01
Frameworks beyond the German core
QSEC covers the German core well. KaitoSec carries ISO 42001 as an operated AIMS, SOC 2 for international customers and the EU AI Act, whose Article 50 transparency duties have applied since August 2026, on the same data model as the ISMS.
02
The switch as a named service
A move out of a grown suite follows a fixed shape: export of the control register, the risk register and the policy library, a mapping pass onto the KaitoSec model, an evidence import for the historical audit trail, then a parallel period in which the old system stays read-only. Surveillance audits and management reviews continue while that runs.
03
Drafts on every record
KaitoSec puts Cmd+J on every record and drafts risk treatments, policy sections, audit answers and BC plans from the live workspace context, with Simple Mode for occasional contributors and Expert Mode for the ISB. The framework still drives the work; KaitoSec AI shortens the path to a draft that holds up.
04
A price procurement can recalculate
KaitoSec publishes list prices per user below the Enterprise plan and quotes advisory as a separate line, so finance can model the total before the first conversation. Compare that against a scope-based quote for the same requirements.