Acuna logo
Privacy Security · Gov Legal

Acuna

Swiss governance, risk and compliance platform covering more than 50 frameworks in one subscription. It maps each requirement once, ties controls to named owners and evidence, adds third-party risk and privacy operations, and prices per organisation rather than per seat.

Active GDPR compliant Subscription API available Verified by Guidaio
Overview

What is Acuna?

Acuna is a governance, risk and compliance platform built and operated by Abilene Group SA, a Swiss GRC group based in Morges. It addresses organisations that already run several regulatory programmes at once rather than teams chasing a first certification, and the vendor states this plainly: its own documentation names Vanta, Drata and Sprinto as the better choice for a startup pursuing an initial SOC 2.

The platform is organised around four included panes. Comply models entities, boundaries and applicability, then structures each requirement and maps it to scope, controls and owners. Implement turns those requirements into controls with attached measures, named owners and recurring checks. Operate runs the daily rhythm of tasks, remediation and due dates. Assure prepares assurance packs, monitors findings and drives continuous improvement cycles. More than fifty frameworks ship pre-loaded with no per-framework fee, among them ISO 27001, ISO 42001, SOC 2, GDPR, FADP, NIS2, DORA, the Cyber Resilience Act, the EU AI Act and ISO 9001, and custom frameworks can be imported as YAML or CSV. A requirement is mapped once and reused everywhere it applies.

Modules extend that core. Supplier Shield handles third-party risk through automated open-source intelligence across DNS, TLS, web headers, breach exposure and reputation, producing composite grades from A to F and continuous monitoring. Data Privacy Management covers records of processing, DPIA, DSAR, breach handling and the generation of processing agreements and transfer impact assessments. A D&B Credit Score module adds supplier financial health from Dun & Bradstreet data.

Aiko+ is the AI layer. It answers plain-language questions from the customer's own records and tags the module each answer came from, proposes first-pass supplier evaluations and cross-framework control mappings, and attaches a confidence score to every suggestion for a human to confirm or override. It respects each user's existing permissions, answers questions on data subject requests and breaches from metadata alone, and can be switched off across the whole organisation with one toggle.

Pricing is per organisation rather than per seat: a single subscription covers all users and all frameworks, from CHF 5,388 a year, invoiced annually. Access is browser-based, in English and French.

What it does

  • Map a requirement once and reuse it across more than 50 frameworks, without duplicating the work
  • Tie every control to a named owner, to its evidence and to a recurring cadence
  • Track compliance health in real time by framework, domain, control set and operating unit
  • Assess and monitor suppliers automatically, with A-to-F grades built from DNS, TLS, header, breach and reputation signals
  • Run privacy operations end to end: records of processing, DPIA, DSAR, breach handling and DPA generation
  • Ask the built-in assistant a question in plain language and get an answer drawn from your own live data
  • Prepare assurance packs and monitor findings continuously instead of scrambling before each audit
Audience

When to use Acuna / When not to

A quick filter to help you decide if Acuna is the right fit.

When to use Acuna

  • Compliance leaders running several frameworks at once, for example ISO 9001 and GDPR in a single operating rhythm
  • Security leaders steering ISO 27001, SOC 2 and NIS2 who need one source of truth across security and compliance obligations
  • Data protection officers handling records of processing, DPIA, DSAR and breach workflows alongside the wider control set
  • Regulated mid-market organisations in the EU and Switzerland, roughly 200 to 5,000 employees, with data residency requirements
  • MSSPs and consulting firms delivering repeatable compliance work across multiple client tenants, with white labelling and mass deployment

When not to use Acuna

  • Cloud-native startups chasing a first SOC 2 quickly and cheaply, a case the vendor itself sends to Vanta, Drata or Sprinto
  • Organisations with no European or Swiss data residency requirement, who pay for a differentiator they will never use
  • Small teams and solo practitioners, since the published entry ticket is CHF 5,388 per year with no free plan or trial
  • Buyers who want to sign up and evaluate on their own, as every path runs through a demo request and a sales conversation
  • Teams needing a mobile app or an interface beyond English and French
Get started

How to use Acuna

A typical end-to-end flow, from setup to results.

