Information Security
HiScout GRC Suite
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by HiScout GmbH · www.hiscout.com
Compare with verinice → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
HiScout GRC Suite — an ISMS, Grundschutz, data-protection and BCM suite from HiScout GmbH, Berlin — is strongest on audit readiness: ISO 19011 audit programmes with annual plans across customer, supplier and internal scopes, mobile on-site evidence capture, central documentation stated to be tamper-proof, and reports naming the underlying Kompendium edition. Weakest are integrations and automation and framework coverage: data arrives by GSTOOL, CMDB and Excel import, an XML interface and a DataExchange extension — the higher scores credit low-code data-model extension and validated questionnaires, the lower ones see import plumbing — with no public information on a REST API, SSO or ticketing connectors, and regime depth concentrated in BSI-Standard 200-1/2/3, ISO 27001/22301 and GDPR rather than NIS2, TISAX, DORA or SOC 2. Information security management clusters at 6 — documented risk methodology to BSI-Standard 200-3 and 100-3, no public information on incident workflows. Sovereignty splits 6–7 over unnamed data centers and a subprocessor list covering website and portal rather than platform; the captured pages give different figures for third-country transfers. We found no public prices on any captured page.
Speaks for it
- Audit readiness scored 7–8 on ISO 19011 audit programmes with annual plans for customer, supplier and internal audits and mobile on-site evidence capture.
- Central capture is stated to be documented tamper-proof (revisionssicher), with reports naming the underlying Kompendium edition and previous editions remaining reproducible.
- Kompendium updates surface only requirements needing re-assessment, with ratings carried over from the previous edition.
- Measures are selectable from stored catalogs — BSI Grundschutz, compliance guidelines, the Standard-Datenschutz-Modell — with audit findings routed automatically to the correct recipients.
- Development and support run 100% in Germany, SaaS data sits in data centers within Germany, and the on-premise variant carries the equal feature set.
Held against it
- Data arrives by GSTOOL, CMDB and Excel import, a dynamic XML interface and a DataExchange extension, and we found no public information on a REST API, SSO or ticketing connectors.
- We found no public information on NIS2, TISAX, DORA or SOC 2 content, capping regime coverage beyond the German home market.
- We found no public information on incident workflows or statutory reporting clocks on the risk side.
- The published subprocessor list covers the website and customer portal rather than the platform itself, and the data centers themselves are not named.
- We found no public prices on any captured page, and the audit module's product factsheet is available only on request.
Best for
- You run a German-market ISMS on BSI IT-Grundschutz and need versioned Kompendium maintenance — parallel editions, a re-assessment filter and carried-over ratings.
- You plan and run ISO 19011 audits across customer, supplier and internal scopes and want mobile on-site evidence capture with tamper-proof central documentation.
- You are a German authority or enterprise that wants development and support 100% in Germany, SaaS data in data centers within Germany and an on-premise variant at equal feature set.
- Your team manages GDPR processing activities and assigns TOMs from stored catalogs such as the Standard-Datenschutz-Modell to them.
Avoid if
- You need NIS2, DORA, TISAX or SOC 2 regimes operationalized — framework coverage scored 5–6 with depth concentrated in the German home regime, and we found no public information on those frameworks.
- You expect feeds from the live estate — directory synchronization, SSO, ticketing connectors or a documented REST API — rather than import, XML and database-connection workflows.
- You need incident handling with statutory reporting clocks in the core risk tool — information security management scored 6, and we found no public information on incident workflows.
- You rely on published prices to budget before a sales conversation — pricing transparency scored 0 across the board and the audit module's product factsheet is request-only.
The scores
Asset & risk management depth
Show reasoningHide reasoning
How this is scored
The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.
0 — No ISMS substance; "information security" is a chapter in the marketing site.
3 — A flat risk list and an asset spreadsheet import; no treatment tracking, no inheritance, incidents live in the ticket system.
5 — Asset and risk management with configurable matrices and treatment tracking; basic incident handling; inheritance and aggregation need manual work.
8 — A real risk backbone: documented methodology (ISO 27005 or equivalent), inherited protection needs across asset relations, incident workflows with statutory reporting clocks (NIS2 24h/72h), risk acceptance with ownership.
10 — Risk management a certifier works inside: complete asset-risk-treatment chain with inheritance, continuity planning, incident reporting with authority export, and risk reporting the executive level actually reads.
