Automation
Permanently audit-ready — not just right before the audit.
Most management systems lie dormant between two audits. PRISM does not: evidence is generated automatically from your systems — Confluence, SAP, SharePoint, REST API — and stored in the platform in a tamper-proof manner.
Connect data sources directly
Confluence pages, SharePoint documents, Google Drive, SAP authorisation reports — PRISM reads your existing sources and analyses them automatically against the standard. No manual transfer required.
Evidence generated during operations
Every approval, every measure, every management review is logged automatically. When the auditor arrives, everything is in place — not because someone worked overtime two weeks beforehand.
Custom systems via API
Fully documented REST API, OAuth2/OIDC for machine users, API keys for system-to-system integration. Whatever your systems can do, PRISM can connect to.
PRISM Product Family
Four products. One shared data foundation.
The PRISM products share the same data foundation — controls, assets, evidence and risks are visible across all products. No exports, no duplicates, no media breaks.
PRISM ISO — Compliance & Certification
Controls, policies, SoA, risk register and certification evidence. The foundation for everything else: what is fulfilled as a control here counts as evidence across all other modules.
View PRISM ISO →PRISM Audit — Audit Management
Internal audit, certification audit, external auditor — on the same data foundation as PRISM ISO. Fieldwork evidence from PRISM ISO flows directly into PRISM Audit.
View PRISM Audit →PRISM Vanguard — Vulnerability Management
Vulnerabilities from Vanguard scans are automatically converted into ISMS risks in PRISM ISO. Calibrated findings flow directly into the certification documentation as control evidence (A.8 ISO 27001).
View Vanguard →PRISM EagleEye — Security Operations
Live operational data from EagleEye (SIEM events, asset dependencies, risk score) flows as evidence into PRISM ISO — automatically, without manual export. Audit evidence is created at the point of incident response.
View EagleEye →How the integration works
All PRISM products share the same asset graph and the same control register. An asset that Vanguard identifies as vulnerable appears immediately as a risk in PRISM ISO — with the correct standard clause reference. EagleEye events automatically generate ISMS entries. PRISM Audit sees all evidence from ISO and Vanguard — without any file export.
Integration Categories
All connections are available in production — no beta, no waiting list. Certified implementation partners available on request.
Documentation & Storage
PRISM ISO + AuditRead existing documents directly as sources — PRISM evaluates them automatically against the standard. No manual transfer required.
Compatible systems ↓
- • Confluence (Atlassian)
- • SharePoint / OneDrive (Microsoft)
- • Google Drive / Google Workspace
ERP & Access Management
PRISM AuditAuthorisation reports and role concepts directly from the ERP into the audit environment — without export, without data loss.
Compatible systems ↓
- • SAP (Extractor, RFC, Basic Auth)
ITSM & Service Management
PRISM ISOUse incidents, changes and assets from your ITSM directly as ISMS elements — operational events become compliance evidence automatically.
Certified partners ↓
- • Damalo — implementation partner for ITSM integration
Asset Management & CMDB
PRISM ISOCapture assets and link them directly to controls, risks and protection requirements — the foundation for a risk-based ISMS per ISO 27001.
Compatible systems ↓
- • PRISM ISO integrated asset CMDB
- • Connect external CMDBs via REST API
Identity & Authentication
PRISM ISO + AuditSSO, machine users and granular API keys — PRISM integrates with any existing identity infrastructure.
Supported standards ↓
- • OAuth2 / OIDC (Client Credentials Flow)
- • API keys with scope control
Open REST API
PRISM ISO + AuditAll data and processes controllable via fully documented endpoints — for custom integrations, automations and reporting.
Details ↓
- • OpenAPI documentation available
- • Webhooks for event-driven workflows
- • Sandbox environment on request
Your system not listed?
The REST API covers everything PRISM can do. If you need a specific integration — ticketing system, CMDB, HR system — we will clarify in a conversation what can be realised within your infrastructure without additional overhead.
Book a call