VPointEU

Compliance
you can show,
not just file.

One platform for the whole EU regulatory remit — governed as a single control set, and operated day to day. The proof your partners can see.

One control set

  • Access review
  • Encryption at rest
  • Incident response
  • Supplier due diligence
  • Records of processing
  • Training completion
  • Business continuity
  • Speak-up channel

The same control set is mapped to GDPR, ISO 27001, NIS2, ISO 37301 and the Whistleblower Directive.

Proven across
Europe.

150+

Organisations on the platform today— across Europe

8yrs

Compliance consultancy behind every module— from real practice

70%

Less manual work on routine compliance— up to, internal benchmark*

14days

From import to your first audit-ready evidence pack— template-led onboarding

* Figures are an internal benchmark based on customer measurement during Q1 2026. Detailed methodology available on request.

Compliance
as trust, made visible.

Compliance is the only function that gets cheaper the better you do it. Most institutions still treat it as cost. Your partners see it differently.

Your enterprise customers, procurement reviewers and supply-chain auditors don't want to hear that you take compliance seriously. They want to see it — and in the deals you're trying to close, that's the difference between “we're still reviewing” and “contract on Friday.”

Compliance isn't a cost centre. It's the most under-priced sales infrastructure in B2B.

A GRC platform
with an execution layer.

Write the control once. Answer every framework it touches.

These obligations overlap far more than they differ.

One control

Access review

Owner: Head of IT · Evidence: review log, approver list

Mapped to

ISO 27001A.5.18 Access rights
ISO 373018.1 Operational planning and control
NIS2Art. 21(2)(i) Access control policies

The list of obligations keeps growing. The control set underneath it does not.

Mapped today

  • GDPR
  • Whistleblowing — Directive 2019/1937
  • ISO 27001
  • ISO 37301
  • NIS2

In development

  • EU AI Act
  • ISO 42001

The work, with a clock on it.

The frame is not the work. A data-subject request arrives with thirty days on it; a whistleblower report has to be acknowledged inside seven.

WhistleblowingCase #2026-04-118

Anonymous report

Identity shielded

  1. 14:02Received via anonymous portal
  2. 14:09Identity separated from the case record
  3. 14:40Triaged — financial conduct
  4. 14:41Investigator assigned
  5. Day 5Acknowledgement sent to the reporter

Directive 2019/1937 · acknowledged day 5 of 7

GDPR

Data-subject requests

RefRequest
DSR-0412Access — Art. 15
DPO review
0/30
DSR-0411Erasure — Art. 17
Collecting
0/30
DSR-0409Portability — Art. 20
Closed
0/30

Response packet assembled · reviewed by the DPO before delivery

Evidence

Audit pack

Assembled on demand, not on a project.

  • Article 30 processing register
  • Data-subject request history
  • Security-incident log
  • Training certificates

EU-only residency · exported whenever it is asked for

Generally available across GDPR, whistleblowing, frameworks, workforce training and the trust centre. AI governance joins the same spine in Q3 2026.

Representative platform surfaces.

The remit,
on one spine.

Each module stands on its own. Together they form a posture you can put in front of any auditor.

Built for institutions running a documented compliance programme — not for a one-off GDPR document pack.

  • One spine under everything the regulation asks for. The statutory clocks run themselves and the trail is written as you work, not reconstructed for an audit.

    • DSAR, erasure & consent queues
    • Public request portal for data subjects
    • Processing records & Article 30 ROPA
    • Security-incident workflow
    • Statutory clocks & audit trails
  • Full implementation of the EU Whistleblower Directive, built so the source is protected from the first second rather than by policy afterwards.

    • Anonymous, source-protected intake
    • Encrypted case lifecycle & SLAs
    • Investigator workbench with audit trail
    • Dynamic form builder per case type
  • Your own policies become the course: the platform drafts it, your team refines and publishes, and your people get one place to do what is assigned to them.

