Next-generation GRC platform

Built by engineers,
designed for decision-makers

The expertise of a cyber consultancy in a single tool. AI-automated ISO 27005 risk management approach, 8 compliance frameworks, a sovereign platform hosted in France.

CISOs & Cyber teams
CIOs & IT Departments
SME & Mid-market CEOs
DPOs & Compliance
5 ISO 27005 phases
8 Integrated frameworks
100% Sovereign AI
12
Critical risks
87%
Compliance
24
Monitored assets
Industry sectors covered

AI at the service of ISO 27005

Galea integrates a cyber-specialist European sovereign AI engine that automates the ISO 27005 risk management approach, generates contextual risk scenarios and maintains ISO 27005 methodological rigour.

The ISO 27005 risk management approach, automated

1
Scoping & Framework
2
Risk sources
3
Strategic scenarios
4
Operational scenarios
5
Risk treatment
ISO 27005 scales G1–G4 / V1–V4
RS/TO pairs (Risk Sources / Targeted Objectives)
Attack paths: Recognise → Enter → Find → Exploit
MITRE ATT&CK mapping
01
Scenario generation

3 to 5 ISO 27005 scenarios per asset, with risk sources, attack paths and MITRE ATT&CK techniques

02
AI vs Expert dual scoring

AI suggests an initial score on the 4x4 matrix, the expert revises it with justification. Full traceability

03
Contextual recommendations

Action plans adapted to the sector and maturity level, classified according to the G·P·D·R model

04
Financial risk quantification

Annual financial exposure, calculated on modelled attack paths

4x4 risk matrix
G4G3G2G1
R3
R1
R4
R2
R5
R6
V1V2V3V4

Manage your compliance on all fronts

Audit multiple regulatory and normative frameworks simultaneously. Galea calculates your coverage rate in real time.

ISO 27001:2022

Information security management system. The 93 Annex A controls are pre-loaded, with per-domain scoring and Statement of Applicability (SoA) tracking.

93 pre-loaded controls
Automatic per-domain scoring
SoA (Statement of Applicability) tracking
Certification report export
Compliance rate
87%
76/93 controls covered 12 in progress

NIS2

European directive on the security of network and information systems. Classification by category (essential/important), 24h early warning, 72h notification obligations, and mandatory cybersecurity measures.

Essential / important entity classification
Incident notification obligations
Article 21 cybersecurity measures
Fines up to €10M or 2% of turnover
Compliance rate
70%
7/10 measures covered 1 in progress

DORA

Digital Operational Resilience Act. European regulation on digital operational resilience for the financial sector. Penetration testing, third-party ICT risk management, and incident reporting.

ICT risk management
Operational resilience testing
Third-party ICT risk management
Incident reporting to authorities
Compliance rate
64%
32/50 requirements covered 8 in progress

HDS & GDPR

Health Data Hosting and General Data Protection Regulation. Processing register, impact analysis (DPIA), data subject rights tracking, and mandatory HDS certification.

GDPR processing register
Data Protection Impact Assessment (DPIA)
HDS certification
Data subject rights tracking
Compliance rate
91%
GDPR: 45/50 articles covered HDS: certified

Your data stays in France.
Our AI too.

In an uncertain geopolitical context, the location of your risk and compliance data is a strategic issue. Galea guarantees that nothing leaves European territory — neither your data, nor the AI models that analyse it.

🇫🇷
Sovereign hosting (France)

Certified European datacenter, ISO 27001 and HDS certified. No transfers to the United States.

🧠
European sovereign AI

Models trained and hosted in Europe. No dependency on OpenAI, Google or Amazon.

🔒
GDPR native

Designed for European compliance from day one. Not an adapted US product.

Our sovereign infrastructure
Galea PlatformFrance — Sovereign French datacenter
🇫🇷
Sovereign AI engineEurope — sovereign models
🇫🇷
DatabaseFrance — encrypted at rest
🇫🇷

From your IT context, Galea produces your analyses.

Galea absorbs your environment and challenges, then produces actionