Scope and assets
Structure scopes, assets, threats, vulnerabilities and security controls.
RiskPilot connects risk assessments, controls, action plans, audits, third parties, resilience and ISMS documentation in a secure multi-tenant platform.
The RiskPilot software interface is currently available in French only. An English application interface is planned for upcoming versions. This English website documents the current product without implying that the application UI is already translated.
RiskPilot helps security and compliance teams replace scattered spreadsheets with governed, traceable records.
Structure scopes, assets, threats, vulnerabilities and security controls.
Assess inherent, current and residual risk on a configurable 5 × 5 matrix.
Track ownership, priorities, deadlines, costs, evidence, Kanban and calendar views.
Manage frameworks, assessments, maturity, evidence, control tests and versioned SoA.
Plan audit engagements, findings, root causes and independent effectiveness reviews.
Record criticality, contracts, dependencies, exit plans and supplier campaigns.
Handle incidents, BIA, RTO, RPO, BCP, DRP and continuity exercises.
Version, approve and share controlled documents through tenant-aware ACLs.
Assets feed risk scenarios; risks generate treatment actions; controls link to requirements; evidence supports compliance and audits; incidents connect to assets, third parties, risks and actions.
RiskPilot helps organisations structure compliance programmes. It is not presented as ISO 27001 certified.
Nginx routes the React/TypeScript SPA and Symfony/PHP-FPM API. PostgreSQL stores business data, Redis transports Messenger jobs, and documents remain in private storage.
Browser → Nginx
├─ React / TypeScript / Vite
└─ Symfony API / PHP-FPM
├─ PostgreSQL
├─ Redis / Messenger
└─ Private document storageDeploy with Docker Compose, inspect the source code and contribute through issues and pull requests.
Open English documentation