    • AI-drafted video scripts & slides
    • Tests with configurable passing scores
    • Policy acknowledgements, dated per person
    • Certificates with expiry tracking
    • Employee portal for assigned work
  • The page your customers read instead of sending you a questionnaire — updated from the records your team already keeps, never a screenshot of last quarter.

    • Frameworks published with their current state
    • Policies and sub-processor list
    • Data residency and a named contact
    • Updates from live records, not exports
  • The AI Act is the deadline; the competence underneath is broader AI governance, built so readiness falls out of running a real programme. A readiness engagement is available now, while the module lands.

    • AI system inventory — in design
    • Risk classification (Annex III & beyond) — planned
    • FRIA & conformity workflow — planned
    • Human-oversight & audit registers — planned
  • After AI governance, ESG and CSRD reporting join the platform as a first-class module, on the same workflow as everything else.

    • CSRD / ESRS reporting
    • Emissions inventory
    • Social & governance disclosures
    • Audit-ready data trails

VPoint is the first European platform we've adopted that didn't feel like a translation of an American product. The AI Governance module, in particular, reads as though it were written here.

Compliance Director

Regional financial institution, Czechia — anonymised on request

VPoint, side by side with modern compliance tools.

Against today's compliance platforms — security-certification tools and EU privacy suites. Most cover one slice deeply. VPoint runs the remit end to end.

What it's built for

the core job

Modern compliance toolsSecurity certs (SOC 2 / ISO 27001), or GDPR advisory + DPO
VPointOperating the EU regulatory remit, day to day

Cost

for a mid-market org

Modern compliance toolsEnterprise quotes (US) or per-seat add-ons
VPointMid-market, per-organisation tiers

Whistleblowing

EU Directive 2019/1937

Modern compliance toolsRarely a first-class module
VPointDedicated module: dynamic forms, anonymous intake, investigator workbench

Workforce training

how content is built

Modern compliance toolsGeneric course catalogue
VPointAI-drafted from your own policies

Data residency

where records live

Modern compliance toolsUS-built tools often US-hosted
VPointEU-only

What happens
in your first 14 days.

Template-led setup, not a six-month rollout. Most institutions are running real compliance workflows in the platform within two weeks.

  1. Day 1–2

    Import what you have

    Policies, registers and documentation lift in via templates and CSV.

  2. Day 3–5

    Configure modules and roles

    Modules, RBAC, sub-processors, statutory clocks and notifications, set to your operating model.

  3. Day 6–8

    Train responsible users

    DPO, HR and module owners trained by role. One 90-minute session each.

  4. Day 9–12

    Run live workflows

    First intake, DSAR queue and training rollout go live. Clocks running.

  5. Day 13–14

    Produce first audit pack

    Export the audit pack — ROPA, DSAR history, incidents, certificates — and publish your trust centre.

One annual figure. No surprises.

These figures cover the platform subscription. Implementation and support are quoted separately, in writing, before you commit.

Foundation

For institutions of 50–250

€1,068/year

€89 per month, equivalent · per organisation, billed annually

  • Whistleblowing module
  • GDPR & data-protection core
  • Unlimited cases
  • EU data residency
  • Email support
Talk to us
Includes AI Governance

Institutional

For institutions of 250–2,500

from€2,988/year

from €249 per month · per organisation, billed annually, scaling with headcount

  • Every live module
  • AI Governance module on Q3 2026 release
  • AI-drafted workforce training
  • Dedicated implementation lead
  • SLA 99.95% — 4-hour response
Talk to us

Sovereign

Ministries & regulated groups

POAannual

price on application — bespoke

  • Private deployment option
  • Roadmap input access
  • Custom AI Act registers
  • Procurement-grade vendor pack
  • Named compliance lead
Talk to us

Let's make your
compliance visible.

Thirty minutes with our European compliance team. No sales theatre, no obligation.

Request a demonstration

Get in touch

Tell us about your compliance posture and we'll come back within one business day.

Address
Na Roudné 443/18, 301 00 Plzeň, Czech Republic
Company ID
IČO 25232240

* Required

By submitting, you agree we may contact you about your enquiry. See our privacy policy.