Audit-grade by default
What teams do today — and why it hurts.
Most risk registers are static 5×5 grids in Excel. Methodology changes don't version — they overwrite. SOP controls aren't linked, so nobody knows whether updating an SOP changed the residual on the risk it controls. Treatment plans live in yet another tool.
One workspace. One audit trail. One transaction.
Pick a methodology — 5×5 default, 3×3, N×M, FMEA, or custom. The methodology is versioned; approving a risk freezes the methodology snapshot onto the assessment so historical decisions stay readable forever. Controls reference SOP versions and have effectiveness multipliers (DESIGNED 0.95, IMPLEMENTED 0.75, VERIFIED 0.50). Treatment plans spawn CAPAs. The heatmap and what-if preview run client-side — no server round-trip.
What you actually get when you turn Risk Management on.
Heatmap on screen. Risk Pack on the desk.
Live heatmap with drillable cells. Risk Pack PDF with cover, methodology snapshot, top-N risks, treatment status, and the audit-trail chain. Designed to ship to a board, not to a regulator alone.
Not an integration. The same database.
SOPs become controls; publishing a new SOP version bumps effectiveness on every linked risk. Audit findings open as risk events in the inbox. Treatment plans spawn CAPAs typed as RISK; closing the CAPA recomputes residual. Methodology snapshots ensure no module update silently re-bands historical work.
What this satisfies.
"Shape" means we mirror the regulation's evidence, signature, and audit-trail requirements in our data model. Where we say "aligned," that's a customer affirmation; where we say "certified," we link the report. See Trust & Security for the current certification state.
RBAC, RLS, and a hash-chained audit trail.
Assessor cannot approve their own assessment under default separation of duties. Approval requires re-authentication and binds the signature to the methodology snapshot. Workspace-isolated by RLS.
Read the full security architecture →The methodology-versioning thing sold us alone. Our previous tool let people silently re-rate historical risks; ours lets the auditor see exactly what we knew at the time.
Forge better processes
One platform. Always audit-ready.
Bring SOPs, checklists, audits, incidents, and CAPAs into one connected system for safer, clearer, and more consistent operations.
No credit card required · Built for teams that run on process