  1. Request a demo from the contact page, giving your name, work email, company and the problem you are trying to solve
  2. Expect a reply within one business day and a 30-minute call scoped to your compliance programme
  3. Agree the subscription plan and any optional modules, then sign the order form to which the processing agreement is annexed
  4. Go through guided onboarding to stand up your scope, controls and operating cadence
  5. Model your entities, boundaries and applicability in the Comply pane so each requirement lands in the right place
  6. Load the frameworks you need from the catalogue, or import a custom one as YAML or CSV
  7. Map requirements to controls once, and let the mapping be reused across every framework that shares them
  8. Assign each control to a named owner, attach its measures and evidence, and set its recurring checks
  9. Run the programme day to day in the Operate pane, tracking tasks, remediation and due dates
  10. Use the Assure pane to prepare assurance packs and monitor findings, and ask Aiko for answers, mappings or supplier evaluations along the way
Quick read

Pros & Cons

Pros

  • One price for the whole organisation, with no per-seat fee: owners, reviewers and auditors can all be given access without inflating the invoice
  • An entry price published openly in a market where competitors routinely hide theirs
  • More than 50 frameworks included with no per-framework charge, so adding a regulation costs work rather than money
  • Terms, privacy policy and a complete data processing agreement are published in full, with no login required
  • Data hosting committed to Switzerland in the processing agreement, with the hosting subprocessor named rather than left vague
  • The AI is designed to stay under human control: confidence scores, mandatory human confirmation, permission awareness and an organisation-wide off switch
  • The vendor publishes an explicit not-a-fit profile and names competitors that suit those buyers better, which is unusually candid

Cons

  • ISO 27001 and SOC 2 appear only as badges: no certificate number, certification body, scope or validity date is published anywhere on the site
  • The trust centre said to hold that evidence sits behind a manually reviewed access request, and the navigation still labels it as coming soon
  • The privacy policy is weaker than the badges, describing an information security management system that is operated, and attributing it to a sister brand rather than the contracting entity
  • Hosting statements conflict: marketing says Switzerland and the EU, the processing agreement says Switzerland exclusively, the privacy policy allows transfers abroad
  • Several advertised modules are marked as coming soon, including AI governance, enterprise risk management, business continuity and the trust centre itself
  • No free plan, no free trial and no self-service signup, so evaluation always requires a sales conversation
  • The vendor never states whether customer data is used to train AI models, while the terms grant a perpetual licence to process that data to improve the service
Pricing

Pricing & Plans

There is no free plan and no free trial. The lowest published price point is the Professional plan, which starts at CHF 5,388 per year and is invoiced annually. Regional equivalents are published for other markets, from EUR 4,999 per year in the European Union and USD 7,999 per year elsewhere. The price covers the entire organisation rather than a number of seats, and includes all users, the four panes and the full framework catalogue. Optional modules are charged in addition, and the Enterprise and MSSP tiers are quoted on request.

Professional - from CHF 5,388 per year (EUR 4,999 per year in the EU, USD 7,999 per year elsewhere)
  • unlimited frameworks
  • custom dashboards
  • integrated KPI and custom reports
  • connectors and API
  • full AI support
MSSP - price on request
  • all Professional features plus white labelling
  • tenant management
  • deployment bundles
  • fully customisable templates with mass deployment and centralised audit
Plan 4
Non-profit and Academic
  • custom discounted rates on request for registered non-profits
  • international NGOs and accredited academic or research institutions
Optional modules charged in addition
  • Supplier Shield TPRM
  • Business Continuity and Crisis Management
  • Enterprise Risk Management
  • Data Protection
Special offers — Discounted rates for registered non-profit organisations and 501(c)(3) equivalents, international NGOs such as UN agencies, the ICRC or Gavi, and accredited universities and research institutions; eligibility is confirmed on request, usually with a registration document or a .edu or .ac domain, with a reply within 48 hours and no commitment · A dedicated MSSP partner tier for companies managing several clients, adding white labelling, tenant management, deployment bundles and mass-deployment templates
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Acuna handles your data.

GDPR overview

Implementation is documented rather than merely claimed. Abilene Group SA states it is subject to the Swiss FADP and, where applicable, the GDPR, and publishes a full data processing agreement in which it acts as processor and the customer as controller. A data protection officer is named, Henri Haenni, reachable at privacy@abileneadvisors.ch. Data subject rights are listed explicitly: access, correction, deletion, restriction, portability, objection and withdrawal of consent, plus the right to complain to a supervisory authority. Technical and organisational measures are itemised in article 7 of the agreement. Two gaps remain. No representative under article 27 is designated, although the vendor is established outside the European Union. And the documents disagree on transfers: the agreement rules out any processing outside Switzerland, while the privacy policy contemplates transfers abroad with a preference for EEA locations.

Who owns the data?

