Coming 2026

Prove what your systems did

Most governance software records what a company says it does, and its green ticks mean somebody completed a task. KWAYZER Governance is being built to record the same things — and then go and check.

The problem

You are running this on a shared drive

Industry surveys put roughly six in ten compliance teams in spreadsheets and folders. It works until somebody asks you to prove something — and then it costs three weeks, or a certification, or a fine.

  • Which version of that policy is current?

    Three PDFs in SharePoint, all called final. The one on the intranet is from 2023. Nobody is certain which one people actually signed.

  • Who approved this, and when?

    It was approved in an email thread. That person has left. The thread is in a mailbox nobody can open, and the approval cannot be produced.

  • The auditor wants evidence by Friday.

    Three weeks of somebody's life, spent screenshotting settings and hunting through folders — for a request that will be identical next year.

  • The policy says 24 hours. Does it happen?

    Leavers are supposed to lose access within a day. Nobody has ever checked whether they do. The control is green because a task was ticked.

  • Are we even in scope for NIS2?

    In force since December 2025, no transition period, and management liability is personal. Around 29,500 German companies are affected — and the law works by self-identification, so there is no register that tells you whether you are one.

  • Our website says we're certified.

    The certificate expired in March. It is still on the pricing page, in the sales deck, and in an answer you gave a prospect last week.

Governance would replace the drive, and then do the thing the drive never could. One place for your documents, approvals, risks and evidence — and then it would go and check whether what you wrote down is actually happening, against your real systems, with the boundary of what it could see stated plainly.

Start here

What it would actually do

Before the clever part: the everyday work this replaces from the first week. Most of the buyers this is designed for are running all of it on a shared drive, a spreadsheet and email approvals today.

  • One dashboard: what needs you today

    Not a module grid. Approvals waiting, policies due for review, evidence about to expire, controls that failed, a statutory clock running. Ranked by what matters, with the owner named.

  • Every company document in one place

    Policies, SOPs, contracts, certificates, licences, insurance. Versioned, owned, classified, with a review date — and exactly one version that is actually in force.

  • Approvals that leave email

    Sequential, parallel or quorum. The approval binds to the exact version approved, so a document edited afterwards goes back for review instead of quietly shipping.

  • Privacy paperwork, handled

    Your processing register, impact assessments, processing agreements, retention schedules and subject access requests — as workflows with owners and deadlines, not four documents somebody rewrites each year.

  • Policies your staff actually acknowledge

    On a phone, in their own language, in under a minute. Reminders escalate on their own. You get evidence of who read which version, and when.

  • One calendar of every deadline

    Policy reviews, audits, vendor renewals, certificate and insurance expiry, training, regulatory dates. Escalation follows the business calendar, so nothing expires into a Saturday.

  • Your vendors, with their paperwork

    Who they are, what data they touch, their processing agreement, their subprocessors, when the contract renews, and evidence that offboarding actually happened.

  • An audit room instead of a shared drive

    An auditor gets exactly the evidence they asked for, for a fixed period, with no ability to browse next door. Their actions log separately from yours.

Free, and useful whether you buy anything

Are you in scope for NIS2?

Germany's NIS2UmsuCG has been in force since December 2025, with no transition period. Around 29,500 German companies are affected, and the law works by self-identification — there is no register that tells you whether you are one of them. Management liability is personal and cannot be delegated away.

Probably not reached by sector

NIS2 names eighteen sectors across Annexes I and II. Yours is not among them — though a supplier relationship with an in-scope company will often put the same security requirements into your contracts anyway.

rule: Annex I and II sector list · no size test applied

This runs entirely in your browser. Nothing you choose is sent anywhere, stored, or recorded — there is no request behind this control at all. It applies the size-cap rule and shows the reasoning; whether the law reaches you is a question for your own counsel.

The product

Twenty-two modules

One graph, one permission model, one audit log. Pick a group — the counts, the names and the descriptions are the specification's own, and every one of them is written as what the product WOULD do.

