
Tazilla
Tazilla is an AI-driven cybersecurity governance platform from Slovak publisher ITACON. It brings risk analysis, threat intelligence, supplier oversight, policy documentation and staff training into one EU-hosted workspace built to satisfy NIS2, GDPR and ISO 27001 requirements.
What is Tazilla?
Tazilla is an AI-driven, modular platform for cybersecurity governance and compliance, published by the Slovak company ITACON s.r.o. and delivered as browser-based software at app.tazilla.com. It gathers into one system the work that many organisations still spread across spreadsheets and disconnected tools: risk management, asset and supplier oversight, policy documentation, incident records, business continuity planning, staff training and regulatory reporting against NIS2, ISO/IEC 27001 and the GDPR.
The platform is organised as modules that can be adopted separately. Risk Analysis lets teams identify assets, attach threats and impacts, calculate risk levels and define matching controls, with visualisations of inherent against residual risk. The AI Advisor shortens that first pass by proposing assets, risks and recommended measures from the organisation's own data, leaving the user to adjust and confirm each suggestion. Behind it sits a modular agentic architecture: separate Assets, Threats, Impacts and Risks agents coordinated by a manager agent, designed to guide non-specialists step by step. Threat Intelligence watches internet-exposed services for weaknesses and presents them in dashboards, while a Honeypot module detects attacks against simulated services and returns only aggregated indicators of compromise. Third Party Management records external partners and scores their inherent and residual risk through questionnaires. Documentation stores policies, guidelines, audits and assessments, and can generate an audit-duration questionnaire and a formal audit request. Employee Awareness delivers AI-narrated online training with testing and tracking. Analytical Insights turns the whole picture into a management view with coloured risk indicators.
Tazilla was designed by practising CISOs and auditors, and is positioned for organisations that fall inside the NIS2 perimeter without necessarily having an internal security team: public institutions, hospitals, universities, ministries and SMEs. Multi-tenant management lets external CISOs and security providers oversee several client organisations from a single dashboard, each with isolated data and separate access control. The publisher claims more than 150 organisations already use it. The project is funded under EU Grant Agreement No. 101127962, supported by the European Cybersecurity Competence Centre. The first version shipped in 2025, and a published roadmap runs from data export through an AI Threat Analyst to AI honeypot deployment in 2027.
What it does
- Run a structured risk analysis: map assets, attach threats and impacts, then calculate inherent and residual risk
- Let the AI Advisor propose assets, risks and security measures, then adjust and confirm each suggestion
- Produce audit-ready documentation, policies, compliance overviews and reports for auditors and regulators
- Monitor internet-exposed services for threats and vulnerabilities, with honeypot indicators of compromise
- Register third parties and score supplier risk through questionnaires before deciding how to work with them
- Assign, deliver and track AI-narrated cybersecurity awareness training across the workforce
- Maintain business continuity planning with BCP and DRP records, RTO and RPO targets
When to use Tazilla / When not to
A quick filter to help you decide if Tazilla is the right fit.
When to use Tazilla
- Public bodies and critical-sector operators that must evidence NIS2 compliance to a regulator
- CISOs and IT administrators in small and mid-sized organisations with no dedicated security team
- External or virtual CISOs and managed security providers overseeing several client organisations at once
- Compliance officers and internal auditors assembling risk reports and audit evidence
- Third-party risk and procurement teams that must assess and document supplier security
When not to use Tazilla
- Consumers and private individuals: the terms restrict the service to business and professional use
- Teams that need programmatic access: no public API or API documentation is published
- Mobile-first users: there is no iOS or Android application, only a browser-based platform
- Security operations centres wanting deep forensics: the honeypot returns only aggregated indicators of compromise
- Organisations outside European regulation, whose priorities are not NIS2, GDPR or ISO 27001
How to use Tazilla
A typical end-to-end flow, from setup to results.
