HomeProductsAIServicesIntegrationsCompany
01 · Information Security Management System · ISO/IEC 27001

Purplecop One GRC

The whole GRC estate in one product. Frameworks, controls, evidence, risk, vendors, audit and awareness — every one of them a module on the same control library and the same evidence store, and every one of them AI-assisted.

14 modules, all included

Every module on one control library.

ISMS14modulesISO/IEC 27001Frameworks75+ frameworks mapped once and reused everywhere.ControlsOne control library. Test a control once, satisfy every frameworkmapped to it.PoliciesAI-drafted policy, versioned, approved and mapped to the controls itsatisfies.EvidenceCollected automatically, timestamped, reused across every framework.Risk RegisterScored, owned and tracked, fed by everything else in the product.TPRMOnboard, assess, score and continuously monitor every vendor.SecurEnd.AIAttack-surface discovery and cyber risk quantification. Theoffensive half.DSPMDiscovers, classifies and protects sensitive data wherever it lives.Audit ManagementInternal and external audit run end to end, with the auditor in theworkspace.CSATMaturity benchmarking against NIST CSF 2.0, ISO 27001 and theregulator packs.LMSRole-based awareness training with per-user risk scores. Builtin-house.Phishing SimulationLive campaigns whose results feed the human-risk score directly.Trust CenterThe public face of the posture, kept current by the evidence store.Asset ManagementThe estate the controls actually apply to, discovered and owned.
5 AI agents, inside these modules

Every agent suggests.
A person still decides.

Each one takes a single repetitive job inside a module you already use, quotes the sentence it based its answer on, and hands it to a person. None of them can change a record. A deterministic file checker inspects every upload before any of them sees it.

AGT-01

Evidence Examiner

lives in Evidence

Reads a document against the requirement and says whether it really proves the control — then quotes the exact sentence that made it decide.

About 12,000 documents a year get opened and asked the same question.

Never marks evidence approved. Never moves the workflow forward.

AGT-02

Policy Drafter

lives in Policies

Finds the right template out of the 1,605 we already own and tailors it to that customer’s departments, systems and review cycle.

It never writes a policy from scratch. A two-day job becomes twenty minutes.

Never publishes. Never approves. Never starts the sign-off.

AGT-03

Risk Challenger

lives in Risk Register

Once a month, compares every risk rating against how its controls are actually performing, and raises a challenge where the two disagree.

A register that has quietly gone out of date gets caught between audits instead of during one.

Never changes a rating. It raises a task for the risk owner.

AGT-04

Audit Reviewer

lives in Audit Management

Acts as a sceptical outside auditor on one requirement and gives a second opinion before the real auditor arrives.

Customers usually find out what an auditor thinks when the auditor tells them. By then it is on the record.

Never writes to the audit record. Never overrides your own conclusion.

AGT-05

Questionnaire Responder

lives in Trust Center

Drafts an answer to every question in a security questionnaire from your live compliance data — and refuses to answer where the proof is missing.

A 300-question questionnaire takes minutes instead of the week a security engineer normally loses to it.

Never sends an answer to the buyer. Never publishes to your Trust Center page.

Where it connects

Standalone,
not isolated.

One identityOne user, one role model, one access trail across all three products.
One control libraryTest a control once. It satisfies every framework mapped to it, in any of the three.
One evidence storeCollected automatically, reused everywhere, never screenshotted twice.

See Purplecop One GRC on your own data.

A walkthrough end to end, then a trial environment scoped to what you actually need to prove.