RiskPilot Website FR GitHub

Welcome to RiskPilot #

Available

RiskPilot is a governance, risk and compliance (GRC) platform connecting context, cyber scenarios, treatments, controls, evidence and information security management system (ISMS) governance.

French and English application #

The application interface is available in French and English. Each user selects a language under Settings → My profile and MFA. The saved preference applies to menus, screens, dialogs, tooltips, accessibility attributes, dates, times, numbers and localized searches. User-entered business content is not translated automatically.

Intended users #

  • Administrator: organization, users, email, integrations, action columns and audit.
  • Risk manager: inventory, risks, governance, treatment plans and indicators.
  • Action owner: assigned actions, progress, comments and evidence.
  • Auditor: assurance work according to permissions.
  • Reader: read access according to granted rights.

Essential workflow #

The main path is: scope → hardware, software or information asset → threat and vulnerability → risk → security control → action plan → evidence → indicator and report.

The organization is the multi-tenant boundary. A resource and all its relationships must belong to the same organization. The interface adapts actions to the role, while the Symfony API remains the security authority.

Functional state verified on 9 August 2026 #

  • a collapsible Assets menu with the complete register and specialized Hardware, Software and Information views;
  • enriched action plans with ticket, URL, origin, type, frameworks, requirements, non-conformities and custom fields;
  • action-column administration with technical-key generation and validation;
  • KPI/KRI definitions, time-series values, idempotency, batch import and CSV export;
  • persistent language preference and complete French/English interface coverage.
  • governed workspaces for operations, decisions, experiments and analyses;
  • versioned annual reports with an activity ledger and a 0-to-5 cyber-maturity radar.
  • RGPD, NIS2, ISO/IEC 27001:2022 and EBIOS Risk Manager starter packs;
  • compliance-assessment maturity radar and native PDF reports;
  • secure Mistral, OpenAI, Gemini or compatible AI-copilot settings.
  • five persisted, ordered and independently validated EBIOS RM workshops;
  • a dedicated NIS2 view and organization-configurable RBAC permission matrix;
  • enriched PDF reports and directly editable operational workflows.
  • explicit compliance-assessment lifecycle and automatic creation of active requirement results;
  • radar excluding unassessed and not-applicable requirements, plus accordion navigation.
  • global GRC copilot, contextual compliance assistance and confirmed guided drafts.

Getting started #

  1. Open Installation to start the Docker stack.
  2. Read Menus, submenus and screens.
  3. Configure the organization, users and your profile language.
  4. Build the inventory before risks, actions and indicators.
  5. Use the API reference for automation.