REGISTRIES & ARTIFACTS

All records, kept current

Bring or build any register or artifact in Freda. Kept current, operated by agents, and queried instantly by your team or your systems.

REGISTRIES & ARTIFACTS

All records, kept current

Bring or build any register or artifact in Freda. Kept current, operated by agents, and queried instantly by your team or your systems.

REGISTRIES & ARTIFACTS

All records, kept current

Bring or build any register or artifact in Freda. Kept current, operated by agents, and queried instantly by your team or your systems.

M

Registries

Vendor registry

Bulk import

Add vendor

Search vendors…

Filter

Display

7

Name

Subprocessors

Location

Certifications

Owner

Criticality

Last review

Contract

Cloudflare


18 listed

US

SOC 2 +3

A

Adam Ivarsson

High

04/09/2026

Grafana Labs

9 listed

US

SOC 2 +1

E

Erik Hennings

Medium

27/08/2026

Datadog, Inc.


14 listed

US

SOC 2 +2

A

Adam Ivarsson

High

26/08/2026

Amazon Web Services


22 listed

Global

critical

SOC 2 +4

R

Ruben Das

Critical

18/08/2026

IBM

16 listed

Global

ISO 27001 +3

G

Gustav Kyringe…

Medium

26/07/2026

SAP

20 listed

EU

ISO 27001 +2

A

Adam Ivarsson

Medium

18/08/2026

Snowflake


11 listed

US

SOC 2 +2

A

Adam Ivarsson

High

18/08/2026

OpenAI


8 listed

US

AI

SOC 2 +1

E

Erik Hennings

High

25/08/2026

Workday


13 listed

US

SOC 2 +2

E

Erik Hennings

Medium

27/08/2026

Slack


15 listed

US

SOC 2 +2

G

Gustav Kyringe…

Medium

01/07/2026

GitHub

10 listed

US

SOC 2 +2

S

Shayan Effati

High

08/07/2026

Stripe

17 listed

US

PCI DSS +2

R

Ruben Das

High

16/06/2026

Okta

12 listed

US

identity

SOC 2 +3

S

Shayan Effati

Critical

20/06/2026

MongoDB

9 listed

US

SOC 2 +2

R

Ruben Das

Medium

15/06/2026

Twilio

14 listed

US

SOC 2 +2

S

Shayan Effati

Medium

15/06/2026

Zendesk

11 listed

US

SOC 2 +1

E

Erik Hennings

Low

18/06/2026

Hi there, Mikael

What would you like to do?

GDPR

What can you help me with?

Ask Freda…

NameSubprocessorsLocationCertificationsOwnerCriticalityLast review
Anthropic
12 listed
US
SOC 2 +2
AAdam Ivarsson
High
10/09/2026
Searching connected systemsReading the trust centerMatching certificationsSetting owner and criticality6 fields filled from 3 sources
Cloudflare18 listedUSSOC 2 +3AAdam IvarssonHigh04/09/2026
Grafana Labs9 listedUSSOC 2 +1EErik HenningsMedium27/08/2026
Datadog, Inc.14 listedUSSOC 2 +2AAdam IvarssonHigh26/08/2026
Amazon Web Services22 listedGlobalSOC 2 +4RRuben DasCritical18/08/2026
IBM16 listedGlobalISO 27001 +3GGustav Kyringe…Medium26/07/2026
SAP20 listedEUISO 27001 +2AAdam IvarssonMedium18/08/2026
Snowflake11 listedUSSOC 2 +2AAdam IvarssonHigh18/08/2026
OpenAI8 listedUSSOC 2 +1EErik HenningsHigh25/08/2026
Workday13 listedUSSOC 2 +2EErik HenningsMedium27/08/2026
Slack15 listedUSSOC 2 +2GGustav Kyringe…Medium01/07/2026
GitHub10 listedUSSOC 2 +2SShayan EffatiHigh08/07/2026
Stripe17 listedUSPCI DSS +2RRuben DasHigh16/06/2026
Okta12 listedUSSOC 2 +3SShayan EffatiCritical20/06/2026
MongoDB9 listedUSSOC 2 +2RRuben DasMedium15/06/2026
Twilio14 listedUSSOC 2 +2SShayan EffatiMedium15/06/2026
Zendesk11 listedUSSOC 2 +1EErik HenningsLow18/06/2026
AgentAlways on
Continuous vendor monitoringWatches connected systems for changes and updates the register itself.
Checking Cloudflare for changes…Checking Datadog for changes…Checking Snowflake for changes…
3 updatedin the last 24 hours
Live, actionable registriesA spreadsheet is out of date the moment you save it. A registry moves when the business does.
Expert-crafted, or your ownReady registries for any domain, or build and adapt your own.
Agents keep it currentNew vendors, changed owners, lapsed reviews, all updated without anyone chasing.
Full documentation managementPolicies, registries, and every document an auditor asks for. Generated from your program, updated as it changes, and ready for your team or your agents to use.
Full lifecycle, trackedEvery document carries who can see it, who approved it, and its full version history.
Traced to the paragraphKnow exactly which paragraph fulfills which obligation, and whether it's actually being followed.
Generated, and kept currentDraft a document from your program in minutes. When the program changes, updating it is one step, not a rewrite.

