VPointEU

Compliance
you can show,
not just file.

One platform for every EU rule you have to follow, with one set of controls underneath, run day to day. The proof your partners can see.

One control set

  • Risk assessment
  • Policy acknowledgement
  • Awareness training
  • Incident response
  • Supplier due diligence
  • Records of processing
  • Data subject requests
  • Business continuity
  • Case investigation
  • Speak-up channel
  • Reporter confidentiality
  • Non-retaliation

The same control set is mapped to GDPR, ISO 27001, ISO 37301, NIS2 and the Whistleblowing Directive.

Proven across
Europe.

150+

Organisations on the platform todayacross Europe

8yrs

Compliance consultancy behind every modulefrom real practice

70%

Less manual work on routine complianceup to, internal benchmark*

14days

From import to your first audit-ready evidence packtemplate-led onboarding

* Figures are an internal benchmark based on customer measurement during Q1 2026. Detailed methodology available on request.

Compliance
as trust, made visible.

Compliance is the only function that gets cheaper the better you do it. Most institutions still treat it as cost. Your partners see it differently.

Your enterprise customers, procurement reviewers and supply-chain auditors don't want to hear that you take compliance seriously. They want to see it. In the deals you're trying to close, that's the difference between “we're still reviewing” and “contract on Friday.”

Compliance isn't a cost centre. It's the most under-priced sales infrastructure in B2B.

A GRC platform
that does the work.

Write the control once. Answer every framework it touches.

These obligations overlap far more than they differ.

One control

Awareness training

Owner: Compliance lead. Evidence: completion log, certificates

One control

Supplier due diligence

Owner: Procurement. Evidence: processor register, signed DPAs

One control

Risk assessment

Owner: Compliance lead. Evidence: risk register, DPIA records

One control

Incident response

Owner: DPO. Evidence: incident log, notification record

Mapped to

GDPRArt. 39(1)(b) Staff awareness and training
ISO 27001A.6.3 Awareness, education and training
ISO 373017.3 Awareness
NIS2Art. 21(2)(g) Cyber hygiene and training

The list of obligations keeps growing. The control set underneath it does not.

Mapped today

  • GDPR
  • Whistleblowing (Directive 2019/1937)
  • ISO 27001
  • ISO 37301
  • NIS2

In development

  • EU AI Act
  • ISO 42001

The work, with a clock on it.

Writing a control down is not the same as doing it. A data-subject request arrives with thirty days on it, a whistleblower report has to be acknowledged inside seven, and the yearly register review and training round carry dates of their own.

WhistleblowingCase #2026-04-118

Anonymous report

Identity shielded

  1. 14:02Received via anonymous portal
  2. 14:09Identity separated from the case record
  3. 14:40Triaged as financial conduct
  4. 14:41Investigator assigned
  5. Day 5Acknowledgement sent to the reporter

Directive 2019/1937, acknowledged day 5 of 7

Deadlines

Open work

RefItem
DSR-0412Access request (Art. 15)
DPO review
0/30
DPIA-07Impact assessment (Art. 35)
Drafting
0/21
ROPA-24Processing register review
In review
0/365
TRN-03Annual training round
Completed
0/60

Statutory deadlines and internal review dates, on one queue

Evidence

Audit pack

Assembled on demand, not on a project.

  • Article 30 processing register
  • Data-subject request history
  • Security-incident log
  • Training certificates

EU-only residency, exported whenever it is asked for

Generally available across GDPR, whistleblowing, frameworks, workforce training and the trust centre. AI governance joins the same platform in Q3 2026.

Representative platform surfaces.

Every obligation,
in one place.

Each module works on its own. Together they are one compliance programme, and one thing to put in front of an auditor.

Built for institutions running a documented compliance programme, not for a one-off GDPR document pack.

  • One system for everything the regulation asks for. The statutory clocks run themselves, and the record is written as you work rather than reconstructed for an audit.

    • DSAR, erasure & consent queues
    • Public request portal for data subjects
    • Processing records & Article 30 ROPA
    • Security-incident workflow
    • Statutory clocks & audit trails
  • Full implementation of the EU Whistleblower Directive, built so the source is protected from the first second rather than by policy afterwards.

    • Anonymous, source-protected intake
    • Encrypted case file, with response deadlines
    • Investigator workbench with audit trail
    • Dynamic form builder per case type
  • Your own policies become the course: the platform drafts it, your team refines and publishes, and your people get one place to do what is assigned to them.

