Information Security
Akarion GRC Cloud (ISMS)
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by AKARION GmbH · akarion.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Akarion GRC Cloud's Information Security module is strongest on framework & standard coverage — a flat 7 — resting on licensed BSI IT-Grundschutz tool status and 217 updates in 2024, while integrations & automation lands 5-7 on thirteen named connectors plus SSO, MFA and autoprovisioning, with no documented API, webhooks or automated evidence collection anywhere. Asset & risk management depth and audit readiness & evidence cluster at 5-6. The lowest scored category is controls, SoA & measures (five 5s, one 6): the rationales report no evidence of SoA generation from live control status, controls carrying their own evidence, or a documented control-to-risk link — 'logisch verknüpfte Datensätze' stays a marketing phrase. The genuine split is sovereignty: four judges at 7, the Skeptic and Evidence Integrator at 4. Both camps cite the same facts — EU-only hosting on STACKIT in DE/AT, Akarion GmbH as a 100% subsidiary of Akarion AG, development 100% in AT and DE — and the same absence of a published DPA, subprocessor list and TOMs; the 4-scorers let that absence cap the score, the 7-scorers weigh the documented chain more. Pricing is unpublished beyond a free demo.
Speaks for it
- Framework & standard coverage flat at 7 across the table, covering the ISO family, EU NIS-2, the BSI 200-x stack, ITGS Kompendium, C5, VDA ISA and PCI DSS
- Licensed BSI IT-Grundschutz tool provider with weekly releases and 217 updates in 2024 showing maintained content
- Thirteen named connectors including Jira, ServiceNow, Matrix42 and Fabasoft, plus custom connectors on request, SSO, MFA and autoprovisioning
- Centralized asset management with visual protection-need determination, customizable risk matrices, and revision-safe incident workflows with task assignment
- EU-only hosting on STACKIT in DE/AT, development 100% in AT and DE, and Akarion GmbH as a 100% subsidiary of Akarion AG
Held against it
- Controls, SoA & measures scores 5-6 with no evidenced SoA generation from live control status, control-to-risk linkage, or controls carrying their own evidence
- No published DPA, subprocessor list or TOMs on any captured page — the cause of the sovereignty split (7 vs 4)
- No documented REST API, webhooks, SCIM or automated evidence collection; connectors serve ticketing and workflow, not continuous control monitoring
- No audit-scoped evidence packs, auditor access roles, or 'state on date X' reconstruction, leaving a full audit file as hand work
- Vendor pages disagree on DORA — present on the homepage framework list, absent from the ISMS and platform pages
Best for
- You run a DACH information-security program on BSI IT-Grundschutz and want the licensed catalogs and the full BSI 200-x stack inside the tool
- You need the German-market regime set — EU NIS-2, VDA ISA, C5, B3S sector profiles — with visible content maintenance
- Your estate already runs on Jira, ServiceNow or Matrix42 and connector-based integration with SSO/MFA covers your automation needs
- You require EU-only hosting and registered German/Austrian entities and are prepared to request the unpublished DPA and subprocessor list during contracting
Avoid if
- You need on-demand SoA generation or controls that carry their own evidence — controls, SoA & measures scored 5-6 with neither evidenced
- You expect a documented REST API, webhooks or automated evidence collection from the live estate rather than named connectors
- You rely on NIS2 24h/72h statutory reporting clocks or protection-need inheritance across asset relations — neither is evidenced anywhere in the evidence
The scores
Asset & risk management depth
Show reasoningHide reasoning
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The CISO
Centralized asset inventory with visual protection-need determination and customizable assessment matrices plus structured, revision-safe incident workflows is a real base. But the evidence never evidences NIS2 24h/72h reporting clocks, risk acceptance with a named owner, or protection-need inheritance across asset relations — the only documented 'Vererbung' is multi-tenant templating — so my two hard questions to a risk register stay unanswered. 2 1 3
The GRC Consultant
Central asset management with visual protection-need determination, customizable matrices, and structured incident handling with task assignment and revision-safe documentation clears the 5-anchor with the task/approval workflows standing in for treatment tracking. But nothing evidences protection-need inheritance across asset relations, NIS2 24h/72h statutory clocks, or risk acceptance with named owners, so the 8-anchor risk backbone is not shown. 1 2
The Drafted IT Officer
Central assets with visual Schutzbedarf determination and matrices that fit my methodology, plus revision-safe incident workflows with task assignment — that's the Grundschutz-flavoured backbone I can actually follow, from a licensed BSI IT-Grundschutz tool vendor. But the evidence is silent on NIS2 24h/72h statutory clocks, risk acceptance with named ownership, and protection-need inheritance across asset relations (only tenant inheritance is evidenced), so it sits between rubric level 5 and 8. 1 2
The Lead Auditor
Central assets with visual protection-needs determination, configurable risk matrices, and structured incident workflows with revision-safe documentation is a textbook anchor-5 picture, with measures and task management around it [E1/E3]. But the evidence is silent on protection-need inheritance across asset relations, NIS2 24h/72h statutory clocks, and risk acceptance with named owners — the 8-anchor substance simply isn't evidenced. 1 2 3
The Evidence Integrator
Central asset inventory with visual Schutzbedarf determination and customizable matrices, plus the licensed BSI IT-Grundschutz tool status implying a documented methodology, lifts this above a flat risk list. But nothing evidences inherited protection needs across asset relations, treatment ownership, or NIS2 24h/72h statutory clocks — the incident module documents steps 'revisionssicher' with no deadline machinery in sight — so it sits just over rubric level 5, not at 8. 1 2
The Skeptic
Central asset inventory with visual protection-need determination and customizable risk matrices, AI-generated risks/measures, and revision-safe incident workflows — that's a solid anchor-5 story. But there is no word on NIS2 24h/72h statutory clocks, and protection-needs inheritance is only evidenced for tenant structures, not asset relations. 1 2 3
Controls, SoA & measures
Show reasoningHide reasoning
How this is scored
Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.
0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.
3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.
5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.
8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.
10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.
The CISO
The control side has substance in principle — licensed BSI IT-Grundschutz tool provider, an Audit module, multi-stage approval workflows, AI-generated measures and audits — but nothing on SoA generation from live control status, measure ownership with delegation and escalation, or findings management. That is anchor-5 territory at best, and I refuse to score capabilities the evidence does not document. 1 2 3
The GRC Consultant
A licensed BSI IT-Grundschutz tool provider must run an operable control fabric, and 'logisch verknüpfte Datensätze' with AI-generated risks, measures and audits plus multi-stage approvals point to linked controls-measures with owners. But SoA generation on demand, findings management in the audit module, and controls carrying their own evidence are nowhere evidenced — I won't certify a checklist as a living system. 1 2 3
The Drafted IT Officer
Measures are generated with a review step, run through task/workflow management with multi-stage approval, and there's a dedicated Audit module; the BSI licence means the Grundschutz catalogs live in the tool rather than a consultant's spreadsheet. What's missing is any evidence of on-demand SoA generation, controls linked to risks, or findings management — that's the gap between checklist operation and rubric level 8, and the evidence doesn't show it. 1 3
The Lead Auditor
Catalog operation is credible — a licensed BSI IT-Grundschutz tool provider, an explicit Audit module, task and multi-stage approval workflows, and logically linked data records with a review step [E2/E3]. Nowhere is an SoA generated from live control status, measure delegation/escalation, or controls carrying their own evidence; that's checklist-plus, not a living control fabric. 1 2 3
The Evidence Integrator
AI-generated measures and audits with a review step, multi-stage approval workflows and task/project management, and a dedicated Audit module take measures past checklist level. But the evidence never shows SoA generation from live control status, explicit control-to-risk linkage, or controls carrying their own evidence — the linkage is a marketing phrase ('logisch verknüpfte Datensätze'), not a documented mechanism, which is exactly where rubric level 8 would have to be earned. 1 2 3 4
The Skeptic
The licensed BSI IT-Grundschutz-Tool status implies real catalogs and methodology, and multi-stage approval workflows plus task/project management suggest measure ownership. But the pages never show SoA generation, a control-to-risk link, or evidence attached to a control — 'logically linked data records' is marketing, not a demonstrated control fabric. 1 2 3
Framework & standard coverage
Show reasoningHide reasoning
How this is scored
Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.
0 — One framework, hard-coded; anything else is "on the roadmap".
