The platform
Everything your management system needs, in one place
Sentinel42 is a complete management system, not a policy pack with a dashboard. The registers, the evidence, the people, the suppliers, the audits, the auditor and the board report all live in the same workspace, and everything you enter counts towards every framework you have switched on.
Unlimited
users at every tier
28
framework modules available
93
Annex A controls with owners and evidence
14 days
free trial, no card
In the core, at every tier
No module needed, no seat counting, no extra invoice. This is what Starter includes on day one.
ISO 27001 management system
The whole standard, not a checklist.
- Clauses 4–10 with editable narratives and approval history
- Statement of Applicability across all 93 Annex A controls with owners and justification
- Risk register with treatment plans, scoring before and after treatment
- Policy library with review dates, approvals and staff acknowledgements
- Internal audits, findings, corrective actions and management review
UK / EU GDPR essentials
Included in every tier, not sold as an add-on.
- Records of processing (ROPA) with lawful basis, retention and transfers
- Data subject requests with statutory clocks and evidence
- Data protection impact assessments
- Personal data breach log with regulator notification deadlines
- Sub-processor register and review reminders
Evidence vault
Every claim in your ISMS points at a file.
- Versioned evidence with owners, freshness rules and expiry warnings
- Linked to controls, clauses, risks, findings and suppliers
- Hash-chained audit log of every change
- One-click audit pack for an assessor
People and HR
Joiners, movers and leavers with the evidence an auditor asks for.
- Personnel register with screening checks and documents
- Lifecycle steps for candidate, joiner, mover and leaver
- Training courses, completions and expiry tracking
- Awareness quizzes and phishing results
- Separate HR access role so personal data stays with the people who need it
Suppliers and third parties
Due diligence that does not live in your inbox.
- Supplier register with criticality, risk scoring and review dates
- Due-diligence requests and questionnaires
- Supplier portal: your supplier answers and uploads certificates themselves
- NDA register and information transfer records
Assets, physical and continuity
The registers Annex A actually asks for.
- Information and physical asset registers with classification and disposal
- Site checks, maintenance and calibration records
- Business impact analysis, continuity plans and restore tests
- Access reviews on a schedule
Reporting and assurance
What you show the board, the customer and the auditor.
- Live readiness by framework, weakest first
- Board scorecard and executive reports with RAG explanations
- Auditor workspace with request tracking and an immutable access log
- Automatic control checks that flag drift for a human to review
- Trust Centre for prospects and customers
- AI assistant grounded in your own ISMS and the user manual
Then add the frameworks you are asked for
28 framework modules are available now, from SOC 2 and ISO 42001 to PCI DSS, TISAX, HIPAA and the EU Cyber Resilience Act. Each one inherits the work you have already done in ISO 27001, so a second certification is a gap list, not a second project.