Smart by default, yours to shape

Registers and artifacts that already know what your business has to track, kept alive and current as your business changes.

Smart by default, yours to shape

Registers and artifacts that already know what your business has to track, kept alive and current as your business changes.

Smart by default, yours to shape

Registers and artifacts that already know what your business has to track, kept alive and current as your business changes.

Vendor registrySearch vendors...NameStatusOwnerProviderDatadogActiveAAnna SDatadogOktaActivePPeter OOktaSnowflakeProspectingNo ownerSnowflakeVercelActiveAAnna SVercelHubSpotActivePPeter OHubSpotLinearIn renegotiationAAnna SLinearSlackActiveFFrank DSlack
Start from scratch, or from oursBuild a register field by field, or take one of ours and shape it.
Article 73 of the AI Act adds four fields to your incident registry:
  • Serious incident
  • AI system concerned
  • Causal link established
  • Reported to authority
Shall I fill them from your connected systems?
Anna SandbergASGo ahead
Adding from connected systems...Added from connected systems
It knows what you needLegal, security and compliance built in. New rules arrive as fields, not as homework.
Access review evidence
Asset registry
Incident Response Plan
Vendor concentration risk
Evidence collection
Contract scanner
Vendor onboarding
PDFSOC2-Q3-evidence.pdf
Incident escalation
SOC 2Compliant
Penetration test report
Training completion
DPIA
ISO 42001
Encryption standard
Subprocessor watch
Vendor concentration risk
Evidence collection run
Control coverage check
Risk registry
Incident escalation
Access Control Policy
Business Continuity Plan
Connected by defaultControls, obligations, registers and artifacts all know about each other. Change one and the rest follow.
Vendor registrySearch vendors...NameStatusOwnerProviderDatadogActiveAAnna SDatadogOktaActivePPeter OOktaSnowflakeProspectingNo ownerSnowflakeVercelActiveAAnna SVercelHubSpotActivePPeter OHubSpotLinearIn renegotiationAAnna SLinearSlackActiveFFrank DSlack
Start from scratch, or from oursBuild a register field by field, or take one of ours and shape it.
Article 73 of the AI Act adds four fields to your incident registry:
  • Serious incident
  • AI system concerned
  • Causal link established
  • Reported to authority
Shall I fill them from your connected systems?
Anna SandbergASGo ahead
Adding from connected systems...Added from connected systems
It knows what you needLegal, security and compliance built in. New rules arrive as fields, not as homework.
Access review evidence
Asset registry
Incident Response Plan
Vendor concentration risk
Evidence collection
Contract scanner
Vendor onboarding
PDFSOC2-Q3-evidence.pdf
Incident escalation
SOC 2Compliant
Penetration test report
Training completion
DPIA
ISO 42001
Encryption standard
Subprocessor watch
Vendor concentration risk
Evidence collection run
Control coverage check
Risk registry
Incident escalation
Access Control Policy
Business Continuity Plan
Connected by defaultControls, obligations, registers and artifacts all know about each other. Change one and the rest follow.
Vendor registrySearch vendors...NameStatusOwnerProviderDatadogActiveAAnna SDatadogOktaActivePPeter OOktaSnowflakeProspectingNo ownerSnowflakeVercelActiveAAnna SVercelHubSpotActivePPeter OHubSpotLinearIn renegotiationAAnna SLinearSlackActiveFFrank DSlack
Start from scratch, or from oursBuild a register field by field, or take one of ours and shape it.
Article 73 of the AI Act adds four fields to your incident registry:
  • Serious incident
  • AI system concerned
  • Causal link established
  • Reported to authority
Shall I fill them from your connected systems?
Anna SandbergASGo ahead
Adding from connected systems...Added from connected systems
It knows what you needLegal, security and compliance built in. New rules arrive as fields, not as homework.
Access review evidence
Asset registry
Incident Response Plan
Vendor concentration risk
Evidence collection
Contract scanner
Vendor onboarding
PDFSOC2-Q3-evidence.pdf
Incident escalation
SOC 2Compliant
Penetration test report
Training completion
DPIA
ISO 42001
Encryption standard
Subprocessor watch
Vendor concentration risk
Evidence collection run
Control coverage check
Risk registry
Incident escalation
Business Continuity Plan
Connected by defaultControls, obligations, registers and artifacts all know about each other. Change one and the rest follow.

FEATURES

Discover more features

FEATURES

Discover more features

FEATURES

Discover more features

Want to see what Freda can do for you?

Want to see what Freda can do for you?

Want to see what Freda can do for you?