The CISO
The risk analysis is certified-in-practice methodology, not a flat list: BSI-Standards 200-3 and 100-3 with measure recommendations via cross-reference tables, and Grundschutz and BCM risk results consolidated in one tool and coordinated through to IT implementation. But we found no public information on incident handling workflows, NIS2 24h/72h reporting clocks, or risk acceptance with named ownership, and the only evidenced carry-over of ratings is between Kompendium editions rather than protection needs propagating across asset relations. 3 2 7 8
The GRC Consultant
The risk backbone is real where it counts for the German market — the risk analysis follows BSI-Standard 200-3 and 100-3 with measure proposals off the Grundschutz cross-reference tables, and Grundschutz and BCM risk results consolidate in one tool through to IT implementation. What I miss is the incident side: we found no public information on incident workflows or statutory reporting clocks, nor on inherited protection needs across asset relations or risk acceptance with named ownership. 2 7 8
The Drafted IT Officer
The risk backbone is documented and real: the risk analysis is stated to fulfil BSI-Standard 200-3 and 100-3 with measure proposals via cross-reference tables, Grundschutz and BCM risk results can flow together in one tool down to IT implementation, and a protection-needs determination exists in the data protection module. We found no public information on incident workflows with statutory reporting clocks or on risk acceptance with named ownership, which keeps it below the top band. 3 2 7 8
The Lead Auditor
The risk methodology is real and documented — risk analysis to BSI-Standard 200-3 and 100-3 with measure suggestions drawn from the cross-reference tables, and Grundschutz and BCM risk results flowing together in one tool down to IT implementation. I found no public information on incident handling with statutory reporting clocks or explicit protection-needs inheritance across asset relations, which is what separates a documented methodology from a backbone a certifier works inside. 3 2 7 8
The Evidence Integrator
A documented risk methodology under BSI-Standard 200-3 and 100-3 with cross-reference measure proposals, Grundschutz and BCM risk results converging in one tool and coordinated through to IT implementation, and continuity as a module give a real backbone. We found no public information on incident handling workflows or statutory reporting clocks, and a protection-needs assessment appears only in the privacy module as a threshold analysis for data protection impact assessments. 2 7 8 3 10
The Skeptic
The Grundschutz pages show a real, documented risk methodology — BSI-Standard 200-3 and 100-3 with measure suggestions drawn from the Kompendium cross-reference tables — and Grundschutz and BCM risk analyses converging in one tool down to IT implementation. But we found no public information on incident workflows, statutory reporting clocks, or risk acceptance with named ownership, and protection-needs inheritance across asset relations is never spelled out. 2 7 8
Controls, SoA & measures
Show reasoningHide reasoning
How this is scored
Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.
0 — A static control checklist; applicability, implementation status and evidence are the consultant's spreadsheet.
3 — Control catalogs with status fields, but no SoA generation, no measure ownership, no link between controls and risks.
5 — Controls linked to risks and measures with owners and due dates; SoA producible with manual assembly; internal audit supported by checklists.
8 — SoA on demand from live control status, measure tracking with delegation and escalation, internal audit workflows with findings management, controls carrying their own evidence.
10 — The control fabric as a living system: catalog updates versioned, SoA always current, audit programs with recurring schedules, and every control answerable with linked evidence at any moment.
