Technology Partner Platform

One platform for compliance, security & risk

DeCompass is the AI-powered GRC platform behind the audits Safe Welkin delivers — bringing every compliance framework, security control, and risk workflow into a single, audit-ready system.

DeCompass compliance dashboard
7+Regulatory frameworks covered
20+Purpose-built modules
< 4hAverage customer onboarding time
24/7Continuous monitoring

Compliance Frameworks

Certify against the standards your customers and regulators ask for — each framework ships as a guided, evidence-linked module.

ISO 27001:2022 (ISMS)

Statement of Applicability, risk register, control library, internal audits, and certification tracking in one workspace.

SOC 2 Type II

Engagement management, continuous control monitoring, and a shared workspace for your team and your auditor.

PCI DSS v4.0

SAQ automation, scoping documents, a guided ROC builder, PAN scanning, and segmentation testing.

GDPR / UK GDPR

DPIAs, a live data inventory (ROPA), consent & cookie management, DSAR handling, and 72-hour breach detection.

NDPA 2023 (Nigeria)

NDPC registration support, DSAR workflows, breach registers, and DPO governance built for the Nigerian market.

NIS / NIS2

Asset and vulnerability management, incident response, and supply-chain security controls for essential-service operators.

Cyber Essentials (UK)

Self-assessment questionnaire, MFA/patching/device checks, an external vulnerability scan, and renewal tracking.

Security & Risk Operations

Move from point-in-time assessments to continuous, evidence-backed security operations.

VAPT & Penetration Testing

End-to-end engagement management, a dedicated tester portal, ASV scans, and a vulnerability disclosure programme (VDP).

Cloud Security Posture Management

Native AWS, Azure, and GCP connectors surface misconfigurations, map them to your frameworks, and track remediation trends.

Threat Intelligence

IOC feeds, dark web monitoring, brand protection, threat-actor tracking, and SOAR-style response playbooks.

Securax — Mobile App Security

Real and simulated mobile app scanning, asset inventory, benchmark scoring, and network topology visibility.

Behavioural Anomaly Detection

SIEM-integrated analytics that flag unusual behaviour automatically — no manual log-trawling required.

Enterprise Risk Register

A single risk register that rolls every framework's risks up into one organisation-wide risk score.

Governance & Operations

The processes around compliance — financial crime, vendors, continuity, and people — run through the same system.

AML & Financial Crime Compliance

Transaction monitoring, sanctions & PEP screening, CDD/EDD/ODD workflows, case management, and FATF-aligned reporting.

Third-Party Risk Management

Vendor lifecycle tracking, security questionnaires, security ratings, and contract & concentration-risk visibility.

Business Continuity (ISO 22301)

Business impact analysis, continuity plans, crisis communication, and a full exercise & testing programme.

Security Awareness & Phishing Simulation

Training courses and simulated phishing campaigns with reporting to track organisation-wide risk reduction.

Ethics & Whistleblowing

A structured intake and case-handling workflow for ethics concerns and whistleblower reports.

Regulatory Updates

A curated feed of regulatory changes, mapped directly to the controls and frameworks they affect.

Platform Infrastructure

The operating layer every module shares — so evidence, tasks, and reporting never live in silos.

Unified & Executive Dashboards

Real-time compliance posture for practitioners, and board-ready summaries for leadership.

Control Registry & Evidence Library

One control catalogue mapped across every framework, with evidence captured once and reused everywhere it applies.

Task Center & Compliance Calendar

Cross-framework tasks, deadlines, and ownership tracked in a single calendar.

Connectors Hub

Native connectors for AWS, Azure, GCP, LDAP, SFTP/FTP, and major SQL/NoSQL databases.

Audit Trail & Multi-Tenant Admin

Full activity logging, role-based access, and custom packages for multi-entity organisations.

Trust Center & External Portals

A public Trust Center, vendor portal, auditor access, and self-service DSAR portals for GDPR and NDPA requests.

See DeCompass in action

Safe Welkin's team can walk you through the platform and help you map it to your compliance obligations.