The customer keeps ownership. Section 6.2 of the terms states that all data submitted, transmitted, generated or stored by the customer, its authorised users and third-party users remains theirs, intellectual property included, and that the vendor acquires no rights beyond those expressly granted. Those granted rights are broad, however: the customer gives Abilene Group SA a non-exclusive, worldwide, perpetual, irrevocable and royalty-free licence, with the right to sublicense, to use, store, reproduce, distribute and display customer data in order to deliver the service and to maintain, support and improve it. Processing under that licence may be automated or manual. Conversely, the platform itself stays the vendor's property under a limited, non-transferable user licence.

Reuse rights

Customer data can be reused freely by the customer, who never gives up ownership of it: a copy can be downloaded from the platform on request, and nothing in the terms restricts what an organisation does with its own records, exports or reports afterwards. The restrictions run the other way, over the product. The licence to the service is personal, non-transferable, non-assignable and non-exclusive, limited to internal business purposes, to the term of the agreement and to the number of authorised users in the subscription plan. Reverse engineering, data scraping and any attempt to bypass technical restrictions are expressly prohibited, in particular through the API. One asymmetry deserves attention: the licence the customer grants the vendor over its own data is perpetual and irrevocable, and it covers improving the product, without the vendor ever stating whether that improvement includes training AI models.

Data retention & training

Retention summary
No numeric retention period is published. The privacy policy says retention depends on the type of data and its legal basis, covering contractual, accounting, evidential and security obligations, and that personal data is kept only as long as required for legal, contractual and governance purposes before being deleted or de-identified. The terms are blunter about the platform itself: the customer may download a copy of its data on request, but is solely responsible for conserving it and keeping a backup, deletion on the platform is definitive, and account access is blocked once the subscription term ends. The vendor gives no warranty on long-term availability or integrity, and may retain data where law requires or permits. Cookie lifetimes are the only precise figures: twelve months for the consent cookie and one hour for the pricing region cookie.
Trains on customer data
Unclear
Subprocessors disclosed
Yes
DPA available
Yes

Hosting summary

The data processing agreement is the most precise source and the most restrictive. It states that all personal data is hosted and processed exclusively within Swiss territory, that the platform runs on cloud infrastructure located in Switzerland, and that no cross-border transfer is intended or authorised without the controller's prior written consent. A single subprocessor is disclosed: Supabase, in the eu-central-2 region in Zurich, for hosting, storage and availability. Any addition or replacement of a subprocessor requires prior written notice, and the terms give the customer a right of reasoned objection. Security measures are itemised, covering role-based access, least privilege, encryption in transit and at rest, backups, redundancy, incident response and logical segregation of client data. Note two caveats. Marketing pages describe residency more loosely as Switzerland and the EU, and the privacy policy allows transfers outside Switzerland with a preference for EEA locations. Separately, the public marketing website itself runs on a United States content delivery edge, which says nothing about where platform data lives.

Hosting countries
🇨🇭 Switzerland
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Acuna.

  • Unverified security claims: ISO 27001 and SOC 2 are shown as badges with no certificate number, body, scope or validity date, and the strips mix them with individual credentials held by team members, which is not the same as certifying the company. Ask for the attestation itself.
  • Over-reliance on the assistant: Aiko proposes control mappings and supplier evaluations with a confidence score, and a rushed team can start approving suggestions without reading them, turning a first-pass aid into an unexamined decision and eroding the reviewer's own judgement.
  • Data licence asymmetry: the customer keeps ownership, but grants the vendor a perpetual, irrevocable, worldwide and sublicensable licence to process that data to improve the service, with no statement anywhere on whether improvement includes training AI models.
  • Backup responsibility sits with the customer: the terms state that deletion on the platform is definitive, that the vendor gives no warranty on long-term availability or integrity, and that account access is blocked at the end of the subscription, so exporting before an exit is entirely the customer's job.
  • Conflicting hosting statements: marketing promises Switzerland and the EU, the processing agreement promises Switzerland exclusively, and the privacy policy allows transfers abroad, so residency should be confirmed in writing rather than assumed from the website.
  • Roadmap risk: several modules presented in the navigation, including AI governance, enterprise risk management, business continuity and the trust centre, are marked as coming soon and cannot be counted on when scoping a programme today.
  • A compliance tool can create false comfort: a dashboard showing controls as green measures what has been recorded in the platform, not what is actually operating in the organisation, and audit readiness still depends on the honesty of the people entering the evidence.
Setup

Setup & Integrations

Technical difficulty

Technically light, organisationally demanding. The platform is browser-based with nothing to install, and onboarding is guided, with the vendor claiming first value within the first hour. The real effort is programme modelling: defining scope and entities, loading frameworks, mapping requirements to controls and assigning named owners. That work needs someone who knows the compliance programme, not an engineer. The vendor sells configuration and advisory services separately, which suggests larger deployments are assisted. API integration and custom YAML or CSV framework imports are the customer's responsibility and do require technical skills.

