Athereon GRC
Modular German governance, risk and compliance platform covering information security, business continuity, data protection, enterprise and supplier risk, with an agentic AI assistant called LAiKA. Hosted in Germany, sold by annual subscription.
What is Athereon GRC?
Athereon GRC is a cloud-based governance, risk and compliance platform published by Athereon GRC GmbH, a company founded in Saarbrücken in 2018 by Eric Bach, Marius Kleber and Philippe Weyand. It is sold as a modular suite rather than a single product: an organisation assembles its own configuration from ten specialised modules covering information security management, business continuity, data protection management, enterprise risk management, supplier risk management, integrated GRC, DORA, NIS2, professional services and the AI module LAiKA.
The platform is deliberately framework-agnostic. It supports ISO 27001, ISO 22301, ISO 31000, ISO 27005, TISAX, NIS2, DORA, BSI IT-Grundschutz, BSI 200-3 and 200-4, IDW PS 340, the EU AI Act and the Cyber Resilience Act, and the vendor states that customer-specific frameworks can be added and that unsupported industry standards will be implemented on request. In practice this means requirements from different standards can be mapped against the same controls and evidence instead of being maintained separately.
Each module carries substantial functionality. Information security brings hierarchical asset management with inherited protection requirements, audit management, policy documentation, measures and controls, and incident handling with statutory reporting under NIS2 and DORA. Business continuity covers business impact analysis, recovery planning to ISO 22301 and BSI 200-4, exercises and crisis alerting by platform, SMS or email. Data protection covers the Article 30 record of processing, impact assessments, breach handling under Articles 33 and 34, and technical and organisational measures. Risk management calculates gross and net risk across a defined lifecycle, and supplier risk adds certificate tracking, smart questionnaires and an exportable DORA information register.
LAiKA is the agentic layer that sits on top. It combines a personal assistant with three specialised agents: an Infrastructure Mapper that turns spreadsheets and CMDB exports into a structured asset landscape, a Compliance Assistant that performs gap analysis and drafts what is missing, and a Questionnaire Assistant that fills in and coordinates security questionnaires. LAiKA acts inside the system rather than returning suggestions in a list, but every change is submitted for human approval and logged. It can be driven in natural language and works inside Microsoft Teams.
The vendor reports more than 200 customer organisations, over five million compliance requirements managed and more than 100,000 active users.
What it does
- Run information security, business continuity, data protection, enterprise risk and supplier risk from one shared data set
- Build and maintain an asset inventory automatically, with protection requirements proposed for approval
- Compare a framework against the current state, produce a prioritised gap analysis and start implementing it
- Answer inbound security questionnaires automatically and chase suppliers on outbound ones
- Export a DORA-compliant information register in one click for submission to the authorities
- Report incidents under NIS2 and DORA from the incident management module
- Generate audit-ready reports for management, auditors and supervisory bodies
When to use Athereon GRC / When not to
A quick filter to help you decide if Athereon GRC is the right fit.
When to use Athereon GRC
- Organisations working towards ISO 27001, TISAX, NIS2, DORA, BSI IT-Grundschutz or the Cyber Resilience Act
- Compliance and information security teams juggling several frameworks across multiple sites at once
- KRITIS operators, public bodies and regulated firms in automotive, healthcare, finance, energy, manufacturing and IT
- Companies that need their compliance data to stay under German or European jurisdiction
- Start-ups and smaller organisations preparing a first certification, which the vendor prices from EUR 5,000 a year
When not to use Athereon GRC
- Buyers who want to sign up and pay online: every plan is quoted individually after a sales conversation
- Small budgets, since the published floor is EUR 5,000 per year excluding VAT, payable in advance
- Anyone looking for a permanent free plan or a self-service trial, neither of which exists
- Teams that need an interface in a language other than German or English
- Developers who expect public API reference documentation, as the REST API is only described commercially
How to use Athereon GRC
A typical end-to-end flow, from setup to results.
