whats-best.ai

Information Security

DataGuard ISMS

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by DataCo GmbH · www.dataguard.de

Compare with SECJUR Digital Compliance Office (ISMS) → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

DataGuard ISMS is the information-security side of the DataGuard platform from DataCo GmbH. Framework coverage scores highest at 6-7: five regimes — DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act — with measures reused across frameworks and a published NIS2-to-ISO 27001 mapping. Information security management holds at 5 — a structured asset register with dependency visualization, risks tied to mitigation tasks — and controls and statement of applicability land at 5-6 on measures tracked with owners and effectiveness checks; no public information exists on a documented risk methodology, incident workflows with statutory reporting clocks, or generating a statement of applicability from live control status. Sovereignty is the weakest counted category at 3-4: a German GmbH with a Munich register entry is verifiable, but hosting location, subprocessors and a data processing agreement are undocumented on the captured pages, and the privacy policy relies on standard contractual clauses for recipients outside the EU/EEA. Integrations drew the widest spread, 4-6, over Jira, Asana and Azure connectors versus an API shown only as a navigation label. Pricing is quote-only across Base, Pro and Enterprise.

Report an error

Speaks for it

  • Framework coverage scored 6-7, the top band on the bench, across DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act with a published NIS2-to-ISO 27001 mapping
  • A structured asset register with owners, tagging, bulk import, dependency visualization and asset-to-risk linking
  • Measures carry owners, implementation status and effectiveness checks, with one measure linkable to several frameworks and evidence auto-assigned to requirements
  • Jira and Asana connectors set up in under 15 minutes, alongside automated Azure asset updates and CRM consent-data flows
  • Automated shareable reports and real-time gap dashboards, backed by a customer case citing 140-plus evidence artifacts for a six-month TISAX build

Report an error

Held against it

  • Sovereignty scored 3-4, with hosting location, subprocessors and a data processing agreement undocumented on the captured pages
  • The privacy policy relies on standard contractual clauses for recipients outside the EU/EEA, and the company operates a London office
  • Incident handling is shown only as configurable workflows, with no public information on statutory NIS2 reporting clocks
  • Statement-of-applicability content reads as guidance on the standard, with no public information on generating one from live control status or on internal audit workflows with findings management
  • The API appears only as a navigation label, with no documented endpoints shown on the captured pages

Report an error

Best for

  • You are a German-market organisation preparing for ISO 27001 or TISAX certification and want predefined measure libraries as starting points
  • You answer to several regimes at once — DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act — and want one measure answered once and reused across frameworks
  • Your team runs on Jira, Asana and Azure and wants compliance data synchronised continuously from those tools
  • You are a smaller team building an ISMS for the first time and want expert support and an external information security officer bundled into the Pro plan

Report an error

Avoid if

  • You must warrant EU/EEA-only processing to your customers — ask the vendor: the public pages we read do not show it
  • Your incident process must carry statutory reporting deadlines — the captured pages show incident handling as configurable workflows
  • You need SOC 2, DORA or BSI IT-Grundschutz coverage — the published framework list covers DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act, with further frameworks marked as coming soon
  • Your auditor demands revision-safe change history and state-on-a-given-date reconstruction — the versioning text on the captured pages describes what the standard demands of documents rather than a platform feature

Report an error

The scores

Asset & risk management depth

Show reasoning
How this is scored

The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.

0 — No ISMS substance; "information security" is a chapter in the marketing site.

3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.

5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.

8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.

10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.

Report an error

The CISO

The asset register is real — owners per asset, tagging, bulk import, asset-to-risk linking and dependency visualization — and risks sit in a central matrix with mitigation tasks, status tracking and pre-built libraries. Incident handling appears as configurable workflows plus a security-incidents module, but we found no public information on a documented risk methodology, inherited protection needs across asset relations, NIS2 24h/72h reporting clocks, or risk acceptance with a named accepting owner. A workable mid-market core, not yet a certifiable risk backbone. 8 9 16 3

Report an error

The GRC Consultant

There is a real core here: structured asset register with owners, tags, dependency visualization and asset-risk linking, a risk distribution matrix, and treatment tracking through tasks with progress and remediation guidance. But I found no public information on a documented risk methodology, inherited protection needs across asset relations, or incident workflows with statutory NIS2 reporting clocks — incident handling surfaces only as a configurable workflow and a module name, which lands this at the workable-core level, not a certifier-grade risk backbone. 3 8 9 16

Report an error

The Drafted IT Officer

A structured asset register with owners, tags, dependency views and risk linking, plus a risk matrix, pre-built risk and measure libraries and treatment tracking with assigned tasks, is a system I could actually run alongside the day job. Incident handling shows up as customizable workflows. I found no public information on a documented risk methodology, inherited protection needs across asset relations, or incident workflows with statutory reporting clocks — dependency visualization is shown, inheritance is not. 8 9 10 16

Report an error

The Lead Auditor

The asset register with owners, tagging, bulk import and asset-to-risk linking, plus a risk distribution matrix, pre-built risk and measure libraries and mitigation tracking with assigned tasks, is a working asset-and-risk core. Incident handling appears only as configurable workflows and a security-incidents module, and we found no public information on statutory reporting clocks (NIS2 24h/72h), a documented risk methodology, or inheritance of protection needs across the visualized asset dependencies. 8 9 16

Report an error

The Evidence Integrator

A structured asset register with owners, tags and visualised dependencies, risks linked to assets, a distribution matrix and mitigation tasks with owners form a real chain, and asset updates can be fed from Azure. But we found no public information on a documented risk methodology, inherited protection needs across asset relations, or incident workflows carrying statutory reporting clocks; incident handling shows up as configurable workflows rather than a clocked process. 8 9 3 16

Report an error

The Skeptic

The asset side is real: a structured register with bulk import, owners, tags and dependency visualization, risks linked to assets and driven through mitigation tasks with a distribution matrix and real-time dashboards. We found no public information on a documented risk methodology, on inherited protection needs across those asset relations, or on incident workflows carrying statutory reporting clocks; incident handling surfaces as a configurable workflow and an entry in the privacy module list. 8 9 16 10

Report an error

Controls, SoA & measures

Show reasoning
How this is scored

Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.

0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.

3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.

5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.

8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.

10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.

Report an error

The CISO

Measures carry owners, implementation status, effectiveness assessment and automatic evidence mapping, and one measure can serve several frameworks — genuinely better than a checklist. The captured pages explain all 93 Annex A controls and what a statement of applicability must contain, but as guidance content; we found no public information on generating a statement of applicability from live control status, on delegation and escalation, or on internal audit workflows with findings management. 10 11 9

Report an error

The GRC Consultant

Measures live in one central place, the same measure links to multiple frameworks, implementation status carries clear responsibilities, effectiveness is assessed, and evidence is mapped to requirements automatically — that is the answer-a-control-once model that makes client twelve cheaper than client one. What holds it below the top band: the SoA material I found explains what a SoA must contain rather than showing the product generating it from live status, and I found no public information on internal audit workflows, findings management, or delegation and escalation. 8 10 11

Report an error

The Drafted IT Officer

Measures are a real module — tracked with owners, reusable across frameworks, effectiveness-rated, with evidence auto-mapped to requirements and predefined ISO 27001 libraries plus expert-developed measures that give me sane defaults. The statement of applicability appears as guidance and customizable templates rather than something generated from live control status, and I found no public information on internal audit workflows or findings management. 10 11 15

Report an error

The Lead Auditor

Measures live in a central place with owner and status tracking, effectiveness assessment, task linking, automatic evidence assignment and reuse of the same measure across frameworks — more than a status-field checklist. The SoA material we saw is guidance about what the standard demands rather than a product feature, and we found no public information on SoA generation from live control status, delegation and escalation, or internal-audit workflows with findings management. 8 10 11