The register half — what applies to you, where it came from, and the documents that answer it.

  • Organisation profile and applicabilityLegal entities, countries, headcount bands, sectors, regulated activities, data categories, certifications held and targeted.

    Legal entities, countries, headcount bands, sectors, regulated activities, data categories, certifications held and targeted. A rules engine would map those facts to applicable obligation packs, and every result would be explainable end to end: input fact, rule, source, effective date, result, confidence, reviewer. Five states, one of which is unknown-because-a-fact-is-missing. Entering a country or acquiring a company would trigger recalculation with an impact preview before anything changed, and no automated step could promote likely-applies to applies.

  • Regulatory radar and source libraryVersioned regulatory sources with jurisdiction, authority, publication and effective dates.

    Versioned regulatory sources with jurisdiction, authority, publication and effective dates. Ingestion would create immutable source snapshots with fingerprints; a new version would produce a textual and semantic diff. Candidate obligations would be extracted with clause citations and would require a human to confirm before becoming an authoritative company obligation. Proprietary regulatory content would never be scraped or redistributed — references and permitted excerpts per licence.

  • Obligation register and common control mappingEach obligation carries its authority, source clause, plain-language requirement, applicability basis, owner, frequency and evidence expectation.

    Each obligation carries its authority, source clause, plain-language requirement, applicability basis, owner, frequency and evidence expectation. Many obligations map to one control, and coverage would be computed from control and evidence state rather than painted by hand. A crosswalk would show which controls satisfy several frameworks and a specific customer contract at once.

  • Governance library and controlled documentsPolicies, procedures, standards, licences, certificates and contracts with full metadata and side-by-side version diff.

    Policies, procedures, standards, licences, certificates and contracts with full metadata and side-by-side version diff. Exactly one current effective approved version per lineage. Seven access classes with separate view and download rights and expiring external share links. Per source and per folder, the tenant would choose whether the document lives here and the external copy is a mirror, or lives externally with governed metadata and a version fingerprint held here — which is the duplicate-ownership problem that kills adoption of every document-governance product.

  • Policy lifecycle and attestationSequential, parallel, quorum and threshold approval chains.

    Sequential, parallel, quorum and threshold approval chains. Acknowledgement campaigns with evidence of who saw which version. Material-change detection would require re-acknowledgement only where relevant sections changed, so a typo fix does not re-interrupt everybody. Exceptions and waivers would attach to exact clauses and expire automatically. An acknowledgement of a policy in a language the employee could not read is weak evidence and the assurance model would treat it as such.

Why this would be hard to copy

Each claim names its mechanism

A claim without one is a sentence anybody could write.

  • Governance you would not have to type

    Every product in this category hands you a blank register. Where discovery is connected, the first draft of your processing register, system inventory and data map would be generated from what your systems actually contain — every entry marked inferred, with its evidence, waiting for a human. Nothing generated could reach a verified state on its own.

    would be seeded from the discovery census · every row lands inferred

  • The check would run against reality

    A control saying leavers lose access within 24 hours would be tested against your identity provider, and the answer would state what it could see. Partial visibility never becomes a universal claim — “verified for users in this tenant at 02:00 UTC; the legacy directory is not covered” is the shape of an honest result.

    a control test would declare the boundary of its own observation

  • Proof debt as a balance

    Everything asserted but unproven, expired or waived would be counted and weighted as a trend. Three convenient exceptions in a quarter would show up as a rising line, which is the conversation a board should be having rather than three closed tickets.

    proof coverage with its denominator shown · proof debt as a trend

  • Leaving would be a feature

    Full export in documented formats, plus a signed evidence certificate an offline verifier can check without trusting our interface. That matters most from a vendor nobody has heard of yet — and export would never sit behind a higher tier, because charging for portability contradicts the pitch.

