The questions that come up most often — about the service, the frameworks, onboarding, security and pricing.
The agent, and what humans sign
Compliance automation gives your team a smarter to-do list: it watches your stack and tells you what to do. An agent does the work itself. ZeroRisk’s agent learns your business, works out which requirements of each framework actually apply, pre-fills your assessments with a confidence score per answer, and drafts the controls and policies you’re missing. Your team’s job changes from doing the homework to reviewing and signing it.
Evidence lives in one library. Attach a document or link it once, and it counts toward every framework that requirement appears in — a penetration test report satisfies SOC 2 and ISO 27001 and NIS2 in one upload. The platform tracks freshness: when evidence ages past its review window, the verdict it supports ages with it, visibly. Nothing in your audit file silently goes stale.
Every verdict — a requirement marked satisfied, a vendor cleared, an access review closed — carries the name and timestamp of the person who reviewed it. The agent prepares; a person you designate decides. That distinction is what auditors care about: your audit file contains accountable, evidence-backed human conclusions, never raw AI output.
Yes — everything. Drafted policies and controls open in an editor; change what doesn’t fit and adopt in one click. Pre-filled answers show their confidence score and can be corrected in a short interview. The agent’s drafts are inputs to your decisions, not decisions.
Frameworks
Six: GDPR, ISO 27001, SOC 2, NIS2, DORA and the EU Cyber Resilience Act (CRA). You choose which the agent runs for you per plan — one on Starter, three on Growth, five on Business, all six on Enterprise. New frameworks are added as regulation evolves, and your existing controls carry into them automatically.
Both sides of it. For your own readiness: records of processing, lawful-basis mapping, and the policies the regulation expects, drafted for you. For your vendors: every processor is checked for Article 28 essentials — is there a DPA, is the sub-processor list evidenced, where does data go — and re-checked every 24 hours. A missing sub-processor list becomes a finding, not a footnote.
DORA’s core demand is proof that you manage ICT third-party risk continuously. ZeroRisk builds the register of ICT providers from your vendor list, maps the contractual provisions DORA expects, and keeps the evidence current with daily monitoring. When your regulator asks for the register, you export it — you don’t assemble it.
Yes. The applicability report tells you first whether you fall in scope as an essential or important entity — many companies don’t know. From there the agent maps the security measures NIS2 requires, including the supply-chain security obligations that make vendor monitoring mandatory rather than optional, and the management-accountability evidence boards now ask for.
Yes, on the Enterprise plan. If you make products with digital elements, the agent maps the CRA’s essential requirements — secure development, vulnerability handling, update obligations — against your practices and drafts what’s missing. CRA obligations phase in through 2027; starting now is what makes the deadline ordinary instead of frightening.
Yes, and this is most of the economics. Do a control once — an access policy, an incident procedure, an encryption standard — and it counts toward every framework that asks for it. Your second framework typically starts more than half pre-filled from your first.
Audits and proof
You export the audit package: scoped requirements, the controls behind them, the evidence behind those, and the named signature on every verdict — current as of that morning. ZeroRisk is auditor-agnostic; the package is built to be accepted by whoever you engage, and audit-window panic stops being part of the calendar.
Auditors accept evidence a person stands behind. In ZeroRisk the AI prepares and a person signs — every conclusion in the file is attributed, timestamped and backed by linked evidence. What auditors reject is unaccountable output; the signature layer exists precisely so there is none.
The signed, exportable record of a completed review: for vendors, the assessment status of your portfolio against your frameworks; for access reviews, the frozen snapshot of who had access and what the owner decided. Each certificate is the evidence artifact an auditor checks — attributable, dated and reproducible.
Data, security and residency
In the EU by default — the platform and CRM run in EU data centers. Where a provider operates globally, transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses. Sovereign and on-premise deployment is available on Enterprise. The details live in our privacy policy.
Data is encrypted in transit and at rest, access is role-based and least-privilege, and that access is itself reviewed — we run the same access-review discipline the product sells. Security questions we haven’t answered here: ask, and you’ll get the documentation.
No. Your uploaded content — policies, evidence, vendor and people data — is processed to provide the service, not to train models. That’s a contractual commitment in our terms, not a settings toggle.
Getting started
The free gap report takes about ten minutes and needs no payment details. From there, onboarding is answering the agent’s profile questions and connecting your vendor list — library vendors activate immediately, uploads are monitored within 24 hours. Most teams see their first pre-filled assessment the same day.
Bring the spreadsheets. Vendor lists import as CSV, your staff directory comes from an HR export, and existing policies and evidence upload into the library where the agent maps them to requirements. Migration is mostly the agent reading what you already have — the gap report then shows what it couldn’t find.
Yes, and you can run both during the transition. Export your policies and evidence from the current tool, upload them, and the agent maps them across your frameworks. See the honest comparisons — ZeroRisk vs Vanta, vs Drata, vs Secureframe — for where switching is worth it and where it isn’t.
Pricing
Plans are priced by the frameworks the agent runs for you and the vendors you monitor — never by team size. Starter is $149/month (billed annually) for one framework and 10 vendors; Growth and Business scale to three and five frameworks; Enterprise covers all six with unlimited vendors. Every plan starts with the free gap report.
No. Employees confirm their equipment, declare shadow IT and acknowledge your policies from a personal email link — no account, no license. Seats exist only for the people who run the program. Attestation coverage rolls up for the auditor regardless of team size.