Whisperly logo
Data Governance Quality · Privacy Security

Whisperly

Whisperly is an AI-driven GRC platform from Estonian publisher Lexelerate OÜ. It bundles privacy records, EU AI Act governance, vendor assessments, questionnaire answering and a public trust page into one workspace for compliance, security and legal teams.

Active GDPR compliant Free plan Contact Sales No public API 18+ Verified by Guidaio
Overview

What is Whisperly?

Whisperly is a governance, risk and compliance platform built around the idea that most compliance work is routine enough to be delegated to software agents. Its pitch is a direct attack on incumbent tools: legacy compliance suites assume a human copies records, chases vendors and formats reports by hand, whereas Whisperly's agents run that work and leave people the judgment calls. The workflow is presented in three movements — discover and document, score and classify, then monitor and report.

The platform bundles five connected solutions that can be adopted separately. Data Privacy covers records of processing activities, data protection impact assessments, data subject access requests, a breach register and a register of DPAs. AI Governance builds an inventory of every AI system in use and classifies its risk under the EU AI Act, ISO 42001 and NIST, including Annex III screening and technical documentation. Vendor Assessment sends structured questionnaires to suppliers and scores the replies automatically. RFP Automation drafts answers to security questionnaires such as SIG, CAIQ and HECVAT from an approved knowledge base. Trust Center publishes a branded public page where prospects can self-serve policies and certification badges.

Discovery leans on read-only connectors into Google Workspace, Microsoft 365, Okta or Entra ID, AWS and Azure accounts, SaaS spend and code repositories, which is how the tool claims to surface shadow AI nobody registered. Groups are handled through multiple legal entities, each keeping its own register and posture. Three segments are addressed explicitly — startups, mid-market and enterprise — plus consultants and law firms. Several free public utilities sit alongside the product, including an EU AI Act compliance checker, a DPO requirement checker and an EU representative checker.

The publisher is Lexelerate OÜ, registered in Tallinn on 21 April 2025, and presents itself as founded by data and AI lawyers and information security leaders. Customers named on its trust page include Bloomberg Adria, Lesnina XXXL and BMTS Technology.

What it does

  • Map AI systems, processing activities and vendors automatically, then generate the records each framework requires
  • Classify risk against the EU AI Act, the GDPR and internal criteria, flagging gaps and attaching evidence
  • Produce and export audit-ready reports and registers at any moment, including RoPA and DPIAs
  • Send structured vendor assessments, score the answers automatically and surface gaps before signature
  • Draft answers to RFPs and security questionnaires from an approved internal knowledge base
  • Publish a branded public trust page with badges, policies and NDA-gated documents
  • Trigger a re-assessment whenever something changes, and notify subscribed clients in one click
Audience

When to use Whisperly / When not to

A quick filter to help you decide if Whisperly is the right fit.

When to use Whisperly

  • Compliance and privacy teams that must keep RoPA, DPIAs, DSARs and a breach register continuously up to date
  • Organisations preparing for the EU AI Act or ISO 42001 and needing an inventory of every AI system in use
  • Security and pre-sales teams drowning in security questionnaires, RFPs and repeated buyer due diligence
  • Groups with several subsidiaries, since workspaces and billing are organised per legal entity rather than per user
  • Startups and consultancies that need to look audit-ready quickly in order to unlock enterprise deals

When not to use Whisperly

  • Buyers who need a published price before talking to a salesperson, since no amount appears anywhere on the site
  • Teams looking for a developer platform: there is no public API and no developer documentation
  • Anyone expecting a mobile application, as the product ships only as a browser workspace
  • Organisations that require their vendor to already hold ISO 27001 or SOC 2, which Whisperly does not yet have
  • Buyers who want to pay monthly, because every plan is sold as a one-off annual subscription
Get started

How to use Whisperly

A typical end-to-end flow, from setup to results.