    the portable governance passport · export is not a paid tier

  • It would never certify anybody compliant

    It would produce registers, evidence, and the difference between what you documented and what your systems actually do. The conclusion stays a human's and, where it matters, a lawyer's. A product that grades your compliance is a product that has taken a decision it cannot be accountable for.

    stated as a refusal in the specification, not as a setting

  • The two modules the category does not have

    A works-council consultation can VOID a change in Germany, and a speak-up channel is legally required at fifty employees. Both are modelled as first-class workflows rather than as a policy document about them — and the speak-up channel would be invisible to tenant administrators, because a whistleblowing channel your own admin can read is not one.

    Works council · Whistleblowing and speak-up, both in the module list

The spine of the whole product

Six states, and green is the rarest

Nothing here would coerce uncertainty into green. A control that cannot be checked says so, and stays visible until somebody resolves it.

  1. Mechanically verified

    Observed at the source, or read back after a change. The only state that is independent of what anybody claims.

  2. Human confirmed

    An authorised person asserted it, with their identity and the time. Useful — and not the same as proof.

  3. Inferred

    Derived with supporting evidence and a confidence. Never a final compliance state, however convincing it looks.

  4. Accepted exception

    A known gap somebody with authority accepted, until a date. Visible residual exposure, not a resolved item.

  5. Expired proof

    The evidence existed and is now outside its freshness policy. Assurance decays on its own.

  6. Unresolved

    Not enough evidence, or no decision. Must stay visible. This is the state every other product quietly rounds up.

Framework packs

Content, not forks

Every pack would be rules, workflows and reports over the same objects. None of them forks the product — which is how a framework vendor ends up with a NIS2 module two years behind its GDPR one.

  • GDPR / privacy

    Processing register, impact assessments, subject requests.

  • ISO 27001

    Control set, statement of applicability, evidence expectations.

  • BSI IT-Grundschutz

    The German public-sector and critical-infrastructure baseline.

  • NIS2

    Scope determination, the §30 risk-management duties, registration and reporting obligations.

  • DORA

    Financial-sector operational resilience and the third-party register.

  • EU AI Act

    Role classification, prohibited-use screen, transparency and oversight duties.

  • SOC 2

    Trust-services criteria mapped onto the same controls.

  • TISAX (VDA ISA)

    The automotive supply chain's information-security assessment.

  • Works council (DACH)

    Consultation triggers and workflow, configured per country.

  • GoBD retention (DACH)

    German record-keeping and retention duties.

What we intend to build

Specified · not built · coming 2026

Everything in this section is SPECIFIED AND NOT BUILT. It is the design we intend to ship in 2026, published so you can judge whether it is worth waiting for — not a description of software you could use today. The section above it is what exists now.

GOVERNANCE-BUILD-spec-v3-UNIFIED.md

Why it would be worth waiting for

  • Governance Reality Check

    Most governance software records what a company SAYS it does, and a green tick means somebody completed a task. A reality check would turn a documented rule into a machine-observable condition, run it against the connected system, and store the observed result with the connector version and the time it was read. A control that says leavers lose access within 24 hours would be checked against the identity provider. A mismatch could not be set to verified by hand: closing it would require new evidence, a read-back, or an authorised exception with an expiry. And every check would declare the boundary of its own observation — verified for users in this tenant at 02:00 UTC, contractors in the legacy directory not covered — because partial visibility becoming a universal claim is the single thing that separates assurance from theatre.

  • Proof coverage and proof debt

    Six assurance states rather than a colour: mechanically verified, human confirmed, inferred, accepted exception, expired proof, unresolved. Inferred would never be a final compliance state. Proof coverage would be a transparent ratio per obligation, control or entity with its denominator shown, never a single score. Proof debt would be the accruing balance of accepted-but-unproven, expired and waived assertions, shown as a trend — so three emergency waivers in a quarter appear as a line going up rather than as three closed tickets.

