Skip to content
VIGÍA · Living risk analysis

The first risk analysis that never stands still.

A traditional analysis is a snapshot that expires the day it is signed. Vigía is a movie: Lucy's interview builds it in 15 minutes and, from then on, it recalculates itself — every month, week or day depending on your plan — crossing threats, vulnerabilities and news with YOUR inventory, YOUR sector and YOUR sites.

✓ No card on Free · Instant activation · Local AI: your data never leaves our data centre

MAGERIT · ISO 27005 · MITRE ATT&CK Local AI — your data never leaves Spain Monitoring CCN-CERT · INCIBE · KEV/EPSS Instant activation — no sales reps

What it covers

The whole risk cycle, in a single tool

Each module shows the plan it is included from. Higher plans include everything from the previous ones.

MAGERIT / ISO 27005 analysis

Guided 9-step flow: assets, dependencies, valuation, threats, inherent and residual risk. Lucy's interview generates it for you and every page explains itself the first time.

From Free
✦ Proposal 1…
✦ Proposal 2…
Use

AI that proposes, you decide

Assisted asset valuation, “Write with Lucy” in justifications, risks and action plans. It never writes alone: it proposes and you approve, adjust or skip. All locally.

Sample on Free · full on Advance

Treatment and action plans

Five strategies (mitigate, transfer, accept, avoid, exploit), recalculated residual, action plans with follow-up and sign-off of the analysis.

From Free

Indicators (KRIs)

Key risk indicators with history, periodicity and trend — to show the auditor (and management) that risk is measured, not guessed.

From Advance

Corporate risks

The risks a manager understands: contracts, suppliers, key people, regulation. With the same treatment engine as the technical ones.

From Enterprise

Continuity (ISO 22301)

BIA by process, continuity plans generated from your real data and a test calendar with lessons learned.

From Enterprise

AI governance (ISO/IEC 42001)

Inventory of AI systems and prior impact assessment — what you will be asked for if you use AI with customers or employees.

From Enterprise
0
expected loss avoided per year

Risk, in euros

Annual expected loss, Monte Carlo simulation and “what if…” scenarios before investing. So management can decide without a MAGERIT lecture.

From Enterprise

Suppliers (TPRM)

Third-party risk connected to your analysis: the supplier you transfer a risk to stays monitored, not forgotten.

From Enterprise

Daily OSINT monitoring

CCN-CERT, INCIBE, exploited vulnerabilities (KEV/EPSS), attack trends, incidents in your sector and the geopolitics of your sites — all cross-checked daily against your assets and risks. If something affects you, you know right away.

Pro · Sentinel
Ransomware risk?
Medium-high · 2 plans ✦

24/7 virtual analyst

Chat with Lucy about YOUR risk posture: she knows your open risks, your plans and your alerts, and answers like your analyst.

Pro · Sentinel
JiraM365Slack

Integrations

Jira, Microsoft 365, EDR, webhooks, API and SSO. Action plans live where your team works, not on another island.

From Enterprise

What sets the plans apart

How often does your risk recalculate?

It is the real difference between plans. Each automatic review regenerates your scenarios, compares with the previous one and tells you in plain language what changed — with an alert in the app and in your inbox.

Manual recalculationYou recalculate the analysis whenever you need it, once a month. The full analysis, at no cost.Free
MonthlyThe analysis reviews itself every month: what got worse, what improved and what is new in the catalog.Advance
WeeklyThe rhythm of a security committee: no figure in your analysis is older than seven days.Enterprise
Daily, with monitoringIf the world changes today, your analysis changes today: OSINT monitoring, sector radar and geopolitical context included.Pro · Sentinel

Continuous monitoring · the heart of Sentinel

An analyst that never sleeps: it watches the world and crosses it with your company

Monitoring is not a news feed. Every day, Vigía reviews your assets and your risks one by one against what is happening out there: official advisories, exploited vulnerabilities, attack trends, incidents at companies in your sector and geopolitical context. If something affects you, your analysis changes — and you find out, with the why.

Your assets, reviewed one by one

Every CCN-CERT and INCIBE advisory and every exploited vulnerability (KEV/EPSS) is checked against your real inventory: what you have, which version, what you expose to the internet. No noise: only what concerns you.

Pro · Sentinel

Trends, before they arrive

Ransomware campaigns, targeted phishing, new MITRE ATT&CK techniques. If a trend points at companies like yours, your risks rise before the hit, not after.