- Open the shared public demonstration account on app.tazilla.com to explore the platform on the fictional Cyberdyne company, without registering
- Compare the four plans on the pricing page and check the user, asset and tenant limits against the size of your organisation
- Start the one-off 30-day free trial of the Starter plan, which requires no payment details
- Create the initial user account, which activates the service, then add and administer the other users
- Activate multi-factor authentication for every user, as the terms require
- Let the AI Advisor generate a first set of assets, risks and recommended controls, then review, adjust and confirm them
- Complete the risk analysis by attaching threats and impacts to assets and recording the selected security measures
- Register suppliers and third parties, send the assessment questionnaires and record their residual risk
- Build the documentation set from the supplied policy templates, then assign awareness training to employees
- Generate risk reports, compliance overviews and audit evidence when an audit or regulatory review approaches
Pros & Cons
Pros
- End-to-end NIS2 coverage in one tool: risk, documentation, incidents, suppliers, continuity, training and audit evidence
- Transparent pricing with a plan-by-plan comparison table and public monthly rates for three of the four tiers
- A 30-day free trial plus a permanently open demonstration account that needs no registration
- EU hosting on Azure in ISO 27001-certified data centres, with TLS 1.2+, AES-256, RBAC, 2FA and daily backups
- An explicit contractual commitment that customer data is never used to train AI models
- Published Data Processing Agreement naming its sub-processor, and a public SLA with P1 to P4 response times
- Modular design and multi-tenant management, useful to external CISOs and to teams that need only part of the platform
Cons
- No public API and no API documentation; advanced integrations are mentioned only for the Enterprise plan
- No named third-party integrations anywhere on the site
- No mobile application: the product is browser-only
- The SLA target availability is 97% per month, which tolerates roughly twenty-two hours of downtime
- Support runs on business days from 08:00 to 16:00 CET, with phone capped at one hour a month and Starter limited to the forum
- ITACON is not yet ISO/IEC 27001 certified; the certification belongs to its partner redByte and ITACON says it is preparing its own
- A young product whose first version shipped in 2025, with several announced features still on the 2026-2027 roadmap
Pricing & Plans
Tazilla has no permanently free plan. Paid subscriptions start at EUR 49 per month for the Starter plan, covering five users and thirty assets, and prices are stated inclusive of VAT. Each customer may take a one-off 30-day free trial of the Starter plan, and a shared demonstration account is available without registration.
- 5 users
- 30 assets in risk analysis and continuity management
- cyber events
- third parties
- configurations
- tasks
- change management
- ISO 27k compliance
- 250 users
- 250 assets
- education for 250 users
- vScan (internal vScan optional)
- honeypot
- unlimited AI agent
- 1 tenant
- forum plus chat and one hour of phone support per month
- same 250-user and 250-asset volumes as SME Edition but 5 tenants
- forum plus chat and one hour of phone support per month
- aimed at external providers managing several organisations
- unlimited users
- assets
- education and tenants
- internal vScan included
- priority support
- advanced integrations and SLA
Data, GDPR & hosting
A consolidated view of how Tazilla handles your data.
GDPR overview
GDPR implementation is documented in detail rather than merely claimed. The homepage states Tazilla is fully GDPR compliant; the privacy policy splits the roles explicitly, ITACON being controller for accounts, billing and operations and Article 28 processor for everything customers enter. A Data Processing Agreement is published and forms part of the terms, with Annex 1 naming the single sub-processor, redByte s.r.o. Data subject rights are listed in full and exercised at tazilla@itacon.sk. Complaints go to the Office for Personal Data Protection of the Slovak Republic. Breaches are notified to the customer within 24 hours, and sub-processor changes 14 days in advance with a 10-working-day objection window. Servers sit in the EU; transfers outside the EEA occur only through third-party AI functions, covered by Standard Contractual Clauses. No Article 27 representative is named, and none is required for a Slovak publisher.
Who owns the data?
Clause 5.4 of the terms states that the customer keeps all rights to the data it enters into or creates within the platform. For the duration of the contract the customer grants ITACON a licence to use that data only as far as necessary to provide, operate, secure and support the service. For personal data entered into Tazilla the customer is the controller and ITACON the Article 28 processor, acting solely on written instructions under the published Data Processing Agreement. The trust centre adds that customer data is never sold or shared and that internal access is limited to three employees and logged.
Reuse rights
Customers may reuse their own data freely, because they own it. Clause 7.4 gives them the right to export everything they entered or generated, metadata included, in a common machine-readable format on request. On departure ITACON must assist the switch to another provider within thirty calendar days and keep access open for at least thirty further days so the data can be retrieved, after which it is securely deleted. ITACON's own reuse is deliberately narrow: clause 3.7 rules out any training or improvement of artificial intelligence models on customer data, by the provider or by third parties, and the Data Processing Agreement permits only aggregated or properly anonymised data to be used to improve the service. The software itself remains ITACON property under a non-exclusive, non-transferable licence, so exported records may be reused but the platform may not be copied, resold or reverse-engineered.