  1. Decide which of the five solutions you need first, since each can be adopted on its own
  2. Book the 30-minute demo, which is the main entry point and the only way to obtain a price
  3. Alternatively, sign up self-service for the free Trust Center, with no credit card required
  4. Wait for the team to approve free Trust Center access, which follows an internal audit
  5. For a migration from another GRC tool, attend the day-one kick-off call mapping data, scope and integrations
  6. Let the team import existing RoPA, consent records, vendor lists, DPIAs and policy templates, with no manual re-entry
  7. Authorise the read-only connectors so the discovery agent can inventory AI systems across your stack
  8. Review every imported record, configure workflows and run the compliance gap check
  9. Enable SSO through Google or Microsoft, which is included on every plan
  10. Confirm go-live, at which point the subscription and billing start
Quick read

Pros & Cons

Pros

  • Five compliance modules on one platform, adoptable separately as needs grow
  • Unlimited users and storage on every tier, with billing per legal entity rather than per seat
  • Data hosted in EU AWS data centres, encrypted with AES-256 at rest and TLS 1.2 or higher in transit
  • A complete Data Processing Agreement published openly and included for all customers
  • A published subprocessor list giving each provider's category and hosting country
  • A contractual commitment not to train AI models on customer content without prior consent
  • A genuinely permanent free Trust Center plan, with no credit card and no commitment

Cons

  • No price is published anywhere, so the product cannot be evaluated without a sales conversation
  • Annual subscriptions only, paid in a single instalment
  • No public API and no developer documentation, and no mobile application either
  • ISO 27001 is only in progress; the publisher currently holds no certification
  • A very young and very small publisher: incorporated in April 2025, EUR 1 of capital, a single director
  • The privacy policy quotes an Estonian registry code that matches no company in the register
  • Interface languages are advertised as multiple but never listed, and the free plan covers only the Trust Center
Pricing

Pricing & Plans

Whisperly publishes no price. A permanent free plan exists, limited to the public Trust Center, and requires no credit card. Beyond it, three tiers are listed for Privacy Automation — Core, Advanced and Enterprise — with feature tables but no amount attached to any of them, and no figure appears in the page source either. All plans are sold as annual subscriptions paid once a year, priced by number of legal entities rather than by headcount, with unlimited users and storage throughout. Vendor Assessment is an add-on and multi-product bundles are quoted individually, so the entry ticket can only be obtained by booking a demo.

Free Trust Center — permanent free plan
  • public trust page
  • policy and document publishing
  • no credit card
  • access approved after an internal audit
Advanced (Most Popular) — for larger organisations
  • everything in Core plus AI agents
  • multilingual platform
  • DSAR
  • AI internal audit
  • breach registry
  • document templates and priority support
  • 1000 AI credits per month
Plan 4
  • Enterprise — everything in Advanced plus dedicated onboarding
  • custom SLA and DPA
  • custom AI credits and a dedicated Customer Success Manager
Plan 5
  • Vendor Assessment add-on and custom multi-product bundles
  • quoted on request
Special offers — Free Trust Center: a permanent free plan with no credit card and no commitment · Migration offer: no charge until you go live, for up to 30 days, when switching from another GRC tool · Billing starts only once the customer confirms the migration is complete · No implementation fees and no per-seat costs on any plan
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Whisperly handles your data.

GDPR overview

GDPR implementation is documented in unusual detail, which is expected from a vendor selling compliance. Lexelerate OÜ acts as controller for the website and as processor for the platform. A full Data Processing Agreement is published openly and included for every customer, alongside general terms, SaaS terms and a privacy notice that tabulates each purpose, its legal basis under Article 6 and its retention period. Data subject rights are exercised through office@lexelerate.ai with a stated 30-day response, and the right to complain to a supervisory authority is spelled out. The vendor's own trust page marks GDPR, UK GDPR and CCPA as compliant, and a product FAQ states plainly that Whisperly is fully GDPR compliant. No Article 27 representative is named, which is consistent with an EU-established company, and no data protection officer is identified.

Who owns the data?

