ethira
FeaturesAboutBlogSign inBook a demo
Platform Features

One platform. Every governance workflow.

Ethira replaces your spreadsheets, email chains, and wiki-hunts with automated governance — across TPRM, AI, data privacy, risk, regulatory compliance, and more.

Book a demoTry for free

No credit card required · Setup in under 10 minutes

What's inside

Six modules. One unified platform.

Start with the one you need most. The rest are already there when you do.

Third-Party Risk Management

Half your vendors were never formally onboarded. Ethira finds them, runs the process end-to-end, and keeps monitoring after.

  • Discovered from contracts, your browser extension, and spend data
  • Onboarding runs itself — docs, corporate check, DORA analysis, risk score
  • Continuous monitoring: news, breach alerts, regulatory changes
  • Subcontractor and nth-party graph included
Learn more

AI Governance & Shadow AI

Half your team is already using AI tools you don't know about. Ethira finds them, names an owner, and governs them — without asking IT for anything.

  • Passive browser extension — no IT rollout, works immediately
  • SSO and DNS scans catch what the browser extension misses
  • MCP access graph: exactly which agent touches which data
  • AI spend by team and tool, with trend reporting
Learn more

Asset Inventory

Your actual asset list — not the one that's three years out of date. Every system, AI agent, dataset, and team, with a named owner attached.

  • Systems, products, agents, microservices, devices
  • Datasets, processes, policies, code repositories
  • People, teams, and physical locations
  • Governance frameworks, controls, and requirements
Learn more

Data Privacy (GDPR)

The RoPA your DPO has been asking for. Complete, current, and not a spreadsheet.

  • Article 30 RoPA with processing purposes
  • Data subject and personal data category registers
  • DPIAs, security measures, and international transfers
  • Retention rules per processing activity

Risk Management

Two risk registers — one for vendors, one for the enterprise — that actually share the same taxonomy and talk to each other.

  • Third-party risk register with per-vendor scoring
  • Enterprise risk register with multiple registers
  • Findings, mitigations, and ROI validation
  • Custom taxonomy — levels, likelihood, impact scales

Trust Exchange

Stop rewriting the same security questionnaire answers from scratch. Answer once, serve forever.

  • Public-facing trust portal with shareable documents
  • AI-assisted questionnaire responses from your knowledge base
  • NDA management and access request workflows
  • Slack and Teams integration for incoming requests

Third-Party Risk Management

From discovery to off-boarding — fully automated

Ethira runs every step of your TPRM programme. Vendors are discovered automatically from contracts, your browser extension, and spend data. Onboarding runs itself — documents collected, corporate data verified, DORA contracts analysed, risks scored — in under 60 seconds per vendor.

  • Auto-discover vendors from contracts, browser extension, SSO data, and spend feeds
  • Fully automated onboarding: documents, corporate verification, contract analysis, risk scoring
  • Continuous monitoring with news, data breach, and regulatory change alerts
  • Subcontractor mapping and nth-party dependency graph for full supply-chain visibility
See TPRM use case
Vendor Onboarding—Acme Corp GmbH
Live
Document Collection
Processing
Certificate of Incorporation
Insurance Certificate
ISO 27001 Certificate
Data Processing Agreement
Privacy Policy
Corporate Data
5 items
LEI Code
VAT Number
EU Entity ID
Data Storage
Data Categories
Contract Analysis
4 items
GDPR Article 28
DORA ICT Requirements
EU AI Act (Annex III)
Custom SLA Requirements
Risk Analysis
5 items
Data Breach & Privacy
Regulatory Non-Compliance
Business Continuity
Fourth-Party Concentration
Cross-border Data Transfer
Vendor Profile
auto-onboarding
AC

Acme Corp GmbH

Frankfurt, DE · Founded 2009

AI Governance

Every AI tool. Named. Governed. Monitored.

Ethira's browser extension passively watches AI tool usage across your workforce — no IT rollout, no agent install. When a new tool is spotted, it's catalogued with a named owner assigned automatically from your org chart. Unsanctioned tools are flagged instantly.

