Risks
A living risk register.
- Inherent and residual heatmap: one click on a cell filters the list.
- Availability, integrity and confidentiality criteria on every risk (GDPR, Art. 32).
- Justified treatment decision: owner, due date, review.
Governa AI · GRC platform operated by LuxGap
Governa AI replaces spreadsheets, email chasers and consolidation meetings. Risk register, NIS2, DORA, ISO 27001 and AI Act questionnaires, third-party assessments, incidents and evidence: everything is linked, segregated per client and ready for the next audit.
The problem
Where do we stand on NIS2, requirement by requirement?
Which critical suppliers have not been reassessed this year?
Who accepted this risk, why, and until when?
When the answer is scattered across spreadsheets, it takes days to piece together. In Governa AI, it fits on one screen, with its source.
The platform
Registers are linked to each other: what you enter in one place feeds the indicators, the reports and the copilot. Each client has its own strictly segregated space.
Scoping
Domains, scopes, assets and actors: the map of your organisation, exportable to a spreadsheet.
Risks
Likelihood × impact register, ISO 27005 or EBIOS RM campaigns, justified treatment decisions and acceptances with a review date.
Third parties
Weighted scoring per criterion, assessment history and concentration alerts on critical providers.
Compliance
Guided frameworks, controls, audits, policies, due diligence questionnaires and a trust centre.
Operations
Incidents with notification countdowns, findings, exceptions and a calendar of deadlines.
Foundation
Evidence register, executive dashboard, board brief and reports in PDF or DOCX.
Users
Roles, a per-module permission matrix and a complete activity log, exportable to CSV.
Guided tour
Eight screens of the real application, on a fictitious data set.
Risks
Compliance
Assessments
Suppliers
Due diligence
Incidents
Analytics
Trust
Frameworks
LuxGap loads the frameworks into the assessment engine. You answer closed questions; Governa calculates the status, the gaps and the coverage.
How the status is calculated
NIS2 · art. 20 Members of the management body take cybersecurity training.
Calculated status Partial
AI Copilot
The Governa copilot has no access to the database. It uses read-only server tools, limited to the active client: it calls them, reads their results and answers with links to the records concerned.
Security
Governa AI applies to its own data the standard LuxGap applies in its external CISO engagements.
Every register belongs to a client and every read goes through segregated access. An automated test checks it on every release.
Admin, CISO, user and your own roles: nine modules, four levels, enforced server-side.
A user can view. They only edit a module when their CISO explicitly grants it.
Every write is recorded with its before and after values, as are sign-ins and downloads. CSV export.
Security events are collected by the LuxGap SIEM and kept for six months.
Lockout after five failed sign-ins, an anti-CSRF token on every action, security headers.
Who is behind it
Security, data protection and compliance. Publishes and operates Governa AI.
Infrastructure and server operations.
Development of the platform software.
Onboarding
Your domains, scopes, assets and priority framework.
Roles, permission matrix, likelihood and impact scales.
Import of your policies, your assessments and the questionnaires you receive.
Hand-over to your teams, backed by LuxGap’s external CISO if you wish.
FAQ
For anything else, the demo is the right time to talk about it.
Book a demoCISOs, DPOs and compliance managers of organisations subject to NIS2 or DORA, or working towards ISO 27001, and the LuxGap teams that support them. Each organisation has its own strictly segregated space.
ISO/IEC 27001:2022 (Annex A and ISMS), NIS2, DORA and the AI Act, 175 requirements in total, plus scored security assessments such as CyberFundamentals. The engine is data-driven: adding a framework means loading its content.
The copilot never accesses the database. It calls read-only server tools, limited to the active client, and only receives their results. Without an AI provider, answers are calculated locally.
In the European Union, on the infrastructure run by LuxOps for the LuxGap group. Each client’s data is segregated and every action is logged.
Yes: registers in XLSX, the activity log in CSV, reports and dossiers in DOCX or PDF.
Yes, the interface is available in French and English. The copilot currently answers in French.
Book a demo: we walk through your risks, your priority framework and your critical suppliers together, then we open your space.
A walkthrough of the platform, a conversation about your obligations and a proposal tailored to your organisation.