Deployment

Web appAPI

Integrations

Dun & Bradstreet

Supported languages

EnglishFrench
Company

Behind Acuna

Company name
Abilene Group SA
Founded
02/12/2015
Country of origin
🇨🇭 Switzerland
Headquarters
Rue de la Gare 39, 1110 Morges, Switzerland
UBO
Henri Haenni
UBO country
🇨🇭 Switzerland
Domain registrar country
🇨🇭 Switzerland
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Acuna.

D DrataV VantaO OneTrustS Swiss GRCS SecureframeS SprintoH Hyperproof
FAQ

Frequently asked questions

What exactly is Acuna?
A governance, risk and compliance platform built and operated by Abilene Group SA in Morges, Switzerland. It organises a compliance programme around four panes, Comply, Implement, Operate and Assure, and ships with more than 50 frameworks pre-loaded.
How is Acuna priced?
Per organisation rather than per seat. A single subscription covers all users and every framework. The Professional plan starts at CHF 5,388 per year with annual invoicing, or EUR 4,999 in the European Union and USD 7,999 elsewhere. Enterprise and MSSP tiers are quoted on request.
Is there a free plan or a free trial?
Neither is published. Access begins with a demo request handled directly by the vendor's team, who reply within one business day and schedule a 30-minute scoping call.
Where is the data hosted?
The data processing agreement states that personal data is hosted and processed exclusively in Switzerland, on Supabase infrastructure in the eu-central-2 region in Zurich, with no cross-border transfer without the customer's prior written consent. Marketing pages describe residency more loosely as Switzerland and the EU.
Which frameworks does it cover?
More than 50 with no per-framework fee, including ISO 27001, ISO 42001, SOC 2, GDPR, FADP, NIS2, DORA, the Cyber Resilience Act, the EU AI Act and ISO 9001. Custom frameworks can be imported as YAML or CSV.
What does the AI assistant actually do?
Aiko+ answers questions from your own records and tags the module each answer came from, proposes first-pass supplier evaluations and cross-framework control mappings, and attaches a confidence score to each suggestion. A human confirms or overrides every one, and the assistant can be switched off across the organisation.
Is a data processing agreement available?
Yes. The full agreement is published on the site as an annex to the order form, with Abilene Group SA acting as processor. Legal questions go to legal@abilenegroup.ch.
Does Acuna offer an API?
Yes. Connectors and an API are included in the Professional plan, and the terms devote a full section to API access and integration. No public API documentation is published, however, so the technical details have to be obtained from the vendor.
Is Acuna certified to ISO 27001 or SOC 2?
The site displays both as badges but publishes no certificate number, certification body, scope or validity date. The privacy policy only says an information security management system is operated, and attributes it to Abilene Advisors rather than to the contracting entity. Ask for the attestation through the trust centre before relying on either claim.
Which languages does the interface support?
English and French. Both are served across the whole site and the vendor confirms the pair in its own reference documentation.
Conclusion

Should you pick Acuna?

Acuna occupies a narrow position and occupies it deliberately. It is aimed at European and Swiss organisations that already run several regulatory programmes and want one place to map requirements, own controls and hold evidence, priced for the whole organisation rather than per seat. On that ground the offer is coherent: an entry price published openly, every framework included, complete legal documentation available without a login, a data processing agreement that names its single hosting subprocessor, and an AI layer built so that a person confirms each suggestion. The editor is not a first-time software startup either, but a Swiss consulting group registered since 2015 that also runs an auditor training academy and a cybersecurity practice.

Two reservations should travel with a buyer into the first call. The first concerns the security claims: ISO 27001 and SOC 2 are displayed as badges without a certificate number, a certification body, a scope or a validity date, the privacy policy makes the weaker statement that a management system is merely operated, and it attributes that system to a sister brand rather than to the company that signs the contract. The trust centre holding the evidence is closed behind a manually reviewed request. For a tool sold to auditors and security officers, that documentation should be read before anything is signed. The second is maturity: several advertised modules are still marked as coming soon, the hosting story differs between marketing, contract and privacy policy, and the product itself is far younger than the company behind it.

For its target buyer the platform deserves the demo. The homework is to ask for the certificates, the penetration test summary and a written confirmation on where data actually lives.