Kardu

Your client is asking for security.Answer with evidence.

Turn compliance into a sales argument:From regulation to action, no in-house team needed.

What sector does your company operate in?
How many employees do you have?
What personal data do you process?
Have you been asked to comply with NIS2?
Do you have a documented security policy?
How many vendors access your systems?
Have you experienced a security incident?
What critical assets do you need to protect?
How long have you been managing compliance in spreadsheets?
Who owns compliance in your company?
Do your customers require ISO 27001?
When is your next audit?
Where do you store control evidence?
Do you have an up-to-date risk register?
Do you need ENS to contract with public sector?
How many regulatory frameworks apply to you?
What sector does your company operate in?
How many employees do you have?
What personal data do you process?
Have you been asked to comply with NIS2?
Do you have a documented security policy?
How many vendors access your systems?
Have you experienced a security incident?
What critical assets do you need to protect?
How long have you been managing compliance in spreadsheets?
Who owns compliance in your company?
Do your customers require ISO 27001?
When is your next audit?
Where do you store control evidence?
Do you have an up-to-date risk register?
Do you need ENS to contract with public sector?
How many regulatory frameworks apply to you?
app.kardu.eu/dashboard
57
ManagedPuntuación de Cumplimiento
Panel

PROGRAMA

Bird view
Marcos
Controles
Evidencias

OPERACIÓN

Infraestructura
Confianza
Comentarios
Ajustes

Buenas tardes, Kardu

Resumen de cumplimiento

+4 esta semana
KD
57

Gestionado

faltan 3 puntos

14 controles necesitan evidencia vinculada para subir tu puntuación.

58

Controles implementados

de 93 aplicables

20

En progreso

pendientes de completar

11

Archivos de evidencia

44 controles cubiertos

28

Tareas abiertas

6 vencidas

Tu foco

Lo que necesita atención hoy

Ver todas →

Revisión de permisos de acceso

A.8.1 · Vencida

Lista los datos que manejas y de quién son

A.5.1 · Vencida

Identifica los clientes que te exigen seguridad

A.15.1 · Vencida

Redactar política de continuidad de negocio

A.17.1 · En desarrollo

Configurar cifrado en reposo

A.10.1 · En desarrollo

Formación anual de concienciación

A.7.2 · Completada

Registro de activos de información

A.8.1 · Completada

Cobertura regulatoria

Controles mapeados a cada marco

ISO 2700162%
NIS258%
DORA45%
ENS51%
GDPR70%

Abrir el gestor de marcos →

Bird view

Tu programa, desde donde empezaste hasta donde termina.

1 de 25 pasos
Alcance1/5
semanas 1-2
Inventaria los sistemas y servicios que usas
Lista los datos que manejas y de quién son
Identifica los clientes que te exigen seguridad
Escribe el alcance de tu programa de seguridad
Determina tu rol legal frente a los clientes
Riesgos
semanas 3-40/5
Políticas
semanas 5-80/7
Trust Center
semana 90/4
Cuestionario
semanas 10-110/4
Cierre
semana 120/3
User

Compliance shouldn'tslow your business down.

Kardu automates risk management and regulatory compliance, turning a legal obligation into a competitive advantage with your clients and partners.

The backbone of your security

ISO 27001 as the core. All your programme's controls, evidence and risks in one system. No spreadsheets, no duplication.

Read more
ISO 27001INT
ISO/IEC 27001:2022 Information Security Management
74%
coverage
11/15
areas done
68/93 controls
Information security policies and governance
3/4
External engagement and threat intelligence
2/4
Asset and information management
6/6
Identity and access management
4/4
Supplier and cloud security
3/5
Incident management
4/5
Business continuity
2/2
Compliance and records management
5/7
People security
6/8

Evidence vault

Every control has its evidence attached. Automatic expiries, proactive reminders and full lifecycle traceability for any audit.

Read more
Evidence Vault
The proof that your security controls are actually in place.
Files
Policies
Questionnaires
6 files · 5 linked to controls
Search evidence...
PDF
ISO27001_Risk_Assessment_2024.pdfA.8.2Mar 122.4 MB
DOC
Access_Control_Policy_v3.docxA.9.1Mar 08340 KB
PDF
Firewall_Config_Audit.pdfA.13.1Feb 281.1 MB
IMG
Employee_Security_Training.pngA.7.2Feb 20890 KB
PDF
Incident_Response_Plan_v2.pdfA.16.1Feb 141.8 MB
PDF
Supplier_NDA_Acme_SL.pdfA.15.1Jan 30220 KB

Focus Mode

Your personal dashboard of pending tasks. Kardu prioritises what needs attention today so you never lose track of your Compliance Score.