3 — Two or three frameworks as separate checklists; the same control is answered once per framework.
5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.
8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.
10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.
The CISO
Fifteen-plus current regimes — NIS2, DORA, VDA ISA, BSI C5, PCI DSS, the full BSI 200-x line — with visible maintenance (weekly releases, 217 updates in 2024) is exactly what my market needs. One-control-many-frameworks mapping is only hinted at via 'logically linked data records' and never shown, so it stays short of rubric level 8. 1 3 2
The GRC Consultant
Seventeen regimes including NIS2, DORA, VDA ISA, the full BSI 200-x stack, B3S sector profiles and PCI DSS with 217 updates in 2024 is the German-market depth rubric level 8 describes, plus sector profiles. The one thing my dozen-client practice needs — explicit one-control-many-frameworks mapping so a control is answered once — is never stated, only implied by 'logically linked' records, so I dock it. 1 2 3
The Drafted IT Officer
Seventeen regimes including NIS-2, DORA, VDA ISA, the full BSI 200-x stack, C5 and PCI DSS, from a licensed BSI IT-Grundschutz tool vendor, with weekly releases (217 updates in 2024) showing the content is maintained rather than frozen. One-control-many-frameworks mapping is only hinted at via 'logically linked data records' and never stated, which is what keeps this below rubric level 8. 1 3 2
The Lead Auditor
Sixteen-plus regimes including NIS2, DORA, VDA ISA, ITGS Kompendium, BSI C5 and sector B3S profiles [E1/E3] is genuinely broad for its market, and the Grundschutz license signals depth beyond a content pack. Missing: proof of one-control-many-frameworks mapping on a single data basis, and the weekly 200+ updates are product releases, not a documented catalog-update cadence when the standard moves — so short of 8. 1 2 3
The Evidence Integrator
Seventeen regimes — ISO family, NIS2, DORA, VDA ISA, the full BSI 200-x set, ITGS Kompendium, C5, B3S sector profiles, PCI DSS — backed by the licensed IT-Grundschutz status and a visible maintenance pulse of 217 updates in 2024. What keeps it under 8: nowhere is one-control-many-frameworks mapping on a single data basis evidenced; breadth is proven, cross-mapping is inferred. 1 2 3
The Skeptic
Fifteen-plus regimes including the full BSI suite, NIS2, VDA ISA, C5, B3S sectoral profiles and PCI DSS — genuinely the right set for DACH. But the pages disagree: DORA sits on the homepage list and is absent from both the ISMS page and the platform page, and nothing demonstrates one-control-many-frameworks mapping rather than parallel checklists. 1 2 3
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".
The CISO
Revision-safe incident documentation, an audit trail and one-click reports for management or auditors are evidenced, which is more than static PDF exports. But there is no evidence of audit-scoped evidence packs, dedicated auditor access roles, or a defensible 'show me the state on date X' — the full audit file still takes hand work. 2 3 1
The GRC Consultant
One-click reports for management and auditors, a real-time risk view, revision-safe incident documentation, an audit trail and granular roles go beyond report generators, and a dedicated Audit module exists. No evidence of per-control evidence packs, auditor access roles, or a 'show me the state on date X' reconstruction — assembling a full audit file still smells like days of work. 1 2 3
The Drafted IT Officer
One-click reports for management or auditors, a real-time risk dashboard, revision-safe incident documentation and an audit trail — as someone who dreads assembling binder evidence, that's genuinely reassuring. But there's no evidence of auditor access roles, audit-scoped evidence packs, or an answer to 'show me the state on date X', so rubric level 8 territory stays unevidenced. 2 3
The Lead Auditor
One-click reports for management and auditors, revision-safe incident documentation, an audit trail and multi-stage approvals are the right vocabulary. But there is no evidence of audit-scoped evidence packs on demand, auditor access roles, or a defensible answer to 'show me the state on date X' — the exact things a certification audit turns on — so this sits between report generators and standing readiness. 1 2 3
The Evidence Integrator
'Revisionssicher' incident documentation, an audit trail and granular roles, and one-click reports for auditors and management clear rubric level 5. No auditor access roles as such, no audit-scoped evidence packs, and no 'state on date X' reconstruction are evidenced — you can demonstrate effectiveness on demand, but not rebuild a defensible history. 2 3
The Skeptic
'One-click reports for management or auditors' and revision-safe incident documentation, plus an audit trail feature, meet the versioned-records-and-report-generators anchor. No evidence packs, no auditor access roles, and no answer to 'show me the state on date X' — assembling a full audit file still looks like work. 2 3
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.
