Vulny

Compliance

Vulny gives you the continuous evidence and governance tooling that modern security frameworks expect. Vulny is a tool that supports your compliance programme — it does not issue certifications.

ISO 27001

Vulny includes a built-in ISMS — risk register, Statement of Applicability across all Annex A controls, incident management and third-party risk — plus the continuous technical testing that controls like A.8.8 (management of technical vulnerabilities) call for.

GDPR

Article 32 requires appropriate technical measures and regular testing of their effectiveness. Continuous vulnerability scanning and documented remediation help demonstrate that. Vulny also provides data export and account deletion for your own data.

SOC 2 readiness

Continuous monitoring, vulnerability management and evidence-ready reporting support the Security and Availability trust-services criteria auditors look for.

PCI DSS

Requirement 11 calls for regular internal and external vulnerability scanning. Vulny’s scheduled scans and exportable reports help you keep that evidence current.

Frequently asked questions

Does Vulny certify my organisation for ISO 27001?

No. Vulny is a tool that supports your compliance programme — it gives you the ISMS and the continuous technical testing the standard expects, but the certificate itself is issued by an accredited certification body after their audit.

Which compliance frameworks does Vulny support?

Vulny supports ISO 27001 (with a built-in ISMS), GDPR Article 32, SOC 2 readiness and PCI DSS Requirement 11 — through continuous vulnerability scanning, documented remediation and evidence-ready reporting.

Can I export evidence for auditors?

Yes. Vulny exports branded PDF and DOC reports for vulnerabilities, incidents, the risk register, the Statement of Applicability and third-party risk — ready to hand to an auditor.

How does Vulny keep compliance evidence current?

Vulny scans continuously and re-checks your assets against newly published CVEs every two hours, so your evidence reflects today’s state rather than a point-in-time snapshot.

Do I need a separate tool for the ISMS?

No. The risk register, Statement of Applicability across all Annex A controls, incident management and third-party risk management are built into Vulny and connected directly to your real scan findings.

See it on your own site

Run one scan for security, SEO and AI-search (GEO) — and get a branded, ISO 27001 ready PDF report.

Scan my site →