Report an error

The Evidence Integrator

Measures are a first-class object with owners, status tracking, effectiveness assessment, tasks, custom definitions and one measure linkable to several frameworks, plus automatic evidence mapping to requirements. The statement-of-applicability content on the site reads as guidance about the standard's demands rather than an on-demand SoA generated from live control status, and we found no public information on internal audit workflows or findings management. 10 11 9

Report an error

The Skeptic

Measures carry owners, implementation status, effectiveness checks, reuse across frameworks and automatic evidence assignment — more than a checklist. But the statement-of-applicability content on the site is educational guide text about versioning duties, we found no public information on generating a SoA from live control status or on internal audit workflows with findings management, and part of the expert measure library is marked available only after release. 10 11

Report an error

Framework & standard coverage

Show reasoning
How this is scored

Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.

0 — One framework, hard-coded; anything else is "on the roadmap".

3 — Two or three frameworks as separate checklists; the same control is answered once per framework.

5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.

8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.

10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.

Report an error

The CISO

DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act are supported, and the cross-mapping is productized rather than promised: the same measure links to multiple frameworks, assets map directly to measures from ISO 27001, NIS2 and TISAX, and a published table maps NIS2 requirements onto ISO 27001:2022 clauses and Annex A. ISO 27001:2022 content including the eleven new controls shows the catalogue moving with the standard. We found no public information on DORA, SOC 2 or BSI IT-Grundschutz, and the measures page itself says further frameworks follow soon. 9 10 13 3 11

Report an error

The GRC Consultant

ISO 27001, TISAX, NIS2, DSGVO and the EU AI Act cover the major German-market regimes, and the cross-mapping is genuine: asset management maps to measures from ISO 27001, NIS2 and TISAX, one measure serves several frameworks, a preconfigured NIS2 framework exists, and the vendor publishes an NIS2-to-ISO 27001:2022 mapping guide. I found no public information on SOC 2, DORA or BSI IT-Grundschutz, and the ready-made measures library leads with ISO 27001 with further frameworks announced as coming — five regimes with real but partial mapping, not a living multi-compliance product. 3 9 10 13

Report an error

The Drafted IT Officer

The German-market majors are all there — ISO 27001:2022, TISAX, NIS2, DSGVO and the EU AI Act — with NIS2 as a preconfigured framework with predefined measures and a published mapping of NIS2 requirements onto ISO 27001 controls, and one measure deliberately reusable across frameworks rather than re-answered per checklist. I found no public information on DORA, BSI IT-Grundschutz or SOC 2, which keeps this short of broad coverage. 2 3 10 13

Report an error

The Lead Auditor

The major regimes for its market are present — DSGVO, ISO 27001:2022, TISAX, NIS2 and EU AI Act — with one-measure-many-frameworks linking, asset management mapped to ISO 27001, NIS2 and TISAX measures, a preconfigured NIS2 framework and a published NIS2-to-ISO 27001 mapping. We found no public information on DORA, BSI IT-Grundschutz or SOC 2, and the measures page states further frameworks are coming soon, so coverage beyond ISO 27001 reads as content packs rather than broad current coverage. 3 7 10 13

Report an error

The Evidence Integrator

Five regimes for its market — DSGVO, ISO 27001 including the 2022 revision, TISAX, NIS2 and the EU AI Act — with a published mapping of NIS2 requirements onto ISO 27001 clauses and controls, and measures reusable across frameworks on one data basis. Additional frameworks are explicitly marked as upcoming, and we found no public information on DORA, BSI IT-Grundschutz or SOC 2 coverage. 7 13 10 3

Report an error

The Skeptic

Five regimes for its German market — DSGVO, ISO 27001, TISAX, NIS2 and the EU AI Act — with genuine reuse of one measure across frameworks and a published NIS2-to-ISO 27001 mapping table. We found no public information on DORA, BSI IT-Grundschutz or SOC 2, no documented update cadence when a standard moves, and the measures page itself says further frameworks are coming soon. 13 10 9

Report an error

Audit readiness & evidence

Show reasoning
How this is scored

Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

0 — Exports are screenshots; history is overwritten in place.