8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.
The CISO
A dozen named native connectors including ServiceNow, Jira, Matrix42 and OmniTracker, plus SSO, MFA and autoprovisioning, means it can feed from the real IT estate. The evidence shows no documented API, no webhooks, no scanner or endpoint sources and no automated evidence collection — automation here is connectors, not continuous control monitoring. 3 1
The GRC Consultant
A thirteen-connector list with Jira, ServiceNow, Matrix42 and omnitracker, custom connectors on request, SSO and autoprovisioning is a genuine estate-facing connector set, not CSV theater. But no documented REST API, webhooks, directory import or scanner feeds appear anywhere, so automated evidence collection against the live estate — the thing that removes recurring toil — is unevidenced. 1 3
The Drafted IT Officer
A dozen named connectors including Jira, ServiceNow, omnitracker and Matrix42 — the ITSM/CMDB world my estate already lives in — plus custom connectors on request, SSO, MFA and autoprovisioning. No documented REST API or webhooks appear anywhere, and the AI generates content for human review rather than automatically collecting evidence from the estate, so it stops short of rubric level 8. 3 1
The Lead Auditor
A real connector set — Jira, ServiceNow, Matrix42, Fabasoft, Confluence and more, plus custom connectors on request — is ServiceNow-class reach, with SSO and autoprovisioning. The evidence says nothing about a documented API, webhooks, SCIM, or automated evidence tests with human review, which is what separates connectors from automation. 1 3
The Evidence Integrator
Thirteen native connectors — ServiceNow, Jira, omnitracker, Matrix42, Fabasoft — plus custom connectors 'auf Anfrage' is a genuinely real set, but it reads as workflow plumbing (ticketing, chat, CRM) rather than feeds from the live estate. The evidence is completely silent on a REST API, directory import (AD/Entra), SCIM, webhooks, and automated evidence tests or continuous control monitoring; 'Autoprovisioning' is one unexplained word, so typed evidence stays typed here. 1 3
The Skeptic
Thirteen named connectors including Jira, ServiceNow and Matrix42 with SSO, MFA and autoprovisioning is a real connector set, anchor-8 territory. But no documented API appears anywhere in the captured pages, webhooks/SCIM are unmentioned, and 'custom connectors on request' is a services line item dressed as product — that knocks it back down. 1 3
European sovereignty
panel opinion
panel disagrees
Show reasoningHide reasoning
How this is scored
Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The CISO
The documented chain is clean: Akarion AG (Munich) holds Akarion GmbH (Linz) 100%, EU-only hosting at STACKIT in DE/AT, infrastructure explicitly under German/Austrian jurisdiction, development in AT/DE. What the evidence does not show is a published DPA/TOMs or subprocessor list, and a risk register that sits in undocumented third-party hands is a finding in my book. 5 3 1
The GRC Consultant
EU end to end in substance: Akarion GmbH (Linz) as 100% subsidiary of Akarion AG (Munich) with registers and jurisdictions, EU-only hosting at STACKIT in DE/AT, development 100% in AT/DE, and a German/Austrian jurisdiction statement. The captured pages show no published DPA, subprocessor list or TOMs — for the system holding my clients' risk registers that documentation is what rubric level 8 demands and doesn't get. 1 3 4 5
The Drafted IT Officer
Substantively clean: EU-only hosting on STACKIT in DE/AT with infrastructure under German jurisdiction, Austrian and German registered entities, 100% development in AT and DE, and a vendor with its own ISO 27001 certificate. The paper trail is what's missing — no public DPA and no subprocessor list anywhere in the evidence, which rubric level 8 requires before I'd sign anything. 3 5 4
The Lead Auditor
European as evidenced end to end: Akarion GmbH (Linz) as 100% subsidiary of Akarion AG (Munich) with full register data and Gerichtsstand [E4/E5], EU-only hosting on STACKIT in DE/AT [E1/E3], development 100% in AT/DE, and infrastructure under German/Austrian jurisdiction. What's absent is the paperwork rubric level 8 demands — no published DPA, no subprocessor list, no named data centers — and for the system holding your risk register, the documented chain matters as much as the actual one. 1 3 4 5
The Evidence Integrator
Austrian GmbH wholly owned by a German AG, EU-only hosting on STACKIT in DE/AT with infrastructure under German jurisdiction, development 100% in AT/DE, and an ISO 27001-certified vendor — the bones are solidly European. But no DPA, no TOMs and no subprocessor list were captured anywhere, so a risk register held under a vendor whose processing chain is undocumented stops just short of rubric level 5. 1 3 4 5
The Skeptic
The substance is European: GmbH in Linz under AG in Munich, EU-only STACKIT hosting in DE/AT, development 100% in AT/DE, and stated German/Austrian jurisdiction for the infrastructure. But the paperwork is absent — no DPA, no subprocessor list, no TOMs on any captured page — and for a system holding your risk register, undocumented subprocessor exposure caps it well below rubric level 8. 1 3 4 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.
