OptiTech logo
Gov Legal · Privacy Security

OptiTech

Swedish compliance automation platform mapping NIS2, DORA, GDPR, ISO 27001 and the EU AI Act to one control set. It collects evidence from connected systems and guides statutory incident reporting to MSB and IMY, from 2,995 kr monthly.

Active GDPR compliant Subscription API available Verified by Guidaio
Overview

What is OptiTech?

OptiTech is a compliance automation platform published by OptiTech Sverige AB, a Swedish company registered on 8 July 2024. Its stated aim is to turn regulatory compliance from an annual project into a continuous, automated process, and it is pitched specifically at Nordic small and mid-sized organisations rather than at the global market the larger platforms address.

Five frameworks are included on every plan: NIS2 (implemented in Sweden as the Cybersecurity Act), DORA, the EU AI Act, GDPR and ISO 27001. Further frameworks are advertised as covered, among them the CRA, SOC 2, ISO 27701, ISO 22301 and TISAX. Controls are cross-mapped, so a single control can satisfy requirements in several frameworks at once and work already done for one standard carries over to the next.

The entry point is an automated gap analysis: twenty questions about sector, size, systems and customers produce a report naming the laws that apply, the NIS2 category the organisation falls into, and a list of gaps ranked by risk. From there the platform generates documentation, drawing on more than fifty Swedish policy templates and on the applicable legal texts, with version control, annual review reminders and employee e-signing.

Evidence collection runs continuously through integrations with the systems a company already uses, verifying matters such as multi-factor authentication, offboarding, backups and patching. Named Swedish integrations include Fortnox, Visma, BankID and Kivra, alongside Microsoft 365. Failing controls can be remediated through an API call or turned into a ticket.

Incident reporting is the module the vendor leans on hardest: guided workflows carry a significant incident through the NIS2 sequence of an early warning within 24 hours, a report within 72 hours and a final report within a month, with countdown timers and pre-filled forms, plus the equivalent 72-hour personal data breach flow to IMY. Around these sit a risk register, supplier assessment with a DORA-ready ICT contract register, security awareness and board training, a public Trust Center, a read-only auditor portal, dashboards, and an AI copilot that answers questions in Swedish. Access uses BankID or SSO, with SCIM on the top plan.

What it does

  • Scope which regulations apply through an automated 20-question gap analysis
  • Collect control evidence continuously from cloud, identity, HR and finance systems
  • Draft policies, procedures and governance documents with AI, in Swedish or English
  • Run the statutory incident workflow to MSB (24 hours, 72 hours, one month) and IMY (72 hours)
  • Maintain a risk register linked to the controls that mitigate each risk
  • Assess and classify suppliers and keep the ICT contract register DORA requires
  • Publish a Trust Center and open a read-only auditor portal
Audience

When to use OptiTech / When not to

A quick filter to help you decide if OptiTech is the right fit.

When to use OptiTech

  • Nordic small and mid-sized companies newly in scope of NIS2 as an essential or important entity
  • Financial institutions and their ICT providers preparing for DORA supervision
  • Security and compliance teams with no dedicated CISO that want to reduce reliance on consultants
  • IT service providers, accounting firms and advisers managing compliance for several clients under the Partner plan
  • Organisations assembling an evidence trail for an ISO 27001 or SOC 2 audit

When not to use OptiTech

  • Organisations outside the Nordics, since the built-in authority workflows target the Swedish regulators MSB and IMY
  • Buyers who want to sign up unaided: the pricing page's sign-up buttons lead to a third-party console, not to the publisher's own
  • Teams looking for a mobile product, as no iOS or Android application exists
  • Anyone expecting the vendor to file with or represent them before a regulator, which the platform terms exclude
  • Buyers who need a supplier with a proven operating track record, given a company registered in July 2024 with no reported employees or revenue
Get started

How to use OptiTech

A typical end-to-end flow, from setup to results.