Pro · Sentinel

Your sector, under the radar

An incident at a company like yours? New risks starting to appear in your industry? Vigía detects them and proposes adding them to your analysis. You learn from the hit someone else took.

Pro · Sentinel

Geopolitics by site

Crises, conflicts and regulatory changes in the countries where you operate. If a site or a supplier sits in a hot zone, its risk rises on its own — with the why explained.

Pro · Sentinel

And nothing stays a mere alert: every finding ends in a recalculated risk, a notification in the app and in your inbox and, if needed, an action plan proposed by Lucy.

Local AI

Your data is yours alone. Literally.

Our AI runs in our own data centre in Spain. Your inventory, your risks and everything you write are processed locally, inside that boundary — nothing is sent to third-party AI providers.

  • No OpenAI, no Google, no provider on the other side of the world
  • Data centre in Spain — your data never crosses a border
  • Nobody trains models on your information
  • When you sell compliance, you start at home
GRC GO DATA CENTRE · SPAIN
Your inventory Your risks Lucy, the AI
OpenAI
Google
Other third parties

Your information does not leave the data centre: any attempt to get out bounces back.

Plans and pricing

What each version includes, no small print

The difference is the cadence: each plan reviews your analysis more often. Prices excl. VAT; paid plans on a 24-month contract, payment gateway and instant activation.

Free0 €<10 employees Advance99 €/mes6 months free Enterprise349 €/mes6 months free Pro · Sentinelfrom €890/monthinstant activation
The analysis
Analysis reviewManual · 1 recalculation/monthMonthly, automaticWeekly, automaticDaily, automatic
Complete MAGERIT / ISO 27005 analysis, guided step by step
Assets · sites · users30 · 1 · 1∞ · 3 · 5∞ · ∞ · 20∞ · ∞ · ∞
Multi-organisation (groups, subsidiaries, consultants)
Extended catalogue (MITRE ATT&CK + business risks + sector/location)
PDF/Word reportBrandedUnbrandedUnbrandedUnbranded
The AI that works for you — locally
Lucy's interview: generated inventory and risks
Assisted asset valuation (the AI proposes, you decide)Sample
“Write with Lucy” in justifications, risks and plansSample
Plain-language summary of every review
Alerts for new catalogue risks
24/7 virtual analyst (chat with your risk posture)
Modules
Key risk indicators (KRIs) with history and trend
Corporate risk register (legal, suppliers, people)
Business continuity: BIA, plans and tests (ISO 22301)
AI governance (ISO/IEC 42001): inventory and prior assessment
Supplier risk (TPRM)
Quantification in € (expected loss, Monte Carlo, “what if…”)
Monitoring and integration
Daily monitoring of official sources (CCN-CERT, INCIBE, KEV/EPSS), cross-checked asset by asset against your inventory
Emerging attack trends: if a campaign targets companies like yours, your risk is recalculated before the hit
Sector radar: incidents and new risks in your industry, detected and proposed into your analysis
Geopolitics by site: crises in your countries → your risk rises on its own
Every alert ends in action: recalculated risk, notification and a proposed action plan
In-app notifications + configurable email alerts
Alerts to Teams / Slack · API · SSO · Jira
Support
SupportStandardStandardPriorityPriority · 99.5% SLA · dedicated onboarding
Start free Activate — 6 months free Activate — 6 months free Activate now

Two ways to start today

Free forever, or your plan activated instantly

Free. Forever.

For companies under 10 employees

  • Complete MAGERIT/ISO 27005 analysis, with nothing cut back
  • Lucy's interview + AI-generated inventory and risks
  • Up to 30 assets · one recalculation per month
  • PDF report for your management or your client
  • No card, no expiry, no small print
Create my free account →

Activate it instantly

Advance · Enterprise · Pro — no sales reps

  • Payment gateway and instant activation: you pay and you are in
  • 6 months free on Advance and Enterprise
  • No sales calls or follow-ups: you try it on your own
  • Everything you built on Free is kept when you upgrade
  • Public prices: what you see in the table is what you pay
Activate my plan →

Questions? Write to us

No sales reps, no calls: we reply in writing within 24 working hours.

Submissions are sent via FormSubmit (USA) to info@grcgo.com. Details and your rights in the privacy policy.

By sending you accept that we process your data only to reply to you. Rights: info@grcgo.com.

Your analysis starts today. And it never expires again.

Fifteen minutes with Lucy and you will have your inventory, your risks and your report. No sales reps, no demos: free, or with your plan activated instantly.