
Whisperly
Whisperly is an AI-driven GRC platform from Estonian publisher Lexelerate OÜ. It bundles privacy records, EU AI Act governance, vendor assessments, questionnaire answering and a public trust page into one workspace for compliance, security and legal teams.
What is Whisperly?
Whisperly is a governance, risk and compliance platform built around the idea that most compliance work is routine enough to be delegated to software agents. Its pitch is a direct attack on incumbent tools: legacy compliance suites assume a human copies records, chases vendors and formats reports by hand, whereas Whisperly's agents run that work and leave people the judgment calls. The workflow is presented in three movements — discover and document, score and classify, then monitor and report.
The platform bundles five connected solutions that can be adopted separately. Data Privacy covers records of processing activities, data protection impact assessments, data subject access requests, a breach register and a register of DPAs. AI Governance builds an inventory of every AI system in use and classifies its risk under the EU AI Act, ISO 42001 and NIST, including Annex III screening and technical documentation. Vendor Assessment sends structured questionnaires to suppliers and scores the replies automatically. RFP Automation drafts answers to security questionnaires such as SIG, CAIQ and HECVAT from an approved knowledge base. Trust Center publishes a branded public page where prospects can self-serve policies and certification badges.
Discovery leans on read-only connectors into Google Workspace, Microsoft 365, Okta or Entra ID, AWS and Azure accounts, SaaS spend and code repositories, which is how the tool claims to surface shadow AI nobody registered. Groups are handled through multiple legal entities, each keeping its own register and posture. Three segments are addressed explicitly — startups, mid-market and enterprise — plus consultants and law firms. Several free public utilities sit alongside the product, including an EU AI Act compliance checker, a DPO requirement checker and an EU representative checker.
The publisher is Lexelerate OÜ, registered in Tallinn on 21 April 2025, and presents itself as founded by data and AI lawyers and information security leaders. Customers named on its trust page include Bloomberg Adria, Lesnina XXXL and BMTS Technology.
What it does
- Map AI systems, processing activities and vendors automatically, then generate the records each framework requires
- Classify risk against the EU AI Act, the GDPR and internal criteria, flagging gaps and attaching evidence
- Produce and export audit-ready reports and registers at any moment, including RoPA and DPIAs
- Send structured vendor assessments, score the answers automatically and surface gaps before signature
- Draft answers to RFPs and security questionnaires from an approved internal knowledge base
- Publish a branded public trust page with badges, policies and NDA-gated documents
- Trigger a re-assessment whenever something changes, and notify subscribed clients in one click
When to use Whisperly / When not to
A quick filter to help you decide if Whisperly is the right fit.
When to use Whisperly
- Compliance and privacy teams that must keep RoPA, DPIAs, DSARs and a breach register continuously up to date
- Organisations preparing for the EU AI Act or ISO 42001 and needing an inventory of every AI system in use
- Security and pre-sales teams drowning in security questionnaires, RFPs and repeated buyer due diligence
- Groups with several subsidiaries, since workspaces and billing are organised per legal entity rather than per user
- Startups and consultancies that need to look audit-ready quickly in order to unlock enterprise deals
When not to use Whisperly
- Buyers who need a published price before talking to a salesperson, since no amount appears anywhere on the site
- Teams looking for a developer platform: there is no public API and no developer documentation
- Anyone expecting a mobile application, as the product ships only as a browser workspace
- Organisations that require their vendor to already hold ISO 27001 or SOC 2, which Whisperly does not yet have
- Buyers who want to pay monthly, because every plan is sold as a one-off annual subscription
How to use Whisperly
A typical end-to-end flow, from setup to results.