- Request a demo or a callback from the website; there is no self-service sign-up
- Attend an initial consultation in which the vendor scopes your organisation size, sites and frameworks
- Receive a free demonstration account set up by the vendor, and explore the software yourself
- Agree a package from XS to XL according to headcount and the modules you actually need
- Import existing data from your current systems, CSV files or other sources during onboarding
- Work with the dedicated onboarding manager through migration and any customisation
- Connect the platform to your ticketing tool such as Jira or ServiceNow, and to your IAM for users and roles
- Synchronise assets and processes from an enterprise architecture tool such as LeanIX, or build them with the Infrastructure Mapper
- Use the REST API for anything the standard connectors do not cover
- Run day-to-day work through dashboards, approval workflows and questionnaires, delegating routine tasks to LAiKA in the interface or in Microsoft Teams
Pros & Cons
Pros
- Broad functional coverage on a single data set, from security and continuity to data protection, risk and suppliers
- Framework-agnostic by design, with customer-specific standards accepted and new ones implemented on request
- Data sovereignty taken seriously: development in Germany and platform hosting in the Open Telekom Cloud in Germany
- The vendor's own information security management system is ISO 27001:2022 certified by DQS under a verifiable, named certificate
- Explicit commitment not to train models on customer data, alongside data minimisation and TLS 1.3 encryption
- The customer chooses the underlying language model, avoiding lock-in to a single AI provider
- Contractual availability of at least 99% on annual average, daily full backups and independent penetration testing
Cons
- No price is shown on any of the five package cards; everything is quoted individually
- No permanent free plan and no self-service trial: the free demo account is provisioned by the vendor after a sales call
- The interface is limited to German and English
- A REST API is advertised but no public API reference is published; the documentation portal requires authentication
- No list of subprocessors is published for the platform itself, only for the marketing website
- The main site and the dedicated LAiKA site contradict each other on whether customer data is used for training
- Payment is due in advance for the whole contract term, which renews automatically unless cancelled three months ahead
Pricing & Plans
There is no permanent free plan. The vendor publishes a single entry point in the pricing FAQ: Athereon GRC is available from EUR 5,000 per year for start-ups and smaller organisations, with the actual figure depending on the number of modules and the structure of the organisation. This amount is exclusive of VAT, which the general terms add to the fee, and payment is due in advance for the contract term. None of the five packages displays a price: each is described as individual and annual, priced on organisation size and GRC complexity rather than on user licences. A free demonstration account is set up by the vendor after an initial consultation, and professional services such as training, migration support and customisation are charged separately.
- XS Starter — up to 50 employees — individual annual price — first structured move to digital GRC processes
- S Growth — up to 200 employees — individual annual price — scaling compliance through early audits
- M Professional — up to 500 employees — individual annual price — multiple sites and parallel frameworks
- L Enterprise — up to 2
- 000 employees — individual annual price — multiple entities and cross-site governance
- XL Corporate — over 2
- 000 employees — individual annual price — KRITIS operators
- groups and institutions
- European hosting
- ISO 27001 certification
- audit-ready reporting
- German and English interface
- continuous updates
- community and support
Data, GDPR & hosting
A consolidated view of how Athereon GRC handles your data.
GDPR overview
The site claims GDPR compliance explicitly, with a DSGVO-konform badge on several pages and a GDPR-compliant claim in the English page description. Athereon GRC GmbH is named as the controller, with a postal address, telephone number and email. The published privacy policy lists the usual data subject rights and documents processing agreements with the site host, Google, Microsoft Teams and Livestorm, US transfers under standard contractual clauses, and joint controllership with LinkedIn for lead generation forms. Two limits should be noted: no data protection officer is named anywhere, and the policy covers the marketing website only, not the platform where customer compliance data actually lives. The general terms fill part of that gap by committing to a processing agreement before any customer personal data is handled.
Who owns the data?
Athereon GRC GmbH positions itself as a processor rather than an owner of customer content. The general terms commit the vendor to signing a data processing agreement before any personal data is handled, and to hosting the software on a server operated in Germany, whether by Athereon itself or by a contracted provider. Mutual confidentiality obligations extend to employees and subcontractors. The separate LAiKA terms grant Athereon only a simple, non-exclusive licence over customer prompts, expressly limited to the duration of the contract and to reproducing, modifying and using them within the software. Nothing in the published documents transfers ownership of customer compliance data to the vendor.
Reuse rights
Customers keep the use of their own data: the platform exists to store, structure and export their compliance records, and nothing in the terms restricts what they may do with the output. On the AI side, the vendor's dedicated data-handling section states that compliance data is never used to train, fine-tune or improve an AI model, that only the information relevant to the current step is passed to the AI reasoning provider, and that this data is not stored beyond generating the answer. Customers choose which large language model LAiKA relies on, including a model running on their own infrastructure. One caveat deserves attention: a product page on the main site describes separate training instances in which each customer system trains on its own data, which reads against the categorical statement made on the dedicated LAiKA site. The vendor also warns that model output is probabilistic and can be wrong, and recommends human review.