  • Passive browser extension discovery — works immediately, zero IT involvement
  • Unsanctioned AI tool detection via SSO, DNS scans, and browser monitoring
  • MCP access graph: visualise every AI agent's tool access and file permissions
  • AI cost attribution by team and tool, with spend trend reporting
See Shadow AI Discovery use case
Claude×
Gmail
Slack
Live
claude.ai
Help me prepare the Q4 board report
Message Claude

Regulatory Compliance

DORA Register of Information — always current, exportable on demand

Ethira keeps a live, DORA-compliant Register of Information for every critical ICT third party. When regulators ask, export the official EBA spreadsheet format in seconds — no manual compilation, no last-minute audit scrambles.

  • Live ICT vendor register mapped to DORA Article 28 requirements
  • Automatic DORA contract analysis — gaps surfaced during onboarding
  • One-click export to official EBA DORA Register of Information format
  • ICT risk management aligned to DORA, ISO 22301, and ISO 42001
See DORA RoI Reporting use case
DORA Register of Information
Live

ICT Vendor Register

4 vendors · DORA Register of Information

VendorCountryICT ServicesCriticalityRisk ScoreStatus
CloudSoft AGDECloud InfrastructureCritical
72
Active
DataVault LtdGBData StorageImportant
45
Active
NetSecure IncUSCybersecurityImportant
61
Active
PayProcess BVNLPayment ProcessingCritical
83
Active

Last updated: 13 May 2026 · DORA Article 28 compliant

4 of 4 vendors

DORA_RoI_2026_Q1.xlsx

EBA format
ABCDEFGHIJKL
1001000200030004000500060007000800090010001100120
2549300CSAG01LEICloudSoft AGCloudSoft AGLegal personDEEUR2 400 000213800PARENT01LEI
3529900DVLT01LEIDataVault LtdDataVault LtdLegal personGBGBP850 000213800PARENT02LEI
4213800NSEC01LEINetSecure IncNetSecure IncLegal personUSUSD620 000
5724500PPBV01LEIPayProcess BVPayProcess BVLegal personNLEUR3 100 000213800PARENT03LEI
6
7
8
B.05.01
B.04.01
B.05.02
B.06.01
B.07.01

More capabilities

The rest of the picture

Three more modules that do their own heavy lifting.

Data Privacy (GDPR)

  • Article 30 Record of Processing Activities
  • Processing purposes register
  • Data subject and personal data categories
  • Data Protection Impact Assessments
  • Security measures documentation
  • International transfer records
  • Retention rules per processing activity
  • Custom fields for local requirements

Risk Management

  • Third-party risk register per vendor
  • Enterprise risk register with multiple registers
  • Bayesian risk scoring model
  • Findings and mitigation tracking
  • ROI validation issue workflow
  • Custom taxonomy — levels, likelihood, impact scales
  • Risk categories and status definitions
  • Risk import and export

Trust Exchange

  • Public-facing trust portal
  • AI-assisted questionnaire responses
  • Knowledge base and Q&A categories
  • Received questionnaire inbox
  • NDA management and e-signature
  • Access request management
  • Slack and Teams integration
  • Outbound trust documents library

Get started today

Turn AI liability into accountability. Get governance in 10 minutes.

Book a demo

No credit card required · Setup in under 10 minutes · Cancel anytime

ethira

Govern every asset. Automatically.

Platform

  • Features
  • AI Governance

Use Cases

  • Shadow AI Discovery
  • AI Agent Governance
  • Third-Party Risk (TPRM)
  • ICT Risk Management
  • DORA RoI Reporting

Company

  • About
  • Blog
  • FAQ
  • Brand
  • Privacy Policy
  • Terms of Service
  • Subprocessors
  • Contact

© 2026 Ethira AB · Luntmakargatan 26, 111 37 Stockholm, Sweden

Privacy PolicyTerms of ServiceSubprocessors