  1. Request the free "Does NIS2 apply to us?" assessment from the contact page
  2. Answer the twenty scoping questions on sector, size, systems and customers
  3. Read the resulting report: applicable laws, NIS2 category and a risk-ranked list of gaps
  4. Choose a plan according to how many frameworks you need to activate
  5. Connect your cloud, identity, HR and finance systems so evidence can be gathered automatically
  6. Grant read-only access where the third-party service allows it; credentials and tokens are stored encrypted
  7. Generate policies and procedures from the templates, then review, adapt and approve them
  8. Set up user access with BankID or SSO, and SCIM provisioning on the Enterprise plan
  9. Populate the risk register and the supplier register, sending questionnaires to vendors
  10. Publish the Trust Center and open the auditor portal when an audit or inspection comes
Quick read

Pros & Cons

Pros

  • Prices are published openly, with no mandatory sales call before you can budget
  • Built explicitly on Swedish legal texts and MSB regulations rather than generic control mappings
  • Statutory reporting workflows to MSB and IMY are built in, with the legal deadlines tracked
  • Native Swedish integrations are advertised, including Fortnox, Visma, BankID and Kivra
  • Customer data ownership is explicit and export is available at any time, including audit-ready formats
  • Contractual commitment not to train models made available to other customers on customer data
  • Detailed and dated contractual documents covering the platform, the website, privacy and service levels

Cons

  • The site is an incompletely edited copy of another vendor's template: residual Postgres navigation, a /postgresql/tutorial link and a postgres sitemap remain
  • Sign-up buttons, the X/Twitter link, the Discord invitation and the Trust Center all point to that other vendor's properties
  • Three legal documents name a different legal entity, OptiTech, LLC., and link to a domain that is openly for sale
  • The subprocessor page places every subprocessor in the United States, contradicting the EU data residency claimed elsewhere
  • SOC 2, ISO 27001, ISO 27701 and HIPAA are claimed without any certificate number or certification body
  • No working application could be reached: the app and api subdomains return one identical placeholder for every path
  • The publisher reports no employees and no revenue in its latest filed accounts, against a site claiming customers and annual audits
Pricing

Pricing & Plans

There is no permanent free plan. The lowest published price point is the Start plan at 2,995 kr per month (SEK), for companies of roughly five to thirty employees and one framework. Professional is 7,995 kr per month and Enterprise starts at 19,995 kr per month. All prices are stated in Swedish kronor and exclude VAT, are billed annually, invoiced in advance and payable within thirty days, with automatic renewal unless cancelled and at least thirty days' notice of any change at renewal. Optional items are charged separately: onboarding from 25,000 kr, NIS2 board training at a fixed 15,000 kr, phishing simulation at 990 kr per month, and vCISO hours through partners. An initial gap analysis is advertised as free. Note that the pricing page nonetheless carries a Start for free strapline that the published plan grid does not support.

Plan 1
  • Start — 2
  • 995 kr/month — 5 to 30 employees
  • 1 framework
  • 10 integrations
  • BankID
  • EU data residency
  • email support
Plan 3
  • Enterprise — from 19
  • 995 kr/month — 150+ employees and regulated financial institutions
  • unlimited frameworks
  • DORA package
  • auditor portal
  • SSO and SCIM
  • API and CLI access
  • dedicated customer success manager
Plan 4
  • Partner Plan — custom rates — accountants
  • advisers and IT service providers managing many clients
  • with volume discounts and white-label options
Plan 5
  • Startup Program — discounted onboarding and credits for early-stage startups
Plan 6
  • Open Source Program — discounted plans for nonprofits and open source organisations
Special offers — Free initial gap analysis: the twenty-question "Does NIS2 apply to us?" assessment · Startup Program: discounted onboarding and credits for early-stage startups · Open Source Program: discounted plans for nonprofits and open source organisations · Partner Plan: volume discounts and white-label options for accountants, advisers and IT service providers
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how OptiTech handles your data.

GDPR overview

GDPR treatment is documented rather than merely asserted. The privacy policy, updated 24 July 2026, names OptiTech Sverige AB (registration number 559489-8917) as controller, states the legal bases relied on (contract, legitimate interest, consent, legal obligation), and lists the full set of data subject rights with a one-month response commitment. It names Integritetsskyddsmyndigheten (IMY) as the supervisory authority for complaints. Transfers outside the EU/EEA are covered by the European Commission's standard contractual clauses. A data processing agreement is offered, subprocessors are said to be engaged under such agreements, and a subprocessor list is published. One caveat: that subprocessor page names a different legal entity and places every listed subprocessor in the United States, which sits awkwardly with the EU residency claimed elsewhere on the site.