3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.

5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.

8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.

10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".

Report an error

The CISO

Automated custom reports in minutes, real-time dashboards for gaps and planned activities, automatic assignment of evidence to requirements, and a customer case describing more than 140 evidence artifacts for a TISAX assessment — more than ad-hoc attachments. We found no public information on revision-safe change history, auditor access roles, or a defensible answer to the state on a given date, so readiness looks strong at the reporting layer without the archival guarantees a certification body asks for. 14 10 12 16

Report an error

The GRC Consultant

Automated, shareable reports in minutes, real-time dashboards for compliance gaps, evidence auto-assigned to requirements, and a customer case citing 140+ evidence artifacts for a TISAX assessment — that is the report-generator-plus-attachments level I can work with, and the customer outcomes suggest it functions. I found no public information on revision-safe change history, auditor access roles, or audit-scoped evidence packs on demand, and nothing that answers the auditor's question of state on a given date. 10 12 14 16

Report an error

The Drafted IT Officer

Automated shareable reports, real-time dashboards for gaps and planned activities, an audit-ready inventory, automatic recording of compliance documentation and evidence auto-assigned to requirements mean the audit file is not assembled from screenshots, and the customer case with 140-plus evidence artifacts is reassuring. But I found no public information on revision-safe change history, audit-scoped evidence packs on demand, or auditor access roles — the question of showing the state on a given date stays open. 9 10 12 14 16

Report an error

The Lead Auditor

Automated custom reports, real-time dashboards for gaps and planned activities, automatic capture and storage of compliance documentation, per-requirement evidence assignment and a case study citing 140+ evidence artifacts for a TISAX audit give standard report generators and evidence per control. We found no public information on revision-safe change history in the platform, audit-scoped evidence packs on demand, auditor access roles, or reconstructing the state on a past date; the versioning text we saw describes the standard's demands on documents rather than a platform feature. 10 12 14 16

Report an error

The Evidence Integrator

Automatic capture and storage of compliance documentation, real-time dashboards, generated downloadable and shareable reports, and a customer case citing 140-plus evidence artifacts point toward evidence collected continuously rather than assembled before the audit. We found no public information on revision-safe change history, audit-scoped evidence packs or auditor access roles; the versioning language on the captured pages describes what the standard demands of the customer, not a product feature. 14 16 12 9

Report an error

The Skeptic

Automated reports, real-time gap dashboards, an audit-ready inventory and automatically assigned evidence are the standard toolkit, and one customer case cites 140-plus evidence artifacts for a six-month TISAX build. The repeat claim that every customer passed external ISO 27001 and TISAX audits on the first attempt is stated without a denominator, and, separately, the reporting pages note their figures rest on internal estimates. Beyond this, we found no public information on revision-safe change history, on-demand audit-scoped evidence packs, or auditor access roles. 12 14 10 9

Report an error

Integrations & automation

Show reasoning
How this is scored

Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.

0 — A closed island: manual entry in, PDF out, no API.

3 — CSV/Excel import and export; no live connections, no API worth the name.

5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.

8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.

10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.