Customers keep ownership of everything they put into the platform. The SaaS terms state that, as between the parties, the customer retains all rights in its Customer Content, and grants Lexelerate only a non-exclusive licence to host, process and use that content for the sole purpose of delivering and supporting the service. Lexelerate takes on no monitoring duty and says it does not monitor content. Under the GDPR the customer acts as controller and Lexelerate as processor. On termination the customer keeps a seven-day window to access, download and export its content in a machine-readable format at no extra charge, after which Lexelerate may delete it.

Reuse rights

Customers may reuse their own content freely: they own it, they decide its scope and categories, and they can export it in a commonly used machine-readable format during the seven days that follow the end of the contract, without paying anything extra and without asking permission. Lexelerate's own use is deliberately narrow. It may host, process and use the content only to provide and support the service. The SaaS terms and the general terms both state that Customer Content will not be used to train Lexelerate's or any third party's general AI models without the customer's prior consent, which makes training an opt-in rather than something to withdraw from. Named subprocessors may process data on Whisperly's behalf: Pydantic Services UK, Qdrant Solutions, Mistral AI, Sentry and AWS. Transfers outside the EU rely on standard contractual clauses, an adequacy decision or the EU-U.S. Data Privacy Framework.

Data retention & training

Retention summary
Platform data is kept for the duration of the subscription. When the contract ends, Lexelerate deletes or returns personal data under the DPA, and customers get a seven-day window to export their content in a machine-readable format free of charge before deletion. Retention controls are configurable by the customer. On the website side the rules are shorter: contact enquiries are deleted 30 days after the reply, data collected on consent is deleted when consent is withdrawn and no later than 30 days after collection, and some records are kept for at most 12 months. Security logs are held up to two months, longer only during an active investigation, and cookies or session data up to one year. The vendor states deletion uses approved methods that prevent recovery, with regular audits of retention schedules.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

The service is delivered exclusively from the cloud on Amazon Web Services, and the publisher states it operates no production data centres of its own. Customer personal data is hosted in AWS data centres located within the European Union unless something else is agreed in writing, and the trust page records Germany as the hosting country for AWS. Four other subprocessors are named with their own locations: Pydantic Services UK in the United Kingdom, Qdrant Solutions in Germany, Mistral AI in France and Sentry in Germany. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys managed through AWS KMS under restricted and logged access. The Data Processing Agreement sets out the cloud shared responsibility model explicitly, and any transfer outside the European Union relies on the 2021/914 standard contractual clauses, an adequacy decision or the EU-U.S. Data Privacy Framework. The publisher is established in Estonia and the contracts are governed by Estonian law.

Hosting countries
🇩🇩 Germany
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Whisperly.

  • Verify the publisher's legal identity before contracting: the privacy policy quotes Estonian registry code 16978857, which matches no company, while the real Lexelerate OÜ code is 17224471
  • Weigh supplier concentration risk: the company was incorporated in April 2025 with EUR 1 of capital, one director and one beneficial owner, for a tool that would hold your entire compliance record
  • Do not read the ISO 27001 and SOC 2 badges on the product pages as the vendor's own; they illustrate what a customer publishes, and Whisperly's ISO 27001 is only in progress
  • Automating compliance can erode the team's own understanding of its obligations: agents draft, but accountability under the GDPR and the EU AI Act stays with your organisation
  • Treat AI-generated answers to questionnaires, DPIAs and policies as drafts; the terms state output is for information and decision support only and may be incomplete or inaccurate
  • Budget cannot be estimated in advance since no price is published, and the commitment is a full year paid up front
  • Read-only connectors reach into identity, cloud, spend and code systems, so scope and approve them carefully before granting access
Setup

Setup & Integrations

Technical difficulty

Low for the customer's technical staff. The free Trust Center is advertised as requiring no engineering and is set up self-service, with access granted after an internal review. A full deployment is guided rather than self-installed: three to four weeks from kick-off to go-live, with a named migration engineer, automated import of existing RoPA, DPIAs, vendor lists and policy templates, and weekly progress updates. The main technical task on the customer side is authorising read-only connectors to Google Workspace, Microsoft 365, Okta or Entra ID and cloud accounts. SSO with Google and Microsoft is included on every plan.