  • Governance seeded from what we already observed

    Every product in this category asks the customer to type their processing register, system inventory and data map from memory, once, after which it rots. Where KWAYZER Atlas has crawled the estate, the first draft would be generated from observation instead — processing activities from observed data categories and flows, system inventory from connected sources, vendor inventory from observed integrations and OAuth grants, retention reality against declared policy. Every generated entry would land marked inferred with its evidence and would wait for a human to confirm it. Nothing generated could reach mechanically verified on its own.

  • The governance-estate importer

    Switching cost is what incumbents rely on. Policies from a document store, risk registers and control matrices from spreadsheets, evidence from folder exports — mapped, deduplicated, versioned, with per-record provenance, using the migration product's own discipline. Every imported record would land as human confirmed at best, never mechanically verified, and import quality would be stated per batch with the unmapped remainder listed rather than dropped.

The modules, named

  • What you are responsible forThe register half — what applies to you, where it came from, and the documents that answer it.
    • Organisation profile and applicability

      Legal entities, countries, headcount bands, sectors, regulated activities, data categories, certifications held and targeted. A rules engine would map those facts to applicable obligation packs, and every result would be explainable end to end: input fact, rule, source, effective date, result, confidence, reviewer. Five states, one of which is unknown-because-a-fact-is-missing. Entering a country or acquiring a company would trigger recalculation with an impact preview before anything changed, and no automated step could promote likely-applies to applies.

    • Regulatory radar and source library

      Versioned regulatory sources with jurisdiction, authority, publication and effective dates. Ingestion would create immutable source snapshots with fingerprints; a new version would produce a textual and semantic diff. Candidate obligations would be extracted with clause citations and would require a human to confirm before becoming an authoritative company obligation. Proprietary regulatory content would never be scraped or redistributed — references and permitted excerpts per licence.

    • Obligation register and common control mapping

      Each obligation carries its authority, source clause, plain-language requirement, applicability basis, owner, frequency and evidence expectation. Many obligations map to one control, and coverage would be computed from control and evidence state rather than painted by hand. A crosswalk would show which controls satisfy several frameworks and a specific customer contract at once.

    • Governance library and controlled documents

      Policies, procedures, standards, licences, certificates and contracts with full metadata and side-by-side version diff. Exactly one current effective approved version per lineage. Seven access classes with separate view and download rights and expiring external share links. Per source and per folder, the tenant would choose whether the document lives here and the external copy is a mirror, or lives externally with governed metadata and a version fingerprint held here — which is the duplicate-ownership problem that kills adoption of every document-governance product.

    • Policy lifecycle and attestation

      Sequential, parallel, quorum and threshold approval chains. Acknowledgement campaigns with evidence of who saw which version. Material-change detection would require re-acknowledgement only where relevant sections changed, so a typo fix does not re-interrupt everybody. Exceptions and waivers would attach to exact clauses and expire automatically. An acknowledgement of a policy in a language the employee could not read is weak evidence and the assurance model would treat it as such.

  • Whether it is actually being doneThe proof half. This is where the product either checks, or admits that it did not.
    • Controls hub

      A common control library with objective, owner, operator, frequency, population and evidence expectation. Design effectiveness and operating effectiveness would be separate states, so a well-designed control nobody runs is not effective and the product says which of the two failed. Test definitions would be versioned, and a changed test could not rewrite historical results.

    • Evidence vault and continuous evidence

      Every item would carry the source identity and connector version, the exact query or test used, the collection timestamp and observation window, a scope and population statement, a content hash, a freshness policy and the collector's identity. Expiry would change control status automatically — assurance decay in code rather than a green badge that never goes out.

    • Audit and assessment centre

      Audit universe, plan, engagements, samples, evidence requests, findings and management responses. Framework assessments and customer security questionnaires would reuse existing controls and evidence rather than starting blank. An external audit room would give time-limited, least-privilege access to exactly the requested evidence and nothing adjacent, and auditor actions would log separately — independence as structure rather than as procedure.

