In conjunction with

EU-Sovereign GRC Cloud for Information Security, Data Protection and Continuity

Akarion is an Austrian-German software company selling a cloud governance, risk and compliance platform to mid-sized enterprises, critical infrastructure operators, healthcare providers, public administration and the consultancies that serve them. Markus Costabiei founded the business in Linz in 2017 alongside Viljem Pitako, Sascha Maschek and Paul Emathinger, initially built around blockchain-backed tamper resistance for GDPR documentation, and the headquarters moved to Munich in 2018. The company now reports more than 900 organisations using its GRC Cloud.

The GRC Cloud bundles five modules — information security, business continuity, audit, data protection and whistleblowing — over one shared database. Assets, processes, people and organisational units are entered once and reused everywhere, so an update propagates instead of being re-keyed per discipline. Predefined control catalogues for ISO 27001, ISO 22301, BSI IT-Grundschutz, TISAX, PCI DSS, DORA and NIS-2 attach to those assets and risks, producing Statements of Applicability, audit programmes and evidence trails. Task workflows fire on deadlines and status changes.

Differentiation rests on jurisdiction and generative AI. Development happens entirely in Germany and Austria, and hosting runs on STACKIT's EU infrastructure, so customer data stays within European legal reach — a pitch aimed squarely at the digital sovereignty debate. A Smart Content AI add-on drafts risks, measures, policies and audit questionnaires from organisational context, which the vendor claims cuts management-system build effort by over eighty percent. Template inheritance lets a parent client push standards down to subsidiaries automatically.

Market Segments:

GRCCompliance

Categories:

Compliance Management