Risk & Incident Management

Structured Risk Handling, Built for Deadline-Driven Response

Log an incident or risk, assign an owner and an independent reviewer, treat it with evidence gated behind a review step, and keep a full audit trail — the same structure that helps you respond within regulatory windows like DPDP's 72-hour breach-notification rule.

Book a Demo
Event-Based Lifecycle

Ends permanently at Closed — a recurrence is logged as a new risk, not reopened.

OpenAssessingTreatmentPending ReviewVerifiedClosed
Four Treatment Paths

Mitigate

Implement controls, then submit evidence for review.

Transfer

Shift the risk to a third party (insurance, contract), then submit evidence.

Accept

Requires a written justification and reviewer approval before closing.

Avoid

Stop the activity causing the risk — closes immediately, no review needed.

Evidence-Gated Review

Submitting for review requires a file or a substantive comment. An independent reviewer — never the same person as the owner — either verifies (which auto-closes the risk) or rejects with a mandatory reason, sending it back for rework. There's no limit on rejection cycles, and every action is logged to a per-risk audit timeline.

Dashboard Views

All Risks

My Risks

Pending Review

Open

In Progress

Each with a live count, so nothing sits unnoticed in a queue.

On the DPDP 72-Hour Rule

Log a data breach as a risk, assign a DPO as reviewer, and use the evidence trail and audit log to demonstrate a timely, structured response. What this doesn't do (yet): automatically submit anything to the Data Protection Board of India, or auto-notify affected data principals — those remain manual steps today.

Walk through a risk end to end

From open to closed, including a rejection and resubmission.