection, cybersecurity, AI governance, whistleblowing and legal holds, so nothing is scoped, tracked or reported twice.

    Crisis escalation on the same record

    A serious incident escalates into crisis management without leaving its own record, carrying the timeline and decisions with it rather than starting over.

    The regulatory deadline engine

    GDPR, NIS2, DORA, the CRA and the EU AI Act clocks are computed from the incident scope and your adopted regulations, not tracked by hand on a spreadsheet.

    Authority directory and templates

    Notification templates and the authorities that receive them are matched to the obligation automatically, so a notification is drafted against the right recipient the first time.

    Public intake portal

    Anyone, staff or an external reporter, can raise an incident through a branded portal that lands directly in triage, with no separate inbox to check.

    Post-incident review and lessons learned

    A structured after-action review closes every incident, so what was learned feeds back into the next one instead of leaving with the person who handled it.

    Run every incident the same disciplined way

    Give incident response a repeatable structure, capture the record as it happens, and let the applicable notifications and their deadlines follow from running the incident well.