NELEUS

Products / 01

Neleus GRC

Governance, risk and compliance for European financial and technology companies. Data protection and cybersecurity first, on a vault that keeps the evidence as you work rather than at audit time.

Lead product

The problem it solves

A European company in finance or technology answers to several regimes at once. Run as separate projects, they produce the same evidence several times over, in several formats, owned by several people, and none of it agrees at audit. The requirements themselves overlap heavily. The work does not have to.

Neleus GRC keeps one governed record of how your organisation actually works, and maps that record onto each regime you answer to. A fact captured for the GDPR is already doing work for the next framework.

What is operational today

The GDPR is operationalised down to the article. The mapping engine is built, and the ISO 27001, NIS2, DORA and EU AI Act libraries are in build. We say that plainly because a compliance vendor that overstates its own coverage is making the worst available error.

Two locks on every action

Access is the product, not a setting inside it. Every action is governed by two locks: what the person may do, and what the agent acting for them may do. The effective permission is the smaller of the two. An agent can never be the accountable owner of a record, and the database schema itself forbids it.

Editions

Two editions exist in the code, and the resolver defaults to the more restrictive one. Prime permits frontier models under your own key. Client is the European posture, and it is what you get unless the edition is set explicitly. An open stance is never the accident of a forgotten variable.

18

Governed
GRC domains

7

Hierarchy layers
available

44 / 31

Agent roster,
31 in service

2

Locks on
every action

See it govern something of yours.

Bring one real policy or process and thirty minutes. We put it in the vault live: the agents, the audit trail, and a refusal on demand.

Book a demo