Acuna
Swiss governance, risk and compliance platform covering more than 50 frameworks in one subscription. It maps each requirement once, ties controls to named owners and evidence, adds third-party risk and privacy operations, and prices per organisation rather than per seat.
What is Acuna?
Acuna is a governance, risk and compliance platform built and operated by Abilene Group SA, a Swiss GRC group based in Morges. It addresses organisations that already run several regulatory programmes at once rather than teams chasing a first certification, and the vendor states this plainly: its own documentation names Vanta, Drata and Sprinto as the better choice for a startup pursuing an initial SOC 2.
The platform is organised around four included panes. Comply models entities, boundaries and applicability, then structures each requirement and maps it to scope, controls and owners. Implement turns those requirements into controls with attached measures, named owners and recurring checks. Operate runs the daily rhythm of tasks, remediation and due dates. Assure prepares assurance packs, monitors findings and drives continuous improvement cycles. More than fifty frameworks ship pre-loaded with no per-framework fee, among them ISO 27001, ISO 42001, SOC 2, GDPR, FADP, NIS2, DORA, the Cyber Resilience Act, the EU AI Act and ISO 9001, and custom frameworks can be imported as YAML or CSV. A requirement is mapped once and reused everywhere it applies.
Modules extend that core. Supplier Shield handles third-party risk through automated open-source intelligence across DNS, TLS, web headers, breach exposure and reputation, producing composite grades from A to F and continuous monitoring. Data Privacy Management covers records of processing, DPIA, DSAR, breach handling and the generation of processing agreements and transfer impact assessments. A D&B Credit Score module adds supplier financial health from Dun & Bradstreet data.
Aiko+ is the AI layer. It answers plain-language questions from the customer's own records and tags the module each answer came from, proposes first-pass supplier evaluations and cross-framework control mappings, and attaches a confidence score to every suggestion for a human to confirm or override. It respects each user's existing permissions, answers questions on data subject requests and breaches from metadata alone, and can be switched off across the whole organisation with one toggle.
Pricing is per organisation rather than per seat: a single subscription covers all users and all frameworks, from CHF 5,388 a year, invoiced annually. Access is browser-based, in English and French.
What it does
- Map a requirement once and reuse it across more than 50 frameworks, without duplicating the work
- Tie every control to a named owner, to its evidence and to a recurring cadence
- Track compliance health in real time by framework, domain, control set and operating unit
- Assess and monitor suppliers automatically, with A-to-F grades built from DNS, TLS, header, breach and reputation signals
- Run privacy operations end to end: records of processing, DPIA, DSAR, breach handling and DPA generation
- Ask the built-in assistant a question in plain language and get an answer drawn from your own live data
- Prepare assurance packs and monitor findings continuously instead of scrambling before each audit
When to use Acuna / When not to
A quick filter to help you decide if Acuna is the right fit.
When to use Acuna
- Compliance leaders running several frameworks at once, for example ISO 9001 and GDPR in a single operating rhythm
- Security leaders steering ISO 27001, SOC 2 and NIS2 who need one source of truth across security and compliance obligations
- Data protection officers handling records of processing, DPIA, DSAR and breach workflows alongside the wider control set
- Regulated mid-market organisations in the EU and Switzerland, roughly 200 to 5,000 employees, with data residency requirements
- MSSPs and consulting firms delivering repeatable compliance work across multiple client tenants, with white labelling and mass deployment
When not to use Acuna
- Cloud-native startups chasing a first SOC 2 quickly and cheaply, a case the vendor itself sends to Vanta, Drata or Sprinto
- Organisations with no European or Swiss data residency requirement, who pay for a differentiator they will never use
- Small teams and solo practitioners, since the published entry ticket is CHF 5,388 per year with no free plan or trial
- Buyers who want to sign up and evaluate on their own, as every path runs through a demo request and a sales conversation
- Teams needing a mobile app or an interface beyond English and French
How to use Acuna
A typical end-to-end flow, from setup to results.