    • Access review campaigns

      Reviewers would attest each account as confirm, revoke, modify or cannot-judge — and cannot-judge would be a first-class answer routed onward, never coerced into confirm. Revocations would become remediation tasks with read-back verification against the identity connector. Population completeness would be stated: reviewed 214 of the 214 accounts visible to this connector, and this other directory is not covered.

  • What is at riskRisk, incidents, resilience, and the third parties who carry your exposure for you.
    • Risk hub and appetite

      Inherent likelihood and impact, existing controls, residual, treatment and owner, with appetite and tolerance per category and business unit. Acceptance would require configured authority and carry automatic expiry. Where a risk carries a monetary exposure model, the model, its inputs and its uncertainty would be shown with it — a single number without its method would be refused, because aggregation that manufactures precision is worse than a colour.

    • Incident, issue and corrective-action hub

      One record for a control failure, policy breach, privacy or cyber incident, audit issue or vendor issue. The timeline would assemble itself from evidence and events. A major incident would open a regulatory-notification ASSESSMENT with its statutory timers running visibly — without asserting that a duty exists, which is a legal conclusion this product does not draw.

    • Business continuity and operational resilience

      Critical processes and services, impact analysis, dependencies, recovery targets, plans and exercises. An actual incident would compare measured recovery against the target and update residual risk from what happened rather than from what was planned.

    • Third-party and vendor governance

      Inventory with criticality, data access, processing locations, contract and data-processing-agreement dates, subprocessors, certifications and AI usage. Questionnaires would prefill from prior evidence, and an automated analysis would have to cite the supplied evidence. Offboarding would be verified rather than assumed — access removed, data returned or deleted, tokens revoked, retention obligations discharged, each with its own evidence.

  • The regulated specialismsTwo packs deep enough to be modules. Both link to the same objects; neither forks the product.
    • Privacy and data governance

      Processing register with legal basis, purposes, categories, recipients, transfers and retention. Impact-assessment workflow. Subject-request case workflow with data-location mapping and deletion evidence. Where the discovery engine is connected, DECLARED data locations and flows would be compared against OBSERVED ones and the mismatches flagged — every competitor takes the customer's word for their register, and this is the one that can check it.

    • AI governance, including agent governance

      Inventory of provider, model, purpose, owner, business process, users, affected persons, data used and jurisdictions, with role classification, risk tier and a prohibited-use screen. A model or version change would create a reassessment event rather than silently inheriting approval. And where a customer runs AI agents — including agents doing compliance work — the inventory would record the agent's identity, permitted tools, data reach, action-level authorisation and kill switch. An agent performing governance is itself a governed system.

  • The half no US-built product hasTwo modules that are legally load-bearing in Germany and much of the EU, and absent from the category.
    • Works council and employee consultation

      A works council has statutory co-determination rights over employee monitoring, technical systems that could monitor performance, working-time rules and AI tools affecting employees. A change that skips consultation is not merely impolite — it can be void. Changes touching consultation-relevant subject matter would be flagged from the change's classification and its graph relationships rather than from a manual checkbox, a consultation workflow would run parallel to the approval chain, and where the tenant configures it the change would be blocked from becoming effective while consultation is outstanding. Subject-matter triggers and legal weight are configured per country.

    • Whistleblowing and speak-up

      Identified, confidential and fully anonymous submissions, reachable without an account, with two-way dialogue with an anonymous reporter through a case key. Cases would be access-restricted to named handlers, not visible to tenant admins, with access attempts logged. Statutory timers — acknowledgement and substantive feedback — would be visible and escalate on a business calendar. Reporter identity would never be inferable from logs, notifications or model context, and an export would never include identity unless the reporter chose to give it.