- Decide which of the five solutions you need first, since each can be adopted on its own
- Book the 30-minute demo, which is the main entry point and the only way to obtain a price
- Alternatively, sign up self-service for the free Trust Center, with no credit card required
- Wait for the team to approve free Trust Center access, which follows an internal audit
- For a migration from another GRC tool, attend the day-one kick-off call mapping data, scope and integrations
- Let the team import existing RoPA, consent records, vendor lists, DPIAs and policy templates, with no manual re-entry
- Authorise the read-only connectors so the discovery agent can inventory AI systems across your stack
- Review every imported record, configure workflows and run the compliance gap check
- Enable SSO through Google or Microsoft, which is included on every plan
- Confirm go-live, at which point the subscription and billing start
Pros & Cons
Pros
- Five compliance modules on one platform, adoptable separately as needs grow
- Unlimited users and storage on every tier, with billing per legal entity rather than per seat
- Data hosted in EU AWS data centres, encrypted with AES-256 at rest and TLS 1.2 or higher in transit
- A complete Data Processing Agreement published openly and included for all customers
- A published subprocessor list giving each provider's category and hosting country
- A contractual commitment not to train AI models on customer content without prior consent
- A genuinely permanent free Trust Center plan, with no credit card and no commitment
Cons
- No price is published anywhere, so the product cannot be evaluated without a sales conversation
- Annual subscriptions only, paid in a single instalment
- No public API and no developer documentation, and no mobile application either
- ISO 27001 is only in progress; the publisher currently holds no certification
- A very young and very small publisher: incorporated in April 2025, EUR 1 of capital, a single director
- The privacy policy quotes an Estonian registry code that matches no company in the register
- Interface languages are advertised as multiple but never listed, and the free plan covers only the Trust Center
Pricing & Plans
Whisperly publishes no price. A permanent free plan exists, limited to the public Trust Center, and requires no credit card. Beyond it, three tiers are listed for Privacy Automation — Core, Advanced and Enterprise — with feature tables but no amount attached to any of them, and no figure appears in the page source either. All plans are sold as annual subscriptions paid once a year, priced by number of legal entities rather than by headcount, with unlimited users and storage throughout. Vendor Assessment is an add-on and multi-product bundles are quoted individually, so the entry ticket can only be obtained by booking a demo.
- public trust page
- policy and document publishing
- no credit card
- access approved after an internal audit
- core data protection features
- AI chatbot
- task management and comments
- SharePoint and Google Drive integration
- SSO
- Advanced Trust Center
- 300 AI credits per month
- everything in Core plus AI agents
- multilingual platform
- DSAR
- AI internal audit
- breach registry
- document templates and priority support
- 1000 AI credits per month
- Enterprise — everything in Advanced plus dedicated onboarding
- custom SLA and DPA
- custom AI credits and a dedicated Customer Success Manager
- Vendor Assessment add-on and custom multi-product bundles
- quoted on request
Data, GDPR & hosting
A consolidated view of how Whisperly handles your data.
GDPR overview
GDPR implementation is documented in unusual detail, which is expected from a vendor selling compliance. Lexelerate OÜ acts as controller for the website and as processor for the platform. A full Data Processing Agreement is published openly and included for every customer, alongside general terms, SaaS terms and a privacy notice that tabulates each purpose, its legal basis under Article 6 and its retention period. Data subject rights are exercised through office@lexelerate.ai with a stated 30-day response, and the right to complain to a supervisory authority is spelled out. The vendor's own trust page marks GDPR, UK GDPR and CCPA as compliant, and a product FAQ states plainly that Whisperly is fully GDPR compliant. No Article 27 representative is named, which is consistent with an EU-established company, and no data protection officer is identified.
Who owns the data?
Customers keep ownership of everything they put into the platform. The SaaS terms state that, as between the parties, the customer retains all rights in its Customer Content, and grants Lexelerate only a non-exclusive licence to host, process and use that content for the sole purpose of delivering and supporting the service. Lexelerate takes on no monitoring duty and says it does not monitor content. Under the GDPR the customer acts as controller and Lexelerate as processor. On termination the customer keeps a seven-day window to access, download and export its content in a machine-readable format at no extra charge, after which Lexelerate may delete it.
Reuse rights
Customers may reuse their own content freely: they own it, they decide its scope and categories, and they can export it in a commonly used machine-readable format during the seven days that follow the end of the contract, without paying anything extra and without asking permission. Lexelerate's own use is deliberately narrow. It may host, process and use the content only to provide and support the service. The SaaS terms and the general terms both state that Customer Content will not be used to train Lexelerate's or any third party's general AI models without the customer's prior consent, which makes training an opt-in rather than something to withdraw from. Named subprocessors may process data on Whisperly's behalf: Pydantic Services UK, Qdrant Solutions, Mistral AI, Sentry and AWS. Transfers outside the EU rely on standard contractual clauses, an adequacy decision or the EU-U.S. Data Privacy Framework.