The CISO
The only public cost signal in the entire sheet is a free demo button — no edition, module, user or scale pricing anywhere, so every real invoice is a sales conversation. That is the market norm and I describe rather than condemn it, but it matches the lowest anchor. 1
The GRC Consultant
A free-demo CTA and a public five-module list are the only buying aids; not one price, edition, scale step, user boundary or setup fee is published, so the invoice is a sales conversation. That is anchor-0 territory, softened one point because the enumerable module structure at least tells a buyer what to ask about. 1
The Drafted IT Officer
The only public offering is a free demo button and a free NIS-2 questionnaire; no edition, module or user price appears anywhere, so every real configuration is a sales conversation. That's rubric level 0 exactly — I know unpublished pricing is the norm in this market, but I still can't put a number in next year's budget from this. 1
The Lead Auditor
The only pricing fact on the site is a free demo; five modules are named but no edition, per-module, per-user or per-entity number appears anywhere. Every configuration is a sales conversation — rubric level 0, describing the market norm rather than condemning it. 1
The Evidence Integrator
The only pricing artifact in the entire sheet is a 'Zur kostenlosen Demo' button — five modules, AI add-ons, and not one public number. rubric level 0 verbatim: every configuration is a sales conversation. 1
The Skeptic
The only pricing-adjacent artifact on any page is a 'kostenlose Demo' button. No edition, module, user, or scale pricing is published anywhere, so the real invoice is uncomputable without a sales conversation — squarely the anchor-0 case. 1
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE ⚠ unverified | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 7 Report an error |
| Subprocessors | EU only ⚠ unverified | 2/2 pts | 1 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The imprint also lists a 100% Austrian subsidiary (Akarion GmbH, Linz, Firmenbuch FN 480226 s) which is the site's Medieninhaber and named in the Nutzungsbedingungen as the contracting entity.
- Weak sourcing — Data residency. The EU-only hosting claim appears only in marketing and use-case copy; no privacy policy, DPA, or subprocessor-list excerpt is among the sources to confirm it.
- Weak sourcing — Subprocessors. No complete subprocessor list is among the excerpts, so beyond the named EU host STACKIT and the unnamed Austrian providers mentioned in the imprint, other processors cannot be verified.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 7 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage akarion.com Checked 15 Sep 2026 Details →
- 2 ISMS module page akarion.com Checked 15 Sep 2026 Details →
- 3 Platform overview page akarion.com Checked 15 Sep 2026 Details →
- 4 About page akarion.com Checked 15 Sep 2026 Details →
- 5 Imprint akarion.com Checked 15 Sep 2026 Details →
- 6 Privacy policy akarion.com Checked 30 Sep 2026 Details →
- 7 Asset & risk management depth — found from sitemap akarion.com Checked 1 Oct 2026 Details →
- 8 Framework & standard coverage — found from sitemap akarion.com Checked 1 Oct 2026 Details →
- 9 Framework & standard coverage — found from sitemap akarion.com Checked 1 Oct 2026 Details →
- 10 Audit readiness & evidence — found from sitemap akarion.com Checked 1 Oct 2026 Details →
- 11 Audit readiness & evidence — found from sitemap akarion.com Checked 1 Oct 2026 Details →