Governance · Risk · Compliance

Your GRC program, unified and provable.

Elpista brings third-party risk, control testing, policy, audit and multi-framework compliance into one platform — Canadian-hosted, ISO 27001-aligned, and verifiable down to a tamper-evident audit trail.

Data resident in Canada ISO/IEC 27001-aligned Tamper-evident audit
Open risks34
Controls tested92%
Vendors128
Maturity 3.7
Purpose-built for Public sectorHealthcareUtilities & OTFinancial servicesRegulated SaaS
One platform, nine disciplines

Everything your risk & compliance team runs — in one place

No more stitching point tools together. Elpista covers the full GRC lifecycle out of the box, each module ready to switch on.

Third-party risk

Vendor registry, automated tiering and inherent-risk scoring, N-tier sub-processors, and a license-free vendor portal for assessments.

Supply chain & threat intel

SBOM ingestion, CVE/NVD correlation, concentration and geopolitical risk, breach monitoring and threat-actor context.

Cyber-maturity

Multi-framework maturity scoring, gap analysis with prioritized remediation, benchmarking and heatmaps.

Evidence & audit

Central, versioned evidence repository linked to controls, with audit-request workflows and packaged sign-off.

Risk & control testing

Risk campaigns, a 1–25 matrix and heat maps, KRIs, and four-method control testing with pass/fail and exceptions.

Risk registers

A unified, filterable register with taxonomy, ownership, treatment tracking, trending, and board-ready export.

Policy lifecycle

Policy library with review cadence, version diff and sign-off, control linkage, and exception management.

Reporting & dashboards

Executive and operational dashboards, a no-code report builder, and a tamper-evident activity log.

Multi-framework

Embedded, maintained content across ISO 27001, NIST CSF/800-53, IEC 62443 and more — with cross-framework mapping.

Why Elpista

Built for the teams the incumbents overlook

Regulated, public-sector, and OT-heavy organizations need depth, residency and proof — not a compliance-badge tool.

Unified, not a point tool

All nine GRC disciplines in one system, sharing one vendor list, one control library and one audit trail.

In-region by design

Data at-rest and backups stay in Canada, encrypted end-to-end. Choose your region for every deployment.

Provable integrity

A hash-chained, tamper-evident audit trail proves no record was altered — the assurance auditors expect.

Real OT / ICS depth

IEC 62443 zones & conduits, NIST 800-82, and CIS v8 IoT/OT — coverage most compliance tools simply don't have.

Fast to value

Modular, out-of-the-box configuration. Live in weeks, not the multi-quarter deployments of legacy GRC suites.

License-free vendor portal

Unlimited third parties complete assessments and upload evidence without a paid seat — predictable TPRM economics.

Multi-framework

Map one control to every framework

Embedded, maintained framework content with automatic cross-framework mapping and Statement of Applicability generation.

ISO/IEC 27001:2022
ISO/IEC 27032:2023
NIST CSF 2.0
NIST 800-53 Rev.5
NIST 800-161
IEC 62443
NIST 800-82
SOC 2
CIS Controls v8
ISO 28000:2022
Shared Assessments SIG
PIPEDA
Security you can verify

We hold ourselves to the standard we help you meet

Selling a security product means proving your own. Elpista is built secure from the data layer up.

  • Hard tenant isolation — application guards plus PostgreSQL row-level security; a stranger tenant sees zero rows.
  • End-to-end encryption — TLS in transit, AES-256 at rest, FIPS-validated cryptography.
  • SSO & MFA — Microsoft Entra ID and SAML/OIDC, with role-based access on every action.
  • Tamper-evident audit — a hash-chained log that verifies integrity after every write.

Trust posture

At a glance

Data residencyCanada
ISO/IEC 27001:2022Aligned
Encryption at rest / in transitAES-256 / TLS
Tenant isolationApp guard + RLS
Audit trailHash-chained
SOC 2 Type IIIn progress
Switch without the services project

Bring your data from ServiceNow or spreadsheets

Import from CSV/Excel and SharePoint, or pull straight from ServiceNow IRM — through one guided, reversible pipeline.

01 · EXTRACT

Upload or pull

Drop a spreadsheet, or pull risks, controls and vendors from ServiceNow.

02 · MAP

Map & transform

Auto-mapping plus crosswalks and scale conversion to your model.

03 · DRY-RUN

Preview first

See exactly what will be created or updated — nothing writes until you confirm.

04 · COMMIT

Load & reconcile

Idempotent import with a reconciliation report and one-click rollback.

See your own data in Elpista →
Pricing

From self-serve to dedicated, in-region deployments

Start on a shared instance, or run a fully isolated deployment for government and enterprise. Modular — pay for the disciplines you use.

Starter

Small teams getting risk & compliance off spreadsheets.
  • Risk register + control testing
  • Core TPRM
  • 3 framework packs
  • Self-serve
MOST POPULAR

Professional

Growing programs that need the full suite.
  • All nine domains
  • 10+ frameworks
  • SSO + 2 integrations
  • Standard SLA

Enterprise

Larger orgs needing scale and control.
  • All frameworks + custom
  • Region choice + residency
  • Dedicated deployment option
  • 99.9% SLA

Government

Public sector & regulated, isolation required.
  • Dedicated, in-region deploy
  • Own IdP & backups
  • Compliance evidence pack
  • Priority support
Transparent, modular pricing — talk to us for a quote.

See Elpista on your own data

A 45-minute walkthrough — we'll load a slice of your real risks, controls and vendors so you see your program running in Elpista, not a canned demo.

Request a demo