Skip to main content
20% off — first 20 customers. See the offer →

The platform

Everything your management system needs, in one place

Sentinel42 is a complete management system, not a policy pack with a dashboard. The registers, the evidence, the people, the suppliers, the audits, the auditor and the board report all live in the same workspace, and everything you enter counts towards every framework you have switched on.

Unlimited

users at every tier

28

framework modules available

93

Annex A controls with owners and evidence

14 days

free trial, no card

In the core, at every tier

No module needed, no seat counting, no extra invoice. This is what Starter includes on day one.

ISO 27001 management system

The whole standard, not a checklist.

  • Clauses 4–10 with editable narratives and approval history
  • Statement of Applicability across all 93 Annex A controls with owners and justification
  • Risk register with treatment plans, scoring before and after treatment
  • Policy library with review dates, approvals and staff acknowledgements
  • Internal audits, findings, corrective actions and management review

UK / EU GDPR essentials

Included in every tier, not sold as an add-on.

  • Records of processing (ROPA) with lawful basis, retention and transfers
  • Data subject requests with statutory clocks and evidence
  • Data protection impact assessments
  • Personal data breach log with regulator notification deadlines
  • Sub-processor register and review reminders

Evidence vault

Every claim in your ISMS points at a file.

  • Versioned evidence with owners, freshness rules and expiry warnings
  • Linked to controls, clauses, risks, findings and suppliers
  • Hash-chained audit log of every change
  • One-click audit pack for an assessor

People and HR

Joiners, movers and leavers with the evidence an auditor asks for.

  • Personnel register with screening checks and documents
  • Lifecycle steps for candidate, joiner, mover and leaver
  • Training courses, completions and expiry tracking
  • Awareness quizzes and phishing results
  • Separate HR access role so personal data stays with the people who need it

Suppliers and third parties

Due diligence that does not live in your inbox.

  • Supplier register with criticality, risk scoring and review dates
  • Due-diligence requests and questionnaires
  • Supplier portal: your supplier answers and uploads certificates themselves
  • NDA register and information transfer records

Assets, physical and continuity

The registers Annex A actually asks for.

  • Information and physical asset registers with classification and disposal
  • Site checks, maintenance and calibration records
  • Business impact analysis, continuity plans and restore tests
  • Access reviews on a schedule

Reporting and assurance

What you show the board, the customer and the auditor.

  • Live readiness by framework, weakest first
  • Board scorecard and executive reports with RAG explanations
  • Auditor workspace with request tracking and an immutable access log
  • Automatic control checks that flag drift for a human to review
  • Trust Centre for prospects and customers
  • AI assistant grounded in your own ISMS and the user manual

Then add the frameworks you are asked for

28 framework modules are available now, from SOC 2 and ISO 42001 to PCI DSS, TISAX, HIPAA and the EU Cyber Resilience Act. Each one inherits the work you have already done in ISO 27001, so a second certification is a gap list, not a second project.

SOC 2 (Type I & II)ISO 27701 (privacy)ISO 42001 (AI management)EU AI ActISO 9001 (quality)DORANIS2NCSC CAF v3.2NIST CSF 2.0 / 800-53NIST 800-171 / CMMC 2.0Cyber EssentialsCyber Essentials PlusDefence Cyber CertificationPCI DSS v4.0.1TISAX / VDA ISA 6ISO 22301 (continuity)HIPAANHS DSPTUK Cyber Security and Resilience BillISO 27017 / 27018 (cloud)CSA STAR (CCM v4 / CAIQ)ISO 27036 (supplier security)EU Cyber Resilience ActFCA / PRA operational resilienceISO 37002 (whistleblowing)ISO 20000-1 (service management)PECR & cookie consent recordsModern Slavery & ESG

See every modulePricingInternational data protection