Who owns the data?

The platform terms state that the customer owns everything it puts into the service: evidence, documents, policies, incident records, vendor assessments and integration data. OptiTech Sverige AB receives only the rights it needs to host, process and display that material in order to run the service, and undertakes not to sell customer data or use it for advertising. The customer can export its data at any time in standard formats, including auditor-ready exports. For personal data held on the customer's behalf the publisher acts as a GDPR processor under a data processing agreement; for the website and its own business contacts it acts as controller.

Reuse rights

Customers keep the right to use and take away their own content: export is available at any time in standard formats, and for thirty days after termination, after which the data is deleted from production systems unless the law requires it to be kept. The customer warrants that it holds the rights to what it uploads. On the publisher's side, use is limited to running the service, and the platform terms add an explicit commitment: customer data is not used to train models made available to other customers. That wording is scoped to models shared with third parties, and does not address training confined to the customer's own tenant. Feedback given to the publisher may be reused freely to improve the product. AI output is presented as a draft the customer must review and approve, not as legal advice.

Data retention & training

Retention summary
Retention is set out by category. Contact and demo enquiries are kept while the exchange is live and for up to twelve months after the last contact. Newsletter subscriptions last until you unsubscribe. Account data is kept for as long as the account exists and for thirty days after termination so that data can be exported. Security and access logs are kept up to twelve months. Accounting records are kept seven years, as the Swedish Bookkeeping Act requires. Data created during a trial is deleted thirty days after the trial ends unless the customer converts to a paid plan. After termination the customer has thirty days to export, after which data is deleted from production systems except where the law requires retention. Data no longer needed is deleted or anonymised.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes

Hosting summary

The publisher states that customer data is processed within the EU/EEA and stored in Swedish and European data centres under European ownership, with the option to select a specific data region for a workspace. Where a transfer outside the EU/EEA occurs, the European Commission's standard contractual clauses are said to apply. The pricing FAQ adds that AI features run on EU-hosted models and that no customer data is sent to US-based AI providers. The security page describes infrastructure running on AWS and Azure in EU and Swedish regions. These claims are contradicted by the site's own subprocessor page, which lists Salesforce, Grafana, Amazon Web Services and Microsoft Azure and gives the location of all four as the United States. That page also names a different legal entity from the publisher, so it may be unedited template material rather than an accurate disclosure. The marketing site itself resolves to an address geolocated in Stockholm, Sweden.

Hosting countries
🇸🇪 Sweden
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting OptiTech.

  • Compliance theatre: green controls in a dashboard are not legal compliance, and the vendor says so itself. Treating a passing score as proof before a regulator is the central misuse risk here.
  • AI-drafted policies invite rubber-stamping. The terms make the customer responsible for reviewing and approving every generated document, yet the appeal of the product is precisely that it drafts them in minutes.
  • Statutory deadlines remain the customer's legal responsibility. Relying on the tool's countdown timers without an internal escalation path leaves a 24-hour NIS2 early warning dependent on a single vendor's uptime.
  • The site's own contradictions should temper trust in its factual claims: an EU residency promise contradicted by its subprocessor list, a founding date contradicted by the company register, and control-check volumes that differ between two pages.
  • Certifications are displayed without a certificate number or certifying body, and the linked Trust Center belongs to a third party, so none of the assurance claims can be independently checked from the site.
  • Supplier concentration risk: the publisher reports no employees and no revenue in its latest accounts, which is a material consideration before entrusting it with an organisation's entire evidence chain.
  • The non-training commitment covers only models made available to other customers, so sensitive incident and audit material may still inform processing confined to your own tenant.
Setup

Setup & Integrations

Technical difficulty

Low to moderate for the compliance work itself. Onboarding starts with a twenty-question assessment that needs no technical skill, and policy generation is questionnaire-driven. The effort sits in connecting source systems: cloud, identity, HR and finance integrations must be authorised by someone able to grant access, though access is read-only where the third party allows and can be revoked at any time. Access uses BankID or SSO, with SCIM on the top plan. Guided onboarding is sold separately from 25,000 kr, and Enterprise API and CLI access lets checks run in CI/CD.

