The platform

One Record for the Whole Programme

Not a SOC 2 tool next to an ISO tool next to a GDPR tool. One organisational truth, with every framework mapped into it and every control tested continuously.

Compliance Management

Implement and maintain SOC 2, ISO 27001, Cyber Essentials, UK GDPR, HIPAA, PCI DSS, DORA and your own frameworks.

Explore Compliance Management
  • FrameworksEvery framework mapped into one record, with a Statement of Applicability where it applies.
  • ControlsOne canonical set of controls, each tested continuously and rated by dimension.
  • EvidenceImmutable and hashed, stamped with how it was produced.
  • AutomationsScheduled tests that keep evidence fresh and raise findings when something drifts.
  • Framework builderYour own obligations, from contracts or internal standards, versioned.

Risk & Vendor Management

Identify, assess and monitor risks and third parties continuously.

Explore Risk & Vendor Management
  • FindingsClosed only when a later test proves the fix held.
  • ExceptionsTime-boxed and approved, with a reminder before they lapse.
  • Risk registerOwners, treatment and the controls that reduce each risk.
  • VendorsDue diligence with certificates on file and reviews on a schedule.
  • IncidentsFrom detection to lessons learned, on the record.

Privacy & Data Protection

Processing records, DPIAs, data-subject requests and data governance, made simple.

Explore Privacy & Data Protection
  • Processing recordsWhat you process, why, and on what lawful basis.
  • DPIAsData protection impact assessments, linked to the systems they cover.
  • Data-subject requestsTracked against their statutory deadlines.
  • AssetsWhat you run and who owns it.
  • Access reviewsDecisions that become evidence.

AI Governance

Govern AI systems and agents with confidence. ISO 42001 and the NIST AI RMF, with risk classes informed by the EU AI Act.

Explore AI Governance
  • AI registryAI systems and agents, their purpose, owner and what they may do.
  • Risk classesInformed by the EU AI Act categories; prohibited uses cannot be approved.
  • Human oversightSensitive actions wait for a person to approve them.
  • ISO 42001The AI management system standard, mapped like any other framework.
  • DoveAn operator that acts with your permissions, only once you confirm.

Governance & Trust

Policies, audits and a Trust Center, backed by a ledger anyone can verify.

Explore Governance & Trust
  • PoliciesVersioned, with staff acknowledgements.
  • AuditsScoped auditor workspaces and a verifiable export.
  • Trust CenterWhat you can prove, published for customers.
  • QuestionnairesAnswered from your live records.
  • Assurance ledgerEvery material change, hash-chained.

How it works

From Connected to Proven in Four Steps

  1. 1

    Connect

    Link your cloud, identity, code, ticketing and HR systems with read-only access, and invite your people with the roles they need.

  2. 2

    Map

    Pick your frameworks. One set of controls maps to all of them, so nothing is done twice.

  3. 3

    Test continuously

    Scheduled tests check that controls operate. Drift becomes a finding the moment it happens.

  4. 4

    Prove

    Share evidence with its provenance with auditors, customers and your board, from a Trust Center or an export.

Integrations

Evidence From the Systems You Run

AWS

Root and console MFA, S3 public access and CloudTrail logging, with the SecurityAudit policy.

GitHub

Two-factor enforcement, branch review rules and ageing Dependabot alerts, read-only.

Okta

MFA on every active user and dormant accounts, with a read-only token.

Google Workspace

2-Step Verification for every user and administrator, and dormant accounts, through read-only domain-wide delegation.

Microsoft 365 / Entra ID

MFA registration, whether Security Defaults or Conditional Access actually require MFA, administrators and dormant accounts.

Microsoft Azure

Storage public access and TLS, Activity Log export and Defender for Cloud, with the Reader roles.

Google Cloud

Bucket public access prevention, uniform access and project IAM, with read-only roles.

Jira

Security issues past their remediation window, and whether production changes are ticketed.

BambooHR

Leavers with their termination dates, and employees without a manager, for joiner and leaver controls.

REST API & webhooks

A read-only REST API for your own reporting, and signed webhooks that tell your systems when something changes.

Dove, Your Compliance Operator

Dove answers from your live controls, evidence and findings, then proposes the next step: re-run a test, request an exception or draft a questionnaire. You confirm each one. It acts with your permissions and goes on the ledger.

How Dove is governed

Ready to prove it?

Know what you are responsible for, control whether it works, and prove it to anyone who asks.

Use your Invitation