The CISO
Measures from stored catalogs (BSI Grundschutz, Standard-Datenschutz-Modell, own measures) feed multiple modules from one data basis, findings are automatically routed to the correct recipients, and after a Kompendium update only requirements needing re-assessment are surfaced with prior ratings carried over — that is versioned control maintenance, not consultant-spreadsheet theater. We found no public information on generating a statement of applicability on demand from live control status, or on delegation and escalation in measure tracking. 3 2 10 11
The GRC Consultant
Measures draw from several catalogs — Grundschutz, compliance guidelines, the Standard-Datenschutz-Modell — assigned once and routed automatically to the correct recipients, which is exactly the answer-once discipline I build catalogs around. Kompendium updates arrive as versioned content with carried-over ratings and a re-assessment filter for changed requirements. We found no public information on statement-of-applicability generation on demand or measure delegation with escalation. 3 2 10 11
The Drafted IT Officer
Measures can be selected from stored catalogs — BSI Grundschutz, compliance guidelines, the Standard-Datenschutz-Modell — and assigned to processing activities, and Kompendium updates are handled with a re-assessment filter and ratings carried over from the previous edition, exactly the toil-cutter a drafted security officer prays for. Measures from audits even route automatically to the correct recipients. We found no public information on generating a statement of applicability from live control status, or on delegation and escalation in measure tracking. 3 2 10 11
The Lead Auditor
Measures are genuinely shared rather than re-typed: TOMs selectable from stored catalogs — BSI Grundschutz, compliance guidelines, the Standard-Datenschutz-Modell — measures maintained in other modules assignable to processing activities, and audit findings routed automatically to the correct recipients against the stored infrastructure. I found no public information on generating a statement of applicability from live control status or on delegation and escalation in measure tracking, so the control side is operable but not evidenced as self-documenting. 3 2 11
The Evidence Integrator
Measures are selectable from stored catalogs (BSI Grundschutz, compliance guidelines, Standard-Datenschutz-Modell) and reused across modules, audit findings route automatically to the correct recipients, and Kompendium updates are version-managed with a filter for requirements needing re-assessment and ratings carried over. We found no public information on producing a statement of applicability from live control status or on delegation and escalation in measure tracking. 3 10 11 2
The Skeptic
Requirement ratings are genuinely versioned across Kompendium editions — parallel editions per scope, a filter showing only requirements needing re-assessment after an update, carried-over ratings, and reports that name their underlying edition — and measures from stored catalogs link to processing activities and reach their recipients automatically. We found no public information on a generated statement of applicability, measure ownership with due dates, or delegation and escalation. 10 11 3
Framework & standard coverage
Show reasoningHide reasoning
How this is scored
Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.
0 — One framework, hard-coded; anything else is "on the roadmap".
3 — Two or three frameworks as separate checklists; the same control is answered once per framework.
5 — The major regimes for its market with partial cross-mapping; newer regimes (NIS2, DORA) present as content packs of varying depth.
8 — Broad current coverage including NIS2/TISAX/DORA where relevant, one-control-many-frameworks mapping, and visible maintenance as regimes evolve.
10 — Framework coverage as a living product: dozens of regimes, genuine multi-compliance mapping on one data basis, per-industry profiles, and documented update cadence when the standard moves.
The CISO
Depth in the home regime is real: full support for BSI-Standards 200-1, 200-2 and 200-3, parallel use of multiple Kompendium editions, certification support for ISO 27001 and 22301, and visible preparation for Grundschutz++ in the OSCAL format. For a company with NIS2 exposure, though, this is one island grown very deep — we found no public information on NIS2, DORA or TISAX content. 3 4 2 9
The GRC Consultant
For its home market the core regimes are genuinely operational — full support for BSI-Standard 200-1/200-2/200-3, certification support for ISO 27001 and 22301, and the data protection module reusing Grundschutz measures for GDPR work, so one measure serves several regimes. Catalog maintenance is visible and serious: parallel Kompendium editions, carried ratings, and active Grundschutz++/OSCAL preparation. We found no public information on NIS2, DORA, TISAX or SOC 2 as content, which caps multi-regime breadth. 3 4 2 9 10
The Drafted IT Officer
For its German home market the coverage is solid: BSI-Standard 200-1, 200-2 and 200-3 fully supported, step-by-step support toward ISO 27001 and 22301 certification, GDPR tooling, and visible maintenance toward Grundschutz++ in OSCAL with parallel Kompendium editions. We found no public information on NIS2, TISAX, DORA or SOC 2, and one-control-many-frameworks mapping is only hinted at through shared measure catalogs. 4 2 9 10
The Lead Auditor
For its home market the depth is exceptional: full support of BSI-Standard 200-1/2/3, parallel Kompendium editions, ratings carried forward on updates, and visible preparation for Grundschutz++ in machine-readable OSCAL — that is regime maintenance you can actually watch. Beyond that, ISO 27001 and 22301 appear as certification support and GDPR as a full module; I found no public information on NIS2, TISAX, DORA or SOC 2, and the multi-framework story rests on shared measures on one central data basis rather than demonstrated one-control-many-frameworks mapping. 4 1 2 9 10
The Evidence Integrator
Deep and visibly maintained coverage of the home regime — full support for BSI-Standard 200-1/2/3, parallel Kompendium editions across different structures, and active Grundschutz++ preparation with OSCAL and the BSI timeline — plus certification support for ISO 27001 and 22301, with measures shared across modules on one data basis. We found no public information on NIS2, DORA, TISAX or SOC 2 as operationalized content. 2 9 10 4 3
The Skeptic
Coverage is deep where the German market counts — full support for BSI-Standard 200-1/2/3, parallel Kompendium editions, active Grundschutz++ preparation with OSCAL and Blaupausen, plus ISO 27001/22301 certification support and Datenschutz catalogs including the Standard-Datenschutz-Modell. But we found no public information on NIS2, TISAX, DORA or SOC 2 content, nor on one-control-many-frameworks mapping; credit to the vendor for stating plainly that Grundschutz++ is implementable only once the BSI publishes a stable version rather than selling it as shipped. 2 9 4 3
Audit readiness & evidence
Show reasoningHide reasoning
How this is scored
Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.