    • AI-drafted video scripts & slides
    • Tests with configurable passing scores
    • Policy acknowledgements, dated per person
    • Certificates with expiry tracking
    • Employee portal for assigned work
  • The page your customers read instead of sending you a questionnaire. Updated from the records your team already keeps, never a screenshot of last quarter.

    • Frameworks published with their current state
    • Policies and sub-processor list
    • Data residency and a named contact
    • Updates from live records, not exports
  • The AI Act is the deadline, but the job underneath it is broader: governing how AI gets used at all, built so that being ready falls out of running the programme properly. A readiness review is available now, while the module is being built.

    • AI system inventory (in design)
    • Risk classification, Annex III and beyond (planned)
    • FRIA and conformity workflow (planned)
    • Human-oversight and audit registers (planned)

VPoint is the first European platform we've adopted that didn't feel like a translation of an American product. The AI Governance module, in particular, reads as though it were written here.

Compliance Director

Regional financial institution, Czechia (anonymised on request)

VPoint, side by side with modern compliance tools.

Against today's compliance platforms: security-certification tools and EU privacy suites. Most do one part of the job well. VPoint runs all of it, day to day.

What it's built for

the core job

Modern compliance toolsSecurity certs (SOC 2 / ISO 27001), or GDPR advisory + DPO
VPointRunning every EU obligation, day to day

Cost

for a mid-market org

Modern compliance toolsEnterprise quotes (US) or per-seat add-ons
VPointMid-market, per-organisation tiers

Whistleblowing

EU Directive 2019/1937

Modern compliance toolsRarely a first-class module
VPointDedicated module: dynamic forms, anonymous intake, investigator workbench

Workforce training

how content is built

Modern compliance toolsGeneric course catalogue
VPointAI-drafted from your own policies

Data residency

where records live

Modern compliance toolsUS-built tools often US-hosted
VPointEU-only

What happens
in your first 14 days.

Template-led setup, not a six-month rollout. Most institutions are running real compliance workflows in the platform within two weeks.

  1. Day 1–2

    Import what you have

    Policies, registers and documentation lift in via templates and CSV.

  2. Day 3–5

    Configure modules and roles

    Modules, RBAC, sub-processors, statutory clocks and notifications, set to your operating model.

  3. Day 6–8

    Train responsible users

    DPO, HR and module owners trained by role. One 90-minute session each.

  4. Day 9–12

    Run live workflows

    First intake, DSAR queue and training rollout go live. Clocks running.

  5. Day 13–14

    Produce first audit pack

    Export the audit pack (ROPA, DSAR history, incidents, certificates) and publish your trust centre.

One annual figure. No surprises.

These figures cover the platform subscription. Implementation and support are quoted separately, in writing, before you commit.

Foundation

For institutions of 50–250

The work itself: cases, requests and the clocks on them.

€1,080/year

Equivalent to €90 per month. Per organisation, billed annually.

  • Whistleblowing: anonymous intake and case work
  • GDPR: request queues, records and incidents
  • Statutory clocks and audit trails
  • Unlimited cases
  • EU data residency
  • Email support
Talk to us
Framework management included

Institutional

For institutions of 250–2,500

One control set across every framework, and all of the work under it.

from€3,000/year

From €250 per month. Per organisation, billed annually, scaling with headcount.

  • Everything in Foundation
  • One control set, mapped across every framework
  • ISO 27001, ISO 37301 and NIS2 management
  • Trust centre, published from live records
  • AI-drafted workforce training
  • AI Governance on the Q3 2026 release
  • Dedicated implementation lead
Talk to us

Sovereign

Ministries & regulated groups

Everything in Institutional, deployed and supported on your terms.

POAannual

Price on application, quoted to scope.

  • Everything in Institutional
  • Private deployment option
  • Roadmap input access
  • Custom AI Act registers
  • Procurement-grade vendor pack
  • Named compliance lead
Talk to us

Let's make your
compliance visible.

Thirty minutes with our European compliance team. No sales theatre, no obligation.

Request a demonstration

Get in touch

Tell us where you are with compliance and we'll come back within one business day.

Address
Na Roudné 443/18, 301 00 Plzeň, Czech Republic
Company ID
IČO 25232240

* Required

By submitting, you agree we may contact you about your enquiry. See our privacy policy.