Report an error

The CISO

Named connectors exist — Jira and Asana connected in under fifteen minutes, automated Azure asset updates, CRM consent flows with continuous synchronization — alongside a listed API and AI-supported automation. We found no public information on directory or SSO/SCIM connectors, a CMDB feed, webhooks, or the depth of what the API exposes; evidence automation is asserted only at the level of documentation, evidence collection and control monitoring. 16 8 14 3

Report an error

The GRC Consultant

An API with its own documentation surface, preconfigured connectors for Jira, Asana, Azure asset updates and CRM consent data, real-time synchronization across integrated tools, and AI-assisted automation — a handful of native connectors around a core API. I found no public information on directory import, SSO/SCIM, webhooks, CMDB or scanner feeds, and the automation claims are headline percentages (up to 40 per cent of tasks) rather than automated evidence tests against the live estate. 1 8 16

Report an error

The Drafted IT Officer

Named connectors — automated Azure asset updates, CRM consent data, Jira and Asana connected in under fifteen minutes — plus continuous real-time synchronization and a listed API surface suggest the platform feeds from real tools. I found no public information on directory import from AD or Entra, CMDB or ticketing connectors, SSO/SCIM, or what the API documentation actually covers, so the estate-feeding side rests on breadth claims. 1 8 16

Report an error

The Lead Auditor

Native connectors are evidenced for Jira and Asana (setup in under 15 minutes), automated Azure asset updates and CRM consent data with continuous real-time synchronisation, alongside an APIs entry, AI-assisted automation and real-time vulnerability detection on assets. We found no public information on directory import (AD/Entra), CMDB, ServiceNow-class ticketing, webhooks, SSO/SCIM, or automated evidence tests with human review. 8 9 16

Report an error

The Evidence Integrator

This is the right direction: automated Azure asset updates, Jira and Asana connectors set up in under fifteen minutes, CRM consent-data flows, and continuous real-time synchronisation of data flows into a central repository — the platform feeds from the estate instead of a bulk-import drawbridge. But the API surfaces only as a navigation label with no documented surface or parity claims, and we found no public information on directory sync, SSO or SCIM, webhooks, or automated control tests with human review. 16 8 1 3

Report an error

The Skeptic

Named connectors are real: automated Azure asset updates, CRM consent data, Asana and Jira in under fifteen minutes, preconfigured integrations and continuous sync — past the CSV stage. The API, though, appears only as a navigation label with no documented endpoints or data model shown, automation is sold as up to 40% of all tasks, and we found no public information on directory import, CMDB, ticketing beyond project tools, SSO/SCIM or webhooks. 16 8 1

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The CISO

A German GmbH with a Munich commercial register entry, named managing directors and DPO contact points is the right jurisdiction for the system that holds the risk register. The privacy policy relies on standard contractual clauses for recipients outside the EU, and we found no public information on hosting location, a published data processing agreement, a subprocessor list, or the ownership behind the Series B investors; a trust center is referenced but its contents are not published on the captured pages. 6 7 5 9

Report an error

The GRC Consultant

A German GmbH with a proper imprint, register entry and a privacy policy that relies on SCCs for recipients outside the EU — the entity is clean, but a UK office and acquisition history sit alongside that. I found no public information on hosting location, named data centers, a subprocessor list, or a downloadable DPA and TOMs, so the subprocessor exposure behind a system holding my clients' risk registers is undocumented. 5 6 7

Report an error

The Drafted IT Officer

A German GmbH with a Munich commercial register entry, a published privacy policy naming a DPO, and standard contractual clauses for recipients outside the EU is a start I can partially verify. But I found no public information on where the platform is hosted, the subprocessor list, a published data processing agreement, or the ownership behind the Series A and B investors — for the system that would hold my risk register, that is too much unknown. 5 6 7

Report an error

The Lead Auditor

The vendor is a German GmbH with a Munich imprint, commercial register entry and a named DPO contact, but we found no public information on where the platform hosting the risk register resides, on subprocessors, or on a published DPA and TOMs. The privacy policy discloses standard contractual clauses for recipients outside the EU/EEA, and the company runs a London office after acquiring a UK consent business, so non-European jurisdictional reach is plausible while remaining undocumented in the captured pages. 5 6 7

Report an error

The Evidence Integrator

A German GmbH with a Munich commercial register entry, a published EU privacy policy and standard contractual clauses under Article 46 GDPR for recipients outside the EEA — which itself confirms third-country transfers occur. We found no public information on hosting location, data residency, a published data processing agreement or a subprocessor list, ownership is undocumented, and a London office sits in the group. 6 7 5

Report an error

The Skeptic

The vendor is a German GmbH with a Munich register entry, a named data protection officer, and a privacy policy that leans on standard contractual clauses for third-country recipients — a clause you only need if such recipients exist. We found no public information on where the platform holding the risk register is hosted, on ownership, or on any subprocessor list, so that exposure remains unquantified. 6 7

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

0 — No public prices at all; every configuration is a sales conversation.