Read more
Focus queue8 controls pending
Security policyISO27001Today
Security roles and responsibilitiesISO27001Today
Separation of dutiesISO27001Tomorrow
Management commitment to securityISO27001Tomorrow
Access control policy reviewNIS2Apr 30
Supplier risk assessmentISO27001May 2
Business continuity plan updateISO27001May 5
Incident response drill documentationNIS2May 8

All your frameworkscoordinated in one system.

Mandatory

NIS2

Mandatory European cybersecurity directive.

21 risk management measures

View official documentation →

Certifiable

ISO 27001

International information security standard.

93 controls across 4 themes

View official documentation →

Spain

ENS

National Security Scheme for public entities and private companies.

75 security measures

View official documentation →

Financial

DORA

Digital operational resilience for the financial sector.

ICT risk management

View official documentation →

Privacy

GDPR

European regulation on the protection of personal data.

99 articles, 6 legal bases

View official documentation →

How it works

From zero to compliance in 12 weeks, with you every step

Built for European SMEs and scale-ups that need ISO 27001 or NIS2 — without a dedicated compliance team.

1. Diagnosis and scope

We define the scope with you

A Kardu consultant reviews your organisation, your risks, and what your clients demand. In 1-2 weeks you have a prioritised work plan, not a generic checklist you fill in alone.

2. You're never on your own

We build the programme with you

Core policies, evidence, and risk matrix, with weekly support from start to finish. Not software you operate solo — a programme we build together.

3. Public trust, ready

Your Trust Center, live

Answer your client's first real questionnaire with evidence, and share your public Trust Center. Demonstrable compliance whenever anyone asks for it, not a PDF sitting in a drawer.

FAQ

Frequently asked questions.

Kardu is a compliance platform built for European companies that need to demonstrate security to clients and investors. It does not replace a certification audit, a security consultant, or legal advice — nor does it claim to. It is software that guides you step by step so that compliance becomes a visible commercial asset, not an administrative burden.

For European companies with 10 to 250 employees — fintech, healthtech, B2B SaaS, public administration suppliers — that have received a compliance requirement (NIS2, ISO 27001, DORA, ENS) from a client, investor or auditor and do not know where to start.

The initial onboarding takes less than 15 minutes. Kardu asks you 4 questions about your company and automatically generates a personalised compliance programme. In your first session you already have a real compliance score and know exactly what to prioritise.

All your data is stored exclusively on servers in the European Union (Frankfurt). Kardu has no servers outside the EU, without exception. We comply with the GDPR and have a signed DPA with every infrastructure provider.

No. Kardu is designed precisely for companies without an internal security team. The Goldfinch AI assistant explains each control in plain language, suggests what evidence to attach and alerts you when something needs attention. If you have any questions at any point, it is there to answer them.

Kardu Foundation is the only entry point today: a 4-week done-with-you onboarding program, not a self-serve signup. Book a conversation with the founding team and we'll figure out together if it's the right fit for your company.

Kardu reflects what your company actually implements and documents — not what you make up. The Trust Center shows your real score based on controls you have completed with attached evidence: a document, a policy, a log. If someone uploads false evidence, the problem is not Kardu — it is document fraud, with the same legal consequences as falsifying a contract. That said, Kardu does not replace an external auditor. For formal certifications (ISO 27001, ENS), an independent certification body always steps in to physically verify what you declare. The Trust Center is an honest progress signal, not an official stamp.See Kardu's Trust Center →

Kardu Foundation:guided setup, not a login.

This is not self-serve. Book a conversation with the founding team and we guide you step by step, from your first control to your first Compliance Score.

  • Initial diagnostic session with the founding team
  • Direct support over 4 weeks
  • Guided setup of your frameworks: ISO 27001, NIS2, DORA, ENS and GDPR
  • EU data residency · Frankfurt, Germany

Tell us where your company stands and we'll figure out together if Kardu Foundation is the right fit.

Talk to us

You'll speak directly with the founding team, not a bot.