Welcome to RiskPilot #
AvailableRiskPilot is a governance, risk and compliance (GRC) platform connecting context, cyber scenarios, treatments, controls, evidence and information security management system (ISMS) governance.
French and English application #
The application interface is available in French and English. Each user selects a language under Settings → My profile and MFA. The saved preference applies to menus, screens, dialogs, tooltips, accessibility attributes, dates, times, numbers and localized searches. User-entered business content is not translated automatically.
Intended users #
- Administrator: organization, users, email, integrations, action columns and audit.
- Risk manager: inventory, risks, governance, treatment plans and indicators.
- Action owner: assigned actions, progress, comments and evidence.
- Auditor: assurance work according to permissions.
- Reader: read access according to granted rights.
Essential workflow #
The main path is: scope → hardware, software or information asset → threat and vulnerability → risk → security control → action plan → evidence → indicator and report.
The organization is the multi-tenant boundary. A resource and all its relationships must belong to the same organization. The interface adapts actions to the role, while the Symfony API remains the security authority.
Functional state verified on 9 August 2026 #
- a collapsible Assets menu with the complete register and specialized Hardware, Software and Information views;
- enriched action plans with ticket, URL, origin, type, frameworks, requirements, non-conformities and custom fields;
- action-column administration with technical-key generation and validation;
- KPI/KRI definitions, time-series values, idempotency, batch import and CSV export;
- persistent language preference and complete French/English interface coverage.
- governed workspaces for operations, decisions, experiments and analyses;
- versioned annual reports with an activity ledger and a 0-to-5 cyber-maturity radar.
- RGPD, NIS2, ISO/IEC 27001:2022 and EBIOS Risk Manager starter packs;
- compliance-assessment maturity radar and native PDF reports;
- secure Mistral, OpenAI, Gemini or compatible AI-copilot settings.
- five persisted, ordered and independently validated EBIOS RM workshops;
- a dedicated NIS2 view and organization-configurable RBAC permission matrix;
- enriched PDF reports and directly editable operational workflows.
- explicit compliance-assessment lifecycle and automatic creation of active requirement results;
- radar excluding unassessed and not-applicable requirements, plus accordion navigation.
- global GRC copilot, contextual compliance assistance and confirmed guided drafts.
Getting started #
- Open Installation to start the Docker stack.
- Read Menus, submenus and screens.
- Configure the organization, users and your profile language.
- Build the inventory before risks, actions and indicators.
- Use the API reference for automation.