Deployment

Web appAPI

Integrations

Fortnox Visma BankID Kivra Microsoft 365

Supported languages

SwedishEnglish
Company

Behind OptiTech

Company name
OptiTech Sverige AB
Founded
08/07/2024
Country of origin
🇸🇪 Sweden
Headquarters
Karlslundsvägen 8, 177 44 Stockholm, Sweden
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇩 Germany
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement OptiTech.

V VantaD DrataS SecureframeS SprintoC Cyberday
FAQ

Frequently asked questions

How does OptiTech pricing work?
It is a flat monthly fee per plan, billed annually, with no usage meters and no per-seat charges. Start is 2,995 kr per month, Professional 7,995 kr per month, and Enterprise starts at 19,995 kr per month. All prices are in SEK and exclude VAT.
What counts as a framework?
A regulation or standard you must comply with: NIS2 (the Swedish Cybersecurity Act), DORA, GDPR, ISO 27001:2022 or the EU AI Act. Your plan determines how many you can activate. Controls are cross-mapped, so one control can satisfy several frameworks at once.
How does the MSB incident reporting flow work?
NIS2 requires three steps: an early warning within 24 hours, an incident report within 72 hours and a final report within one month. The platform guides each step with pre-filled forms and deadline countdowns. The equivalent 72-hour personal data breach flow to IMY is also included.
Is there a free trial?
No free trial of the product is advertised. What is offered free is an initial gap analysis, the twenty-question "Does NIS2 apply to us?" assessment. The platform terms say only that free trials may be offered, and there is no permanent free plan in the published grid.
Can I add frameworks or change plans later?
Yes, you can upgrade or add frameworks at any time and the work already done carries over. Because controls are cross-mapped, a newly added framework often starts partly complete on the strength of controls you already have in place.
Where is customer data stored?
The platform terms and pricing page state that data is processed in the EU/EEA, in Swedish and European data centres, with a region selectable per workspace and standard contractual clauses for any transfer outside the EEA. Note that the site's own subprocessor page contradicts this by locating all four listed subprocessors in the United States.
Is customer data used to train AI models?
The platform terms commit that customer data is not used to train models made available to other customers. That commitment is scoped to models shared with third parties and does not address training confined to your own tenant. No separate opt-out mechanism is documented, because the commitment is unconditional.
Is there an offer for consultants, accountants or IT providers?
Yes. The Partner plan provides a multi-tenant console for managing compliance across many clients, with volume discounts and white-label options. Pricing is on request. Separate programmes exist for early-stage startups and for nonprofits and open source organisations.
Which languages does it support?
Documentation is generated in Swedish or English, the AI copilot answers in Swedish, awareness training is delivered in Swedish, and support is provided in Swedish and English on Swedish business days.
Is there a mobile app?
No. No iOS or Android application was found in the app stores, and the site displays no store badges. The product is delivered as a web application, with API and CLI access available on the Enterprise plan.
Conclusion

Should you pick OptiTech?

OptiTech addresses a real and well-defined need: Nordic small and mid-sized companies newly caught by NIS2 and DORA, who must produce evidence and meet statutory reporting deadlines without the budget for continuous consultancy. The proposition is coherent, the prices are published openly rather than hidden behind a sales call, and the platform terms and privacy policy are detailed, dated and consistent with an identity that checks out: OptiTech Sverige AB is a real company, confirmed at the Swedish register and by EU VAT validation, with a matching name, number and address.

The reservations are nonetheless substantial, and they concern the site rather than the idea. The website is an incompletely edited copy of another vendor's template. Its sign-up buttons lead to that vendor's console, its X/Twitter link to that vendor's account, its Discord invitation to that vendor's server, and its Trust Center to that vendor's domain. The machine-readable files tell the same story: the llms.txt index is titled after a database product and points entirely off-site, and the declared MCP endpoint belongs to the same third party. Three legal documents name a different legal person, OptiTech, LLC., and link to a domain that is openly for sale, which also disposes of the security contact address published on the site.

Two further points deserve attention. The subprocessor page places every listed subprocessor in the United States, contradicting the EU residency claimed on the pricing page and in the platform terms. And the scale implied by the marketing sits uneasily with the public record: the company was registered in July 2024, not January 2023 as the site's own timeline states, and its latest accounts report no employees and no revenue. Verify the entity, the hosting and the certifications directly with the vendor before committing.