- Request a demo from the contact page, giving your name, work email, company and the problem you are trying to solve
- Expect a reply within one business day and a 30-minute call scoped to your compliance programme
- Agree the subscription plan and any optional modules, then sign the order form to which the processing agreement is annexed
- Go through guided onboarding to stand up your scope, controls and operating cadence
- Model your entities, boundaries and applicability in the Comply pane so each requirement lands in the right place
- Load the frameworks you need from the catalogue, or import a custom one as YAML or CSV
- Map requirements to controls once, and let the mapping be reused across every framework that shares them
- Assign each control to a named owner, attach its measures and evidence, and set its recurring checks
- Run the programme day to day in the Operate pane, tracking tasks, remediation and due dates
- Use the Assure pane to prepare assurance packs and monitor findings, and ask Aiko for answers, mappings or supplier evaluations along the way
Pros & Cons
Pros
- One price for the whole organisation, with no per-seat fee: owners, reviewers and auditors can all be given access without inflating the invoice
- An entry price published openly in a market where competitors routinely hide theirs
- More than 50 frameworks included with no per-framework charge, so adding a regulation costs work rather than money
- Terms, privacy policy and a complete data processing agreement are published in full, with no login required
- Data hosting committed to Switzerland in the processing agreement, with the hosting subprocessor named rather than left vague
- The AI is designed to stay under human control: confidence scores, mandatory human confirmation, permission awareness and an organisation-wide off switch
- The vendor publishes an explicit not-a-fit profile and names competitors that suit those buyers better, which is unusually candid
Cons
- ISO 27001 and SOC 2 appear only as badges: no certificate number, certification body, scope or validity date is published anywhere on the site
- The trust centre said to hold that evidence sits behind a manually reviewed access request, and the navigation still labels it as coming soon
- The privacy policy is weaker than the badges, describing an information security management system that is operated, and attributing it to a sister brand rather than the contracting entity
- Hosting statements conflict: marketing says Switzerland and the EU, the processing agreement says Switzerland exclusively, the privacy policy allows transfers abroad
- Several advertised modules are marked as coming soon, including AI governance, enterprise risk management, business continuity and the trust centre itself
- No free plan, no free trial and no self-service signup, so evaluation always requires a sales conversation
- The vendor never states whether customer data is used to train AI models, while the terms grant a perpetual licence to process that data to improve the service
Pricing & Plans
There is no free plan and no free trial. The lowest published price point is the Professional plan, which starts at CHF 5,388 per year and is invoiced annually. Regional equivalents are published for other markets, from EUR 4,999 per year in the European Union and USD 7,999 per year elsewhere. The price covers the entire organisation rather than a number of seats, and includes all users, the four panes and the full framework catalogue. Optional modules are charged in addition, and the Enterprise and MSSP tiers are quoted on request.
- unlimited frameworks
- custom dashboards
- integrated KPI and custom reports
- connectors and API
- full AI support
- all Professional features plus multi-entity management
- role-based access control
- Trust Center
- Breach Scanner
- D&B Credit Score integration
- dedicated onboarding and support
- custom SLA and priority access to new features
- all Professional features plus white labelling
- tenant management
- deployment bundles
- fully customisable templates with mass deployment and centralised audit
- custom discounted rates on request for registered non-profits
- international NGOs and accredited academic or research institutions
- Supplier Shield TPRM
- Business Continuity and Crisis Management
- Enterprise Risk Management
- Data Protection
Data, GDPR & hosting
A consolidated view of how Acuna handles your data.
GDPR overview
Implementation is documented rather than merely claimed. Abilene Group SA states it is subject to the Swiss FADP and, where applicable, the GDPR, and publishes a full data processing agreement in which it acts as processor and the customer as controller. A data protection officer is named, Henri Haenni, reachable at privacy@abileneadvisors.ch. Data subject rights are listed explicitly: access, correction, deletion, restriction, portability, objection and withdrawal of consent, plus the right to complain to a supervisory authority. Technical and organisational measures are itemised in article 7 of the agreement. Two gaps remain. No representative under article 27 is designated, although the vendor is established outside the European Union. And the documents disagree on transfers: the agreement rules out any processing outside Switzerland, while the privacy policy contemplates transfers abroad with a preference for EEA locations.
Who owns the data?
The customer keeps ownership. Section 6.2 of the terms states that all data submitted, transmitted, generated or stored by the customer, its authorised users and third-party users remains theirs, intellectual property included, and that the vendor acquires no rights beyond those expressly granted. Those granted rights are broad, however: the customer gives Abilene Group SA a non-exclusive, worldwide, perpetual, irrevocable and royalty-free licence, with the right to sublicense, to use, store, reproduce, distribute and display customer data in order to deliver the service and to maintain, support and improve it. Processing under that licence may be automated or manual. Conversely, the platform itself stays the vendor's property under a limited, non-transferable user licence.
Reuse rights
Customer data can be reused freely by the customer, who never gives up ownership of it: a copy can be downloaded from the platform on request, and nothing in the terms restricts what an organisation does with its own records, exports or reports afterwards. The restrictions run the other way, over the product. The licence to the service is personal, non-transferable, non-assignable and non-exclusive, limited to internal business purposes, to the term of the agreement and to the number of authorised users in the subscription plan. Reverse engineering, data scraping and any attempt to bypass technical restrictions are expressly prohibited, in particular through the API. One asymmetry deserves attention: the licence the customer grants the vendor over its own data is perpetual and irrevocable, and it covers improving the product, without the vendor ever stating whether that improvement includes training AI models.