0 — Exports are screenshots; history is overwritten in place.
3 — PDF reports exist but evidence is attached ad hoc and changes leave no reliable trail.
5 — Versioned records, standard report generators, evidence attachments per control; assembling a full audit file still takes days.
8 — Revision-safe change history, audit-scoped evidence packs on demand, management reports current at a click, auditor access roles.
10 — Audit readiness as a standing state: continuous evidence status per framework and scope, exportable proof packs an external auditor accepts as-is, and a defensible answer to "show me the state on date X".
The CISO
The audit management module claims central, tamper-proof documentation, audits planned per ISO 19011 with an annual plan grouped by audit programme, mobile on-site evidence capture with real-time observations, and reports that state the underlying Kompendium edition and remain available for previous editions — the bones of a defensible audit file. We found no public information on auditor access roles or audit-scoped evidence packs assembled on demand. 10 11 12
The GRC Consultant
Everything relevant is captured centrally and documented revision-safe, audits run per ISO 19011 with annual plans grouped by audit programme, and mobile applications collect evidence on site with photos and notes — that is the standing-audit-file shape I want to hand a certifier. Reports state the underlying Kompendium edition and prior editions remain reproducible, with ad-hoc reporting for management. We found no public information on dedicated auditor access roles or exportable audit-scoped evidence packs. 10 11 12
The Drafted IT Officer
Audit handling looks genuinely operable: central capture with revisionssichere (tamper-proof) documentation, audits to ISO 19011 across customer, supplier and internal scopes, an annual audit plan grouped by programme, mobile on-site evidence capture, and ad-hoc reporting. Reports state the underlying Kompendium edition and older editions remain printable, which answers 'which version was this' nicely. We found no public information on auditor access roles or audit-scoped evidence packs on demand, so it is a strong seven rather than a standing state. 10 11 12
The Lead Auditor
Revision-safe documentation is claimed outright with all information centrally captured, and reports name the underlying Kompendium edition while reports on previous editions remain available — that gives a defensible answer for the state under a given framework edition. Mobile evidence capture in real time, ISO 19011 audit programmes with annual plans, and ad-hoc reporting round it out; I found no public information on auditor access roles or exportable evidence packs per scope, so this is strong but not the standing state I certify against. 10 11 12
The Evidence Integrator
Revision-safe central documentation is stated outright, alongside audit programmes with annual plans for customer, supplier and internal audits per ISO 19011, mobile on-site evidence capture, dashboards, ad-hoc reporting, and reports stamped with the underlying Kompendium edition where prior editions remain reproducible. We found no public information on dedicated auditor access roles or a full point-in-time reconstruction of any past state. 11 10 12
The Skeptic
The audit module is unusually concrete: ISO 19011 audit programmes with an annual plan, customer, supplier and internal audits, mobile on-site evidence capture with real-time observations, photos and notes, findings routed as measures to the right recipients, and central revision-safe documentation plus ad-hoc reporting. We found no public information on auditor access roles or audit-scoped evidence packs, and revision safety is asserted on the module page rather than shown in mechanism. 11 12 10
Integrations & automation
Show reasoningHide reasoning
How this is scored
Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.
0 — A closed island: manual entry in, PDF out, no API.
3 — CSV/Excel import and export; no live connections, no API worth the name.
5 — Directory import (AD/Entra), a documented REST API for core objects, a handful of native connectors (ticketing, CMDB or SSO); automation is reminders and recurrence.
