ExGear Insight has grown from an audit and GRC core into an integrated suite of assurance domains — all sharing one risk universe, one control library, and one evidence base.
The latest additions to the suite — built on the same shared data model as the audit and GRC core.
A governed register for every managed asset, fed by automated discovery and verified in the field.
Full third-party risk management from onboarding to structured offboarding.
One lifecycle for every change — regulatory, software, infrastructure, policy, and organisational.
The conduct layer of your control environment — from code of conduct to board committees.
Board-grade reporting across every domain, on one indicator registry.
The authoritative home for GRC evidence — from formal request campaigns to court-admissible chain of custody.
Personal and team work management — Kanban, list, Gantt, and sprint boards, natively linked to your GRC data.
Productivity modules at roughly 95% completion — rolling out on the same platform foundation. Ask us about early access.
Incident intake and triage, ITIL-style problem management, and corrective action plans — with AI-assisted root-cause analysis using 5-Whys, fishbone, and fault-tree methods.
Business impact analysis with RTO/RPO targets, versioned recovery plans, exercise management, and dependency mapping — aligned to ISO 22301, NIST SP 800-34, and DORA.
Role-based training programs, assessment engine with proctoring, learning paths, and QR-verifiable digital certificates — mapped to NIST, ISO 27001, PCI DSS, and HIPAA training requirements.
Contract lifecycle from draft to termination with per-clause obligation tracking, multi-stage reviews, amendment versioning, and renewal automation.
Designed and specified — coming to the platform next.
GRI, SASB, ISSB (IFRS S1/S2), CSRD/ESRS, and TCFD reporting with cross-standard mapping — report once, satisfy many.
Ingest findings from Nessus, Qualys, and Burp; AI triage and deduplication; SLA-driven remediation tracking.
CycloneDX and SPDX ingestion, component-to-vulnerability matching, and license compliance for your software supply chain.
The audit and GRC foundation everything else builds on.
One integrated data model across every module — risks, controls, evidence, and reporting that finally agree with each other.