Organisations on the platform today— across Europe
Compliance
you can show,
not just file.
One platform for the whole EU regulatory remit — governed as a single control set, and operated day to day. The proof your partners can see.
One control set
- Access review
- Encryption at rest
- Incident response
- Supplier due diligence
- Records of processing
- Training completion
- Business continuity
- Speak-up channel
The same control set is mapped to GDPR, ISO 27001, NIS2, ISO 37301 and the Whistleblower Directive.
Proven across
Europe.
Compliance consultancy behind every module— from real practice
Less manual work on routine compliance— up to, internal benchmark*
From import to your first audit-ready evidence pack— template-led onboarding
* Figures are an internal benchmark based on customer measurement during Q1 2026. Detailed methodology available on request.
Compliance
as trust, made visible.
Compliance is the only function that gets cheaper the better you do it. Most institutions still treat it as cost. Your partners see it differently.
Your enterprise customers, procurement reviewers and supply-chain auditors don't want to hear that you take compliance seriously. They want to see it — and in the deals you're trying to close, that's the difference between “we're still reviewing” and “contract on Friday.”
Compliance isn't a cost centre. It's the most under-priced sales infrastructure in B2B.
A GRC platform
with an execution layer.
Write the control once. Answer every framework it touches.
These obligations overlap far more than they differ.
One control
Access review
Owner: Head of IT · Evidence: review log, approver list
Mapped to
The list of obligations keeps growing. The control set underneath it does not.
Mapped today
- GDPR
- Whistleblowing — Directive 2019/1937
- ISO 27001
- ISO 37301
- NIS2
In development
- EU AI Act
- ISO 42001
The work, with a clock on it.
The frame is not the work. A data-subject request arrives with thirty days on it; a whistleblower report has to be acknowledged inside seven.
Anonymous report
Identity shielded
- 14:02Received via anonymous portal
- 14:09Identity separated from the case record
- 14:40Triaged — financial conduct
- 14:41Investigator assigned
- Day 5Acknowledgement sent to the reporter
Data-subject requests
Audit pack
Assembled on demand, not on a project.
- Article 30 processing register
- Data-subject request history
- Security-incident log
- Training certificates
Generally available across GDPR, whistleblowing, frameworks, workforce training and the trust centre. AI governance joins the same spine in Q3 2026.
Representative platform surfaces.
The remit,
on one spine.
Each module stands on its own. Together they form a posture you can put in front of any auditor.
Built for institutions running a documented compliance programme — not for a one-off GDPR document pack.
One spine under everything the regulation asks for. The statutory clocks run themselves and the trail is written as you work, not reconstructed for an audit.
- DSAR, erasure & consent queues
- Public request portal for data subjects
- Processing records & Article 30 ROPA
- Security-incident workflow
- Statutory clocks & audit trails
Full implementation of the EU Whistleblower Directive, built so the source is protected from the first second rather than by policy afterwards.
- Anonymous, source-protected intake
- Encrypted case lifecycle & SLAs
- Investigator workbench with audit trail
- Dynamic form builder per case type
Your own policies become the course: the platform drafts it, your team refines and publishes, and your people get one place to do what is assigned to them.
- AI-drafted video scripts & slides
- Tests with configurable passing scores
- Policy acknowledgements, dated per person
- Certificates with expiry tracking
- Employee portal for assigned work
The page your customers read instead of sending you a questionnaire — updated from the records your team already keeps, never a screenshot of last quarter.
- Frameworks published with their current state
- Policies and sub-processor list
- Data residency and a named contact
- Updates from live records, not exports
The AI Act is the deadline; the competence underneath is broader AI governance, built so readiness falls out of running a real programme. A readiness engagement is available now, while the module lands.
- AI system inventory — in design
- Risk classification (Annex III & beyond) — planned
- FRIA & conformity workflow — planned
- Human-oversight & audit registers — planned
After AI governance, ESG and CSRD reporting join the platform as a first-class module, on the same workflow as everything else.
- CSRD / ESRS reporting
- Emissions inventory
- Social & governance disclosures
- Audit-ready data trails
“VPoint is the first European platform we've adopted that didn't feel like a translation of an American product. The AI Governance module, in particular, reads as though it were written here.
Compliance Director
Regional financial institution, Czechia — anonymised on request
VPoint, side by side with modern compliance tools.
Against today's compliance platforms — security-certification tools and EU privacy suites. Most cover one slice deeply. VPoint runs the remit end to end.
What it's built for
the core job
Cost
for a mid-market org
Whistleblowing
EU Directive 2019/1937
Workforce training
how content is built
Data residency
where records live
What happens
in your first 14 days.
Template-led setup, not a six-month rollout. Most institutions are running real compliance workflows in the platform within two weeks.
Day 1–2
Import what you have
Policies, registers and documentation lift in via templates and CSV.
Day 3–5
Configure modules and roles
Modules, RBAC, sub-processors, statutory clocks and notifications, set to your operating model.
Day 6–8
Train responsible users
DPO, HR and module owners trained by role. One 90-minute session each.
Day 9–12
Run live workflows
First intake, DSAR queue and training rollout go live. Clocks running.
Day 13–14
Produce first audit pack
Export the audit pack — ROPA, DSAR history, incidents, certificates — and publish your trust centre.
One annual figure. No surprises.
These figures cover the platform subscription. Implementation and support are quoted separately, in writing, before you commit.
Foundation
For institutions of 50–250
€89 per month, equivalent · per organisation, billed annually
- Whistleblowing module
- GDPR & data-protection core
- Unlimited cases
- EU data residency
- Email support
Institutional
For institutions of 250–2,500
from €249 per month · per organisation, billed annually, scaling with headcount
- Every live module
- AI Governance module on Q3 2026 release
- AI-drafted workforce training
- Dedicated implementation lead
- SLA 99.95% — 4-hour response
Sovereign
Ministries & regulated groups
price on application — bespoke
- Private deployment option
- Roadmap input access
- Custom AI Act registers
- Procurement-grade vendor pack
- Named compliance lead
Let's make your
compliance visible.
Thirty minutes with our European compliance team. No sales theatre, no obligation.
Get in touch
Tell us about your compliance posture and we'll come back within one business day.
- Address
- Na Roudné 443/18, 301 00 Plzeň, Czech Republic
- Phone
- +420 774 787 107
- info@vpointapp.com
- Company ID
- IČO 25232240