8 — Real connector set (Jira/ServiceNow-class ticketing, CMDB, cloud and endpoint sources), webhooks, SSO/SCIM, automated evidence tests with human review.
10 — The platform behaves like infrastructure: API parity for the data model, event streams, continuous control monitoring against the live estate, and automation that measurably removes the recurring toil rather than renaming it.
The CISO
The real estate can feed the tool: import from GSTOOL, CMDB and Excel, a dynamic XML interface for binding data rather than re-typing it, a DataExchange extension for database connections, and validated questionnaires that write directly into the database. We found no public information on a REST API, SSO or SCIM, ticketing connectors of the Jira/ServiceNow class, or automated evidence tests with human review. 3 2 11
The GRC Consultant
Data comes in from the real estate — GSTOOL, CMDB and Excel import plus a dynamic XML interface for live binding, with a DataExchange extension for database connections — and decentralized questionnaires flow through a validation process straight into the database. The low-code model lets a customer extend the data model without programming. We found no public information on a REST API, directory or SSO integration, ticketing connectors, or automated evidence testing with human review. 3 2 11
The Drafted IT Officer
It feeds from more than spreadsheets: data from GSTOOL, CMDB and Excel can be imported or bound via a dynamic XML interface, a DataExchange extension covers database connections, and questionnaire answers flow directly into the database after validation. But that is an import-and-XML world, not a connector world — we found no public information on directory import from Active Directory/Entra, a documented REST API, ticketing or single-sign-on connections. 3 2 11
The Lead Auditor
Feeding the real estate is present but dated: direct import from GSTOOL, CMDB and Excel, a dynamic XML interface for binding data in, and a DataExchange extension for database connections — exactly the federal tooling you would expect. I found no public information on a REST API, directory import, SSO, webhooks or ticketing connectors, and the automation evidenced is push-button report compilation and questionnaire imports rather than continuous collection. 3 2
The Evidence Integrator
This is an import drawbridge rather than a live feed: GSTOOL, CMDB and Excel arrive by import or a dynamic XML interface, database connections come through the DataExchange extension, and low-code lets customers extend the data model themselves. We found no public information on a documented REST API, directory synchronization (AD/Entra), ticketing or cloud/endpoint connectors, SSO/SCIM, webhooks, or automated evidence tests against the live estate — so evidence stays typed, not tested. 2 3 1 11
The Skeptic
Beyond flat file import there is a dynamic XML interface, GSTOOL and CMDB import, a DataExchange extension for database connections, and decentralized questionnaires feeding validated answers directly into the database. We found no public information on a documented REST API, directory or single-sign-on connectors, ticketing integration, or automated evidence testing, so what is shown is import and workflow plumbing rather than feeding from the live estate. 2 3 11
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for the system holding your risk register.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The CISO
A Berlin GmbH under German parent HiSolutions AG, development and support entirely in Germany, SaaS in data centers within Germany, on-premise at equal feature set, and a federal SaaS variant operated by ITZBund — a sovereignty position I can defend to my own auditor. The published subprocessor list covers the website and customer portal rather than the platform and names a processor relying on the EU-US Data Privacy Framework, the data centers themselves are not named, and the captured pages give different figures for third-country transfers. 4 5 6 2
The GRC Consultant
A German GmbH in Berlin, SaaS data stored in data centers within Germany with an on-premise variant at equal feature set, development and support 100 percent in Germany, named subprocessors with Article 28 contracts, and a federal SaaS offering via ITZBund — that is about as German as deployment gets. The product data centers are not individually named, and webinar registrations run through an Irish GoTo entity whose processing the privacy policy concedes occurs in a third country under the Data Privacy Framework and standard contractual clauses. 4 5 6 2
The Drafted IT Officer
What I can verify is German: Berlin entity with register entry, SaaS data stated to sit in data centers within Germany, an on-premise variant with the identical feature set, and development and support 100% in Germany. The published subprocessor picture covers the website and customer portal — DEONT GmbH hosting, Sendinblue, GoTo, a YouTube embed and a tracking pixel — rather than the GRC platform itself, the data centers are not named, and webinar data via GoTo is processed in a third country under Data Privacy Framework and standard-clauses safeguards. 4 5 6 2
The Lead Auditor
This is a chain I can mostly defend: a Berlin entity wholly owned by the German HiSolutions AG, development and support 100 percent in Germany, SaaS data in data centers within Germany, and an on-premise variant with equal feature set — plus an ITZBund-hosted standard offering for federal authorities. The published processor list covers the website and customer portal rather than the platform itself, and the webinar chain relies on EU-US Data Privacy Framework certification, so a US reach remains at the periphery. 4 5 6 2