Data retention & training
Hosting summary
The data processing agreement is the most precise source and the most restrictive. It states that all personal data is hosted and processed exclusively within Swiss territory, that the platform runs on cloud infrastructure located in Switzerland, and that no cross-border transfer is intended or authorised without the controller's prior written consent. A single subprocessor is disclosed: Supabase, in the eu-central-2 region in Zurich, for hosting, storage and availability. Any addition or replacement of a subprocessor requires prior written notice, and the terms give the customer a right of reasoned objection. Security measures are itemised, covering role-based access, least privilege, encryption in transit and at rest, backups, redundancy, incident response and logical segregation of client data. Note two caveats. Marketing pages describe residency more loosely as Switzerland and the EU, and the privacy policy allows transfers outside Switzerland with a preference for EEA locations. Separately, the public marketing website itself runs on a United States content delivery edge, which says nothing about where platform data lives.
Things to keep in mind
Risks and trade-offs to weigh before adopting Acuna.
- Unverified security claims: ISO 27001 and SOC 2 are shown as badges with no certificate number, body, scope or validity date, and the strips mix them with individual credentials held by team members, which is not the same as certifying the company. Ask for the attestation itself.
- Over-reliance on the assistant: Aiko proposes control mappings and supplier evaluations with a confidence score, and a rushed team can start approving suggestions without reading them, turning a first-pass aid into an unexamined decision and eroding the reviewer's own judgement.
- Data licence asymmetry: the customer keeps ownership, but grants the vendor a perpetual, irrevocable, worldwide and sublicensable licence to process that data to improve the service, with no statement anywhere on whether improvement includes training AI models.
- Backup responsibility sits with the customer: the terms state that deletion on the platform is definitive, that the vendor gives no warranty on long-term availability or integrity, and that account access is blocked at the end of the subscription, so exporting before an exit is entirely the customer's job.
- Conflicting hosting statements: marketing promises Switzerland and the EU, the processing agreement promises Switzerland exclusively, and the privacy policy allows transfers abroad, so residency should be confirmed in writing rather than assumed from the website.
- Roadmap risk: several modules presented in the navigation, including AI governance, enterprise risk management, business continuity and the trust centre, are marked as coming soon and cannot be counted on when scoping a programme today.
- A compliance tool can create false comfort: a dashboard showing controls as green measures what has been recorded in the platform, not what is actually operating in the organisation, and audit readiness still depends on the honesty of the people entering the evidence.
Setup & Integrations
Technical difficulty
Technically light, organisationally demanding. The platform is browser-based with nothing to install, and onboarding is guided, with the vendor claiming first value within the first hour. The real effort is programme modelling: defining scope and entities, loading frameworks, mapping requirements to controls and assigning named owners. That work needs someone who knows the compliance programme, not an engineer. The vendor sells configuration and advisory services separately, which suggests larger deployments are assisted. API integration and custom YAML or CSV framework imports are the customer's responsibility and do require technical skills.
Deployment
Integrations
Supported languages
Behind Acuna
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Acuna.
Frequently asked questions
What exactly is Acuna?
How is Acuna priced?
Is there a free plan or a free trial?
Where is the data hosted?
Which frameworks does it cover?
What does the AI assistant actually do?
Is a data processing agreement available?
Does Acuna offer an API?
Is Acuna certified to ISO 27001 or SOC 2?
Which languages does the interface support?
Should you pick Acuna?
Acuna occupies a narrow position and occupies it deliberately. It is aimed at European and Swiss organisations that already run several regulatory programmes and want one place to map requirements, own controls and hold evidence, priced for the whole organisation rather than per seat. On that ground the offer is coherent: an entry price published openly, every framework included, complete legal documentation available without a login, a data processing agreement that names its single hosting subprocessor, and an AI layer built so that a person confirms each suggestion. The editor is not a first-time software startup either, but a Swiss consulting group registered since 2015 that also runs an auditor training academy and a cybersecurity practice.
Two reservations should travel with a buyer into the first call. The first concerns the security claims: ISO 27001 and SOC 2 are displayed as badges without a certificate number, a certification body, a scope or a validity date, the privacy policy makes the weaker statement that a management system is merely operated, and it attributes that system to a sister brand rather than to the company that signs the contract. The trust centre holding the evidence is closed behind a manually reviewed request. For a tool sold to auditors and security officers, that documentation should be read before anything is signed. The second is maturity: several advertised modules are still marked as coming soon, the hosting story differs between marketing, contract and privacy policy, and the product itself is far younger than the company behind it.
For its target buyer the platform deserves the demo. The homework is to ask for the certificates, the penetration test summary and a written confirmation on where data actually lives.
- Choosing a selection results in a full page refresh.
- Opens in a new window.