Data retention & training
Hosting summary
Tazilla runs on Microsoft Azure, on servers located within the European Union, in data centres certified to ISO/IEC 27001. No specific hosting country is named. Kubernetes is used to match Azure-level service targets, network access is restricted behind firewalls and private VPCs, and configurations are hardened and patched regularly. Data in transit is encrypted with TLS 1.2 or above, and the SLA cites TLS 1.3; data at rest is encrypted with AES-256, key management being handled entirely by Azure. Automated daily backups are encrypted, retained for thirty calendar days and then securely deleted, with real-time database redundancy. Access to customer data is limited to three employees and logged. Transfers outside the EU or EEA can occur only where AI functions are provided by third parties located outside the bloc, and are covered by Standard Contractual Clauses. The jurisdiction governing the contract is Slovakia, with disputes heard by Slovak courts.
Things to keep in mind
Risks and trade-offs to weigh before adopting Tazilla.
- AI outputs are advisory only: the terms explicitly disclaim their accuracy, completeness, timeliness and fitness for purpose, and require professional review before any security decision
- Treating generated risk analyses as finished work is the main misuse risk; the customer stays responsible for every decision taken on that basis
- Some AI functions run through third parties outside the EU or EEA, so data entered into them may leave the bloc under Standard Contractual Clauses
- The ISO/IEC 27001 and ISO 9001 certificates cited belong to the partner redByte, not to ITACON, which states it is still preparing its own certification
- Liability is capped at twelve months of fees with a floor of EUR 1,500, which is modest against the value of a compliance failure
- The demonstration account is shared by every visitor, so nothing real should ever be entered into it
- Target availability is 97% per month excluding planned maintenance, so the platform should not be treated as an always-on incident response tool
Setup & Integrations
Technical difficulty
Low. Tazilla is pure SaaS: nothing to install, access is through a browser at app.tazilla.com. Creating the initial user account activates the service, after which the customer administers its own users and enables multi-factor authentication. The AI Advisor is designed to carry the heaviest part of the first risk analysis, so no in-house security expertise is strictly required, and guidance, policy templates and workflows are supplied. The publisher states that most organisations are running within days, with risk, documentation, compliance and training usable almost immediately.
Deployment
Supported languages
Behind Tazilla
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What exactly is Tazilla?
How much does it cost, and is there a free plan?
Can I try it before buying?
Where is my data hosted?
Is my data used to train AI models?
Is a Data Processing Agreement available?
Does Tazilla offer an API or a mobile app?
What happens to my data if I leave?
Which languages does the platform support?
Who publishes Tazilla?
Should you pick Tazilla?
Tazilla occupies a clear European niche: cybersecurity governance and NIS2 compliance for organisations that must satisfy a regulator without necessarily employing a full security team. Its strength is coverage. Risk analysis, threat intelligence, supplier assessment, policy documentation, business continuity, incident records and awareness training all live in one place, and the platform is explicitly built to produce the evidence an auditor asks for. The AI layer is used where it saves the most time, on the first pass of a risk analysis, and the terms are candid that its output is advisory and needs professional review before any decision is taken.
The commercial and legal posture is unusually transparent for a young vendor. Three of the four plans carry public monthly prices, the Data Processing Agreement names its single sub-processor, the SLA publishes response times, and clause 3.7 commits in writing that customer data will never train an AI model. Hosting is in the EU on Azure, in ISO 27001-certified data centres, with a documented right to export and leave.
The reservations are equally clear. There is no public API, no mobile application and no named integration, which limits how far Tazilla can sit inside an existing toolchain. Target availability is 97% a month and phone support is capped at one hour. The ISO/IEC 27001 certificate belongs to the development partner redByte, not to ITACON itself, which says it is preparing its own. The product shipped its first version in 2025 and several announced capabilities are still dated 2026 or 2027.
For a mid-sized European organisation or a public body entering the NIS2 perimeter, and for external CISOs managing several clients through the multi-tenant plans, Tazilla is a serious and well-documented candidate. Organisations wanting deep integration or round-the-clock support should look further.
- Choosing a selection results in a full page refresh.
- Opens in a new window.