The Evidence Integrator
A German GmbH under German parent HiSolutions AG, development and support 100 percent in Germany, SaaS data stated to sit in data centers within Germany, an on-premises variant with equal functionality, and Art. 28 GDPR contracts with the named Berlin hoster make a strong chain for the system holding the risk register. The captured residency statement covers the website and customer portal rather than naming the product's data centers, the subprocessor exposure of the core product is not confirmed on the captured pages, and webinar processing runs through GoTo under the EU-US Data Privacy Framework. 4 5 2 6
The Skeptic
The chain is visibly German — a Berlin GmbH under German parent HiSolutions AG, development and support 100% in Germany, SaaS data in data centers within Germany, an on-premises option with equal features, and a federal SaaS variant via ITZBund. But the published subprocessor list covers only website and customer-portal processing rather than the GRC product itself, the data centers are not named, and the captured pages both state that no third-country transfer is foreseen and invoke GoTo's EU-US Data Privacy Framework certification for webinar processing. 4 2 6 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.
0 — No public prices at all; every configuration is a sales conversation.
3 — An entry price exists, but module add-ons, scale steps or bundled consulting make the real total incomputable.
5 — Most editions carry real numbers with billing period stated and software separated from services; at least one commonly needed module or scale step is unpriced.
8 — Every edition and module priced publicly with entity/user boundaries and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: modules, scale steps, service packages and renewal rules public, so the invoice for a 100-employee company and a certification project is a two-minute exercise.
The CISO
We found no public prices on any captured page — no edition, module, user or scale pricing anywhere, and the audit management module's product sheet is available only on request. Computing the real invoice for a 400-employee certification project is impossible without a sales conversation. 11
The GRC Consultant
We found no public prices at all on the captured pages — no edition, module or user figures anywhere — and even the audit-management product sheet is offered only on request, so every configuration begins with a sales conversation. 11 3
The Drafted IT Officer
We found no public price figures on the captured pages — no edition prices, no billing periods, nothing per module. Even the audit-management module's product information is provided only on request, and the pages route enquiries to a sales address, so the real invoice is computable only through a sales conversation. 3 11
The Lead Auditor
No public price appears on any captured page; even the audit module's product factsheet is request-only, with the sales address as the path to information. Every configuration is a sales conversation, which the market norm tolerates but the buyer should know upfront. 3 11
The Evidence Integrator
The captured pages carry no prices for any module, edition or scale step, and the audit module's product factsheet is offered only on request. Every configuration therefore points to a sales conversation. 11 3
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 6 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 23 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. This statement covers HiScout's own website and customer-portal processing, which is hosted by the Berlin-based DEONT GmbH; the excerpt says nothing about where the core HiScout GRC software itself is deployed, and it elsewhere concedes that webinar registrations via GoTo Technologies are processed in a third country.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (hiscout.com, hiscout.com/module/grundschutz, hiscout.com/module/datenschutz, hiscout.com/ueber-uns, hiscout.com/impressum, hiscout.com/datenschutzerklaerung and 6 more). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 49 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
Sources (12)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.hiscout.com Checked 15 Sep 2026 +1 earlier capture: 23 Aug 2026 Details →
- 2 IT-Grundschutz module page www.hiscout.com Checked 15 Sep 2026 +1 earlier capture: 23 Aug 2026 Details →
- 3 Data protection module page www.hiscout.com Checked 15 Sep 2026 Details →
- 4 About page www.hiscout.com Checked 15 Sep 2026 Details →
- 5 Imprint www.hiscout.com Checked 15 Sep 2026 Details →
- 6 Privacy policy www.hiscout.com Checked 15 Sep 2026 +1 earlier capture: 24 Aug 2026 Details →
- 7 Asset & risk management depth — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →
- 8 Asset & risk management depth — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →
- 9 Framework & standard coverage — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →
- 10 Framework & standard coverage — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →
- 11 Audit readiness & evidence — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →
- 12 Audit readiness & evidence — found from sitemap www.hiscout.com Checked 1 Oct 2026 Details →