  • The record, and who you have to answer toChange, authority, the calendar, the board, and the customers who ask you the same questions every quarter.
    • Change, update request and approval hub

      One universal request object covering policy and document updates, control changes, access changes, exceptions, vendor onboarding, AI-use approval, regulatory remediation and works-council consultation. Impact analysis would be automatic: the graph would list the affected policies, obligations, controls, risks, vendors, systems and open audits BEFORE anyone approves. Emergency changes would be permitted and would force retrospective review with evidence.

    • Decision, authority and corporate governance register

      It would record what was decided, the alternatives considered, the rationale, the decision-maker, the authority basis, the conditions and the expiry. A delegation-of-authority matrix for who may approve spend, contracts, risks, policies, vendors and exceptions, at which thresholds, in which entity. Officer designations as governed role records with appointment evidence. Deliberately a lightweight governance record and not a board-meeting suite.

    • Governance calendar, training and recurring duties

      One calendar for policy reviews, audits, vendor renewals, risk reviews, regulatory deadlines, control cycles, training, and certificate and insurance expiry. Escalation would respect the business calendar, time zone, delegation and absence — a risk acceptance expiring on a Saturday escalates on Monday to a present human, rather than into a void.

    • Executive and board assurance

      Governance health, residual risk outside appetite, proof coverage and debt, overdue accountable items, failed controls, regulatory-change exposure, audit findings and vendor concentration. Every executive metric would drill through to its source records, and there would be no untraceable risk score anywhere in the product. Assurance-pack snapshots would be immutable, so a board can prove later what it was actually shown.

    • Trust centre and customer assurance

      A public, tenant-branded assurance page where every entry would be backed by a claim object carrying its substantiation and expiry — and a claim whose substantiation lapses is flagged to its owner and falls off the public page rather than going stale. Non-disclosure-gated document requests with approval, watermarking and expiring links. Inbound security questionnaires prefilled from the same objects. Subprocessor-change notification to subscribed customers.

The packs — content over the same objects, never a second product

  • GDPR / privacy

    Processing register, impact assessments, subject requests.

  • ISO 27001

    Control set, statement of applicability, evidence expectations.

  • BSI IT-Grundschutz

    The German public-sector and critical-infrastructure baseline.

  • NIS2

    Scope determination, the §30 risk-management duties, registration and reporting obligations.

  • DORA

    Financial-sector operational resilience and the third-party register.

  • EU AI Act

    Role classification, prohibited-use screen, transparency and oversight duties.

  • SOC 2

    Trust-services criteria mapped onto the same controls.

  • TISAX (VDA ISA)

    The automotive supply chain's information-security assessment.

  • Works council (DACH)

    Consultation triggers and workflow, configured per country.

  • GoBD retention (DACH)

    German record-keeping and retention duties.

The shape of the plans

No numbers yet — pricing is set when the product opens, and a figure written here now would be one somebody quoted from.

  • Core

    The library, policies, approvals, change requests, basic risk, the calendar, the audit log, the employee surface — and speak-up. Unlimited employees. For a company of 20–100 people putting a first governance system in place.

  • Assurance

    Adds controls, evidence, automated tests, reality checks, audits, vendor governance, access reviews and the trust centre, with obligation packs included. For a growing regulated or business-to-business company.

  • Enterprise

    Adds enterprise sign-on and provisioning, advanced segregation, a dedicated environment, residency, the API, log export, board assurance and an auditor portal. For groups and high-assurance buyers.

What it would refuse to do

It would never certify anybody compliant. It produces registers, evidence and the difference between what you documented and what your systems actually do; the conclusion is a human's and, where it matters, a lawyer's. Audit history and data export would never sit behind a higher tier — portability is a product principle, and charging for it contradicts the pitch. And templates are templates: a starter policy library is not legal advice.

Pricing

Not available yet. Join the waitlist and we will come back to you before it opens, not after.

Join the waitlist

This is a real list that a person reads — not a form that collects an address and does nothing with it.