Deployment

Web app

Integrations

SharePoint Google Drive Google Workspace Microsoft 365 Okta Microsoft Entra ID Amazon Web Services Microsoft Azure

Supported languages

English
Company

Behind Whisperly

Company name
Lexelerate OÜ
Founded
21/04/2025
Country of origin
🇪🇪 Estonia
Headquarters
Sepapaja 6, Lasnamäe District, Tallinn, Harju County, 15551, Estonia
UBO
Tijana Žunić Marić
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

How much does Whisperly cost?
No amount is published. The pricing page lists Core, Advanced and Enterprise tiers with their features but attaches no figure to any of them, and no price appears in the page source. You have to book a demo to get a quote.
Is pricing charged per user?
No. Every plan includes unlimited users and unlimited storage, and pricing is based on the number of legal entities rather than headcount. A legal entity is a subsidiary or a distinct department needing its own compliance workspace; most standalone companies need only one.
Is there a free plan?
Yes, and it is permanent rather than a trial. The free Trust Center lets you publish a public trust page with no credit card and no commitment; you upgrade only when you need advanced access controls. The privacy and AI governance modules are not included.
Which regulations does Whisperly cover?
The GDPR and UK GDPR for privacy, the EU AI Act and ISO 42001 for AI governance, with NIST also referenced. The Trust Center can additionally display SOC 2 and ISO 27001 badges that belong to your own organisation.
Is Whisperly itself ISO 27001 certified?
Not yet. Its own trust page marks ISO 27001 as in progress, with an update dated 4 May 2026 announcing the start of the ISMS certification journey. GDPR, UK GDPR and CCPA are marked as compliant, which is a self-declaration rather than a certification.
Where is customer data hosted?
Exclusively on Amazon Web Services, in data centres located within the European Union unless otherwise agreed in writing. The publisher operates no data centres of its own and lists AWS with Germany as its hosting country on the trust page.
Is customer content used to train AI models?
Not without prior consent. Both the SaaS terms and the general terms state that Customer Content will not be used to train Lexelerate's or any third party's general AI models unless the customer agrees, making training opt-in.
Does Whisperly offer an API?
No public API or developer documentation could be found. There is no api or docs subdomain, the API paths return real 404s, and neither the sitemap nor the llms.txt file lists any developer reference.
Who is behind Whisperly?
Lexelerate OÜ, a private limited company registered in Tallinn, Estonia on 21 April 2025, at Sepapaja 6. Note that the privacy policy quotes registry code 16978857, which matches no company in the Estonian register; the real code is 17224471.
How long does it take to get started?
The free Trust Center is self-service. A full migration from another GRC tool is described as three to four weeks, from a day-one kick-off call to go-live, guided by a named migration engineer, with no billing until the customer confirms.
Conclusion

Should you pick Whisperly?

Whisperly is a coherent attempt to fold five compliance disciplines — privacy records, AI governance, vendor risk, questionnaire answering and public trust publishing — into a single workspace, and to hand the repetitive parts to agents. On documentation it performs better than most tools of its age: the Data Processing Agreement is published in full rather than promised on request, the subprocessor list names each provider with its hosting country, hosting is committed to EU AWS regions, and the contract states that customer content will not train AI models without prior consent. Billing per legal entity with unlimited users is a genuinely unusual commercial choice that favours small teams with complex structures.

The reservations are mostly about maturity and transparency of a different kind. No price is published anywhere, so nobody can size the tool without a sales call. The publisher, Lexelerate OÜ, was registered in Tallinn in April 2025 with EUR 1 of capital, one director and a first partial year turnover of about EUR 13,550 — a very small counterparty for software that sits at the centre of a compliance programme. It holds no certification: ISO 27001 is explicitly in progress, and the ISO and SOC badges seen on the product pages describe the customer's posture, not Whisperly's. One factual defect deserves correction by the vendor: the privacy policy publishes an Estonian registry code that matches no company.

For an organisation that needs EU and UK coverage, values documented data handling and can accept a young supplier, Whisperly is worth the demo. For buyers who need published pricing, an API, or a certified vendor today, it is not there yet.