Skip to main content
Tool Portfolio

Tools for Information Security & Compliance

The software and knowledge tools that DLAU Consulting develops and operates itself – from supplier audits through BSI IT-Grundschutz to a sovereign AI instance.

A shared technical foundation

Most of the tools share a web front end, a PostgreSQL database with tenant-separated access rights, and operation in Docker for self-hosting. This consolidates maintenance and further development across all tools. They are complemented by a dedicated AI lab on local hardware that works without any external cloud and hosts several specialised agents.

Productive tools

Nine tools in active use – each with its purpose, core functions and status.

01
Live

Supplier Audit Tool

Structured supplier and certification audits across a wide range of standards.

Plans, conducts and evaluates audits of suppliers, sites and customers against a broad set of security and compliance catalogs – with weighted scores, findings and audit reports.

Core functions

  • Audit programme wizard with live score
  • Findings & corrective actions with deadlines
  • Certification cycles per ISO/IEC 17021
  • Excel import/export of the catalogs, PDF report
≈ 54 catalogs · ≈ 11,800 audit questions
Next.js React Supabase shadcn/ui
02
Live

Grundschutz++

ISMS based on the new, process-oriented BSI methodology Grundschutz++.

Maps the BSI's Grundschutz++ approach: nearly a thousand machine-readable requirements across nineteen practices, assigned to thirty-one target-object categories with automatic inheritance.

Core functions

  • Requirements explorer with deterministic inheritance
  • Cross-reference to ISO 27001, NIS-2, KRITIS & DORA
  • Implementation status and progress
  • Automatic reconciliation with the BSI library
≈ 1.000 requirements · 19 practices · 31 target-object categories
Next.js Supabase Zod
Learn more
03
Live

NIS-2 Tool

Self-assessment and reporting obligations under NIS-2 and BSIG 2025.

Guides an organisation through the requirements of the NIS-2 Directive, supports the assessment of whether it is affected and classifies the reporting obligations.

Core functions

  • Guided self-assessment via wizard
  • Sector and applicability classification
  • Reporting obligations under IR (EU) 2024/2690
  • Role-based permissions
Next.js Supabase RLS
Learn more
04
MVP

Knowledge Hub

Question-and-answer assistant on a curated BSI knowledge base.

Answers compliance questions with evidence drawn from a knowledge base. If no suitable source is found, the assistant answers from general expertise only with an explicit note – instead of making something up.

Core functions

  • Semantic search across document sections
  • Answers with a citation of document and page
  • Strict source binding with fallback labelling
  • Admin area for importing PDFs
Target corpus ≈ 48 specialist documents
Next.js FastAPI pgvector Ollama Anthropic
05
Active

Compliance-Kompass

Curated regulatory knowledge base with a specialised expert assistant.

Bundles around forty-eight processed specialist documents on BSI IT-Grundschutz, ISO 27000, KRITIS, NIS-2, NIST and EU law and provides a dedicated assistant specialised in research and concept work on them.

Core functions

  • Curated, reviewed document collection
  • Topic-focused compliance research
  • Support with security concepts
  • Also feeds the Knowledge Hub
≈ 48 specialist documents
Knowledge base Research assistant
06
MVP

ISMS/Siko-Factory

The factory for your ISMS: automatically generates complete BSI IT-Grundschutz security concepts from the information network.

Generates a complete IT-Grundschutz security concept from the inventory data of an information network. The pipeline models target objects, derives requirements, runs the risk analysis and plans measures through to emergency management.

Core functions

  • Import of the information network from NetBox
  • Cascading phases from structure to emergency management
  • Risk wizard (gross & net), compliance cockpit
  • Emergency management per BSI 200-4 (MTPD, RTO, RPO)
Proven: 55 target objects · ≈ 2,450 requirements · 54 risks
Next.js Supabase BullMQ NetBox n8n
07
Active

ISB Control

Control and audit tool for the ISO – designed for CRA conformity from the outset.

Supports the information security officer with ongoing control and evidence. Maps BSI modules and requirements and manages information networks, risks, deviations, measures and evidence.

Core functions

  • Control along the BSI modules
  • Requirements catalog with reference values
  • Risks, deviations and measures plan
  • Reports with Excel export and PDF view
CRA-compliant: secure SDLC, SBOM & vulnerability management
Static Web PostgREST PostgreSQL Docker
08
Active

AI Lab – Sovereign AI Instance

A dedicated AI environment on local hardware, without dependence on external cloud services.

Runs language models and AI assistants entirely on the internal network and on in-house hardware. Requests and content never leave the infrastructure, so even sensitive and regulated topics can be handled.

Core functions

  • Chat interface (Open WebUI) with single sign-on
  • Local model execution via Ollama
  • Vector database (Qdrant) and tracing (Langfuse)
  • FastAPI platform as the basis for the agents
Operated on in-house hardware (NVIDIA DGX Spark) – no external data sharing
Open WebUI Ollama Qdrant Langfuse FastAPI
09
Active

Lab Agents

A team of specialised AI agents, centrally controlled through a control centre.

Several specialised agents take on clearly delimited tasks and work on the sovereign AI instance. A control centre consolidates control, task distribution and monitoring.

Core functions

  • Agents: Meta, BSI, Security, Doc, Lab, Learn, Deploy
  • Central control centre with individual and batch requests
  • Real-time responses with a rating function
  • Feedback flows into the further development of the model
FastAPI Agent registry Knowledge search

In preparation

Beyond the productive tools, further tools are being planned – shown here as an outlook, not yet implemented.

Planned

KRITIS-Tool

Evidence management and audits for operators of critical infrastructure.

Planned

BCM-Tool

Business continuity management per BSI 200-4.

Planned

ISMS-Factory

End-to-end generation of ISMS artefacts from inventory data.

Planned

Pentesting Tool

Support for security testing and its documentation.

Planned

AI Security Concept for Classified Information

Drafting of classified-information security concepts with expert assistance.

Looking for a tool to meet your requirement?

We will show you the tools in a live demo and clarify which one fits your compliance task.