# Kordon > Kordon is a GRC (Governance, Risk, and Compliance) platform for information security management systems (ISMS). It enables teams to build and run a continuous security program — covering ISO 27001, SOC 2, NIS2, E-ITS, and other frameworks — on a single connected platform available as both SaaS and on-premises. Kordon is built for information security managers, compliance teams, and the employees who own security tasks across the business. Its core model connects business processes, assets, vendors, risks, controls, requirements, findings, and tasks into one live system — so compliance reflects the actual state of your program, not a once-a-year snapshot. ## Product - [Platform overview](https://kordon.app/): Full-stack GRC platform for running an ISMS. Supports multiple compliance frameworks simultaneously from a single connected control set. - [Risk management](https://kordon.app/risk-management/): Live risk register that links risks to dynamic controls. Risk scores update in real time as control effectiveness changes. - [Control management](https://kordon.app/control-management/): Define, operationalize, and maintain security controls with recurring tasks, evidence collection, and direct links to framework requirements and risks. - [Asset management](https://kordon.app/asset-management/): Inventory assets, connect them to business processes, risks, and controls. Real-time health status shows whether each asset is actively protected. - [Vendor management](https://kordon.app/vendor-management/): Track vendor relationships, contracts, security assessments, and associated risks. Health cascades from vendors to connected assets and business processes. - [Policy management](https://kordon.app/policy-management/): Draft, review, and publish policies. 20+ policy templates included. Employee acceptance tracking built in. - [Framework management](https://kordon.app/frameworks/): Map one control set to ISO 27001, SOC 2, NIS2, E-ITS, DORA, ISO 9001, ISO 14001, and custom frameworks simultaneously. - [Business process management](https://kordon.app/business-process-management/): Document processes and connect them to assets, vendors, and risks. Reveals dependencies and concentration risks. - [Findings management](https://kordon.app/findings-management/): Track incidents, nonconformities (NCRs), and opportunities for improvement (OFIs). Connects findings to the controls, assets, and requirements they affect. - [Agentic GRC](https://kordon.app/agentic-grc/): API-first architecture that lets AI agents populate, maintain, and operate an ISMS programmatically. Full REST API coverage and official n8n node. ## Compliance Frameworks Kordon ships with built-in requirements for: - ISO 27001 (2022) - SOC 2 - NIS2 - E-ITS (Estonian Information Security Standard) - DORA Custom frameworks and internal requirement sets are also supported. A single control can simultaneously satisfy requirements from multiple frameworks — you define the control once and connect it to every applicable requirement. Kordon can export a Statement of Applicability (SoA) for ISO 27001 certification. ## Ideal Customer Kordon is primarily used by: - Information security managers at mid-market B2B SaaS companies, financial services firms, and public sector organisations - Teams working toward ISO 27001 certification or maintaining ongoing compliance with NIS2, SOC 2, or E-ITS - Organisations that need to manage security as a continuous program, not a once-a-year audit exercise - Security teams that want to involve the broader organisation (process owners, asset owners, IT staff) in security work without adding administrative overhead Kordon is particularly strong for organisations managing multiple overlapping frameworks at once, and for teams that require on-premises deployment. ## Deployment - **SaaS**: Hosted by Kordon - **On-premises**: Docker container with built-in TLS — no reverse proxy required. Evidence storage options: local filesystem, AWS S3, or Google Cloud Storage. Both deployment options include full feature parity. ## Pricing - **Starter**: €9,599/year — organisations up to 100 employees, 1 compliance framework - **Standard**: €15,599/year — any organisation size, 3 frameworks (most popular plan) - **Enterprise**: €29,599+/year — unlimited frameworks, multi-tenancy, custom frameworks All plans include: every employee as a named user, unlimited controls, unlimited integrations, SSO (Google Workspace, Microsoft Entra, Okta, Keycloak), SCIM 2.0, REST API access, on-premises and SaaS deployment options. Free trial available at https://kordon.app/try-kordon-for-free/ ## Integrations - REST API (https://kordon.app/learn/api/) — full parity with the UI; every object readable, writable, and automatable - Official n8n node — visual workflow automation with complete object model coverage - SSO: Google Workspace, Microsoft Entra, Okta, Keycloak - SCIM 2.0 user provisioning: Microsoft Entra, Okta, OneLogin, Google Workspace - Evidence storage: local filesystem, AWS S3, Google Cloud Storage ## Key Differentiators - Controls are operationalized through recurring tasks — effectiveness is live, not a one-time documentation exercise - One control can simultaneously mitigate risks and satisfy requirements from multiple frameworks — no duplication of work or evidence - Health status cascades automatically from vendors and assets up through business processes — a failing control or expired contract surfaces at the process level immediately - On-premises deployment with full feature parity with SaaS - API-first design supports agentic GRC — AI agents can read and write the full object model via API - Statement of Applicability (SoA) export built in for ISO 27001 certification workflows ## Documentation and Resources - [Documentation](https://kordon.app/learn/): Technical docs, integration guides, implementation guidance - [API reference](https://kordon.app/learn/api/): Full REST API documentation - [Blog](https://kordon.app/blog/): Practical GRC guidance for security and compliance teams - [Cybersecurity news](https://kordon.app/cybersecurity-news/): Weekly cybersecurity news summaries - [Pricing](https://kordon.app/pricing/): Full pricing details with plan comparison - [Contact](https://kordon.app/contact-us/): Sales and support inquiries - [Free trial](https://kordon.app/try-kordon-for-free/): Start a free trial ## Company Kordon is built and headquartered in Estonia. The platform has particular depth for E-ITS (the Estonian information security standard) and is widely used by Estonian public sector and private sector organisations subject to E-ITS obligations.