Data retention & training
Hosting summary
The service is delivered exclusively from the cloud on Amazon Web Services, and the publisher states it operates no production data centres of its own. Customer personal data is hosted in AWS data centres located within the European Union unless something else is agreed in writing, and the trust page records Germany as the hosting country for AWS. Four other subprocessors are named with their own locations: Pydantic Services UK in the United Kingdom, Qdrant Solutions in Germany, Mistral AI in France and Sentry in Germany. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys managed through AWS KMS under restricted and logged access. The Data Processing Agreement sets out the cloud shared responsibility model explicitly, and any transfer outside the European Union relies on the 2021/914 standard contractual clauses, an adequacy decision or the EU-U.S. Data Privacy Framework. The publisher is established in Estonia and the contracts are governed by Estonian law.
Things to keep in mind
Risks and trade-offs to weigh before adopting Whisperly.
- Verify the publisher's legal identity before contracting: the privacy policy quotes Estonian registry code 16978857, which matches no company, while the real Lexelerate OÜ code is 17224471
- Weigh supplier concentration risk: the company was incorporated in April 2025 with EUR 1 of capital, one director and one beneficial owner, for a tool that would hold your entire compliance record
- Do not read the ISO 27001 and SOC 2 badges on the product pages as the vendor's own; they illustrate what a customer publishes, and Whisperly's ISO 27001 is only in progress
- Automating compliance can erode the team's own understanding of its obligations: agents draft, but accountability under the GDPR and the EU AI Act stays with your organisation
- Treat AI-generated answers to questionnaires, DPIAs and policies as drafts; the terms state output is for information and decision support only and may be incomplete or inaccurate
- Budget cannot be estimated in advance since no price is published, and the commitment is a full year paid up front
- Read-only connectors reach into identity, cloud, spend and code systems, so scope and approve them carefully before granting access
Setup & Integrations
Technical difficulty
Low for the customer's technical staff. The free Trust Center is advertised as requiring no engineering and is set up self-service, with access granted after an internal review. A full deployment is guided rather than self-installed: three to four weeks from kick-off to go-live, with a named migration engineer, automated import of existing RoPA, DPIAs, vendor lists and policy templates, and weekly progress updates. The main technical task on the customer side is authorising read-only connectors to Google Workspace, Microsoft 365, Okta or Entra ID and cloud accounts. SSO with Google and Microsoft is included on every plan.
Deployment
Integrations
Supported languages
Behind Whisperly
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
How much does Whisperly cost?
Is pricing charged per user?
Is there a free plan?
Which regulations does Whisperly cover?
Is Whisperly itself ISO 27001 certified?
Where is customer data hosted?
Is customer content used to train AI models?
Does Whisperly offer an API?
Who is behind Whisperly?
How long does it take to get started?
Should you pick Whisperly?
Whisperly is a coherent attempt to fold five compliance disciplines — privacy records, AI governance, vendor risk, questionnaire answering and public trust publishing — into a single workspace, and to hand the repetitive parts to agents. On documentation it performs better than most tools of its age: the Data Processing Agreement is published in full rather than promised on request, the subprocessor list names each provider with its hosting country, hosting is committed to EU AWS regions, and the contract states that customer content will not train AI models without prior consent. Billing per legal entity with unlimited users is a genuinely unusual commercial choice that favours small teams with complex structures.
The reservations are mostly about maturity and transparency of a different kind. No price is published anywhere, so nobody can size the tool without a sales call. The publisher, Lexelerate OÜ, was registered in Tallinn in April 2025 with EUR 1 of capital, one director and a first partial year turnover of about EUR 13,550 — a very small counterparty for software that sits at the centre of a compliance programme. It holds no certification: ISO 27001 is explicitly in progress, and the ISO and SOC badges seen on the product pages describe the customer's posture, not Whisperly's. One factual defect deserves correction by the vendor: the privacy policy publishes an Estonian registry code that matches no company.
For an organisation that needs EU and UK coverage, values documented data handling and can accept a young supplier, Whisperly is worth the demo. For buyers who need published pricing, an API, or a certified vendor today, it is not there yet.
- Choosing a selection results in a full page refresh.
- Opens in a new window.