3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.

5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.

8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.

Report an error

The CISO

The captured pricing page lists Base, Pro and Enterprise with their inclusions, and each plan ends in a request for an offer — we found no published figures for any plan, edition or module. The only numbers are marketing claims such as "Bis zu 50 % günstiger als externe Berater" and a "Keine versteckten Kosten" promise on the demo form, so the real invoice remains a sales conversation even though the plan architecture helps a buyer pre-scope. 4 2 9

Report an error

The GRC Consultant

Three named tiers — Base, Pro, Enterprise — each behind a request-a-quote button, with no public numbers anywhere on the pricing page; a 'no hidden costs' slogan is not a price. The only figures anywhere are percentage claims such as up to 50 per cent cheaper than external consultants, so the real invoice is a sales conversation in every configuration. 2 4 9

Report an error

The Drafted IT Officer

All three plans — Base, Pro and Enterprise — end in 'Angebot anfordern', so not one figure is public and every configuration is a sales conversation. The tier contents are listed, which tells me the shape of the offer, but 'up to 50 percent cheaper than external consultants' is a marketing claim, not an invoice. 2 4

Report an error

The Lead Auditor

All three plans — Base, Pro and Enterprise — end in 'Angebot anfordern' (request a quote), and we found no public price figures, billing periods or module prices anywhere. The only public numbers are relative claims such as up to 50 percent cheaper than external consultants, plus a 'no hidden costs' slogan on a demo form, none of which let a buyer compute a real invoice. 2 4 9

Report an error

The Evidence Integrator

Plan names and feature groupings for Base, Pro and Enterprise are public, but every tier, including Base, is quote-only ('Angebot anfordern') with no figure anywhere on the captured pricing page. The only cost signals are comparative marketing claims — up to fifty percent cheaper than external consultants, no hidden costs — which leave the real invoice incomputable. 4 2

Report an error

The Skeptic

Every plan — Base, Pro and Enterprise — offers nothing but 'Angebot anfordern', so no public price exists anywhere to compute an invoice from. The Pro tier blends an external information security officer, data migration and expert support into the software quote rather than separating services from the platform, and a 'keine versteckten Kosten' line on the demo section does the work a number would. 4 9

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (17)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage (DE) www.dataguard.de Checked 16 Sep 2026 Details →
  2. 2 ISO 27001 framework page www.dataguard.de Checked 16 Sep 2026 Details →
  3. 3 NIS2 framework page www.dataguard.de Checked 16 Sep 2026 Details →
  4. 4 Vendor pricing page www.dataguard.de Checked 16 Sep 2026 Details →
  5. 5 About page www.dataguard.de Checked 16 Sep 2026 Details →
  6. 6 Imprint www.dataguard.de Checked 16 Sep 2026 Details →
  7. 7 Privacy policy www.dataguard.de Checked 30 Sep 2026 Details →
  8. 8 Asset & risk management depth — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  9. 9 Asset & risk management depth — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  10. 10 Controls, SoA & measures — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  11. 11 Controls, SoA & measures — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  12. 12 Framework & standard coverage — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  13. 13 Framework & standard coverage — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  14. 14 Audit readiness & evidence — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  15. 15 Audit readiness & evidence — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  16. 16 Integrations & automation — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →
  17. 17 Integrations & automation — found from sitemap www.dataguard.de Checked 1 Oct 2026 Details →