Data retention & training
Hosting summary
Athereon GRC states that customer data is stored exclusively in Germany, in the GDPR-compliant Open Telekom Cloud, and the general terms back this up contractually: the software is hosted on a server operated within Germany, by Athereon itself or by a contracted provider. The vendor presents this as protection against third-country access and describes the platform as developed and operated in Germany. Data is encrypted in transit and at rest, with TLS 1.3 named on the AI side, and communication with AI reasoning providers runs over encrypted channels only. Full backups are taken daily in the Open Telekom Cloud, with an additional full backup before every major update, and the vendor reports several successful independent penetration tests. One nuance is worth noting: while the platform is described as hosted in Germany, the LAiKA pages describe hosting in sovereign data centres within the EU, giving the Open Telekom Cloud as an example rather than as the only location. Note also that the marketing website itself is served from a global content delivery network, which says nothing about where customer records are kept.
Things to keep in mind
Risks and trade-offs to weigh before adopting Athereon GRC.
- Agentic AI acting inside a compliance system can breed over-trust: the approval step only protects you if someone actually reads what LAiKA proposes before clicking through it
- The vendor states plainly that a language model is probabilistic and that its output can be untrue, and recommends human review — treat generated policies, risks and questionnaire answers as drafts, not as evidence
- The two vendor pages disagree on training: the dedicated LAiKA site rules out any use of customer data for training, while a product page describes separate training instances working on customer data. Get the answer in the contract
- The published privacy policy covers the marketing website, not the platform, so any GDPR fact drawn from it says nothing about how your compliance records are handled
- No subprocessor list is published for the platform, and the AI reasoning provider is chosen by you rather than disclosed by the vendor — the transparency burden shifts to your own supplier assessment
- Concentrating security, continuity, privacy and supplier data in one system raises the stakes of exit: contracts renew automatically unless cancelled three months before term, and fees are paid in advance
- Efficiency figures such as 85% less effort or a 100% audit success rate are vendor claims with no published method, and the LAiKA site's own testimonials name no company
Setup & Integrations
Technical difficulty
Low to moderate, and largely handled by the vendor. The platform is a browser-based service with nothing to install. Existing data can be taken over from current systems, CSV files or other sources, and the vendor claims a transfer within a few days rather than a long migration project, with a dedicated onboarding manager throughout and a stated time to value of under four weeks. Optional work adds effort: connecting a ticketing tool, an enterprise architecture tool or an identity provider, or building custom interfaces on the REST API. The AI-first approach is presented as lowering the specialist knowledge users need day to day.
Deployment
Integrations
Supported languages
Behind Athereon GRC
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What kind of organisation is Athereon GRC built for?
Which frameworks does it support?
How much does it cost?
Is there a free trial or a free plan?
Where is the data hosted?
Is customer data used to train the AI?
Which language model does LAiKA use?
Is there an API?
Which languages and platforms are supported?
What service commitments does the contract carry?
Should you pick Athereon GRC?
Athereon GRC is a serious, narrowly focused product rather than a general-purpose assistant, and it is easy to verify. The publisher is a real legal entity registered at the Saarbrücken commercial register since June 2018, its own information security management system carries a named ISO 27001:2022 certificate issued by DQS, and its case studies name identifiable customers with published testimonials. For an organisation that has to satisfy several frameworks at once, the promise of a single data set behind ISO 27001, business continuity, GDPR, enterprise risk and supplier risk is the main argument, and the modular pricing means unused areas are not paid for.
The AI layer is more interesting than most compliance chatbots because it is designed to act rather than advise: LAiKA creates assets, policies, measures and risks inside the system, with an approval step and a log for every change. Letting the customer choose the underlying language model, including one running on their own infrastructure, is unusual and genuinely reduces vendor lock-in.
Two reservations should temper this. First, the commercial model is opaque by design: no package shows a price, the only published figure is a EUR 5,000 annual floor, and there is no way to evaluate the product without talking to sales. Second, the vendor contradicts itself on whether customer data feeds model training — the dedicated LAiKA site rules it out categorically while a product page on the main site describes separate training instances working on customer data. For a tool whose entire value rests on handling sensitive compliance records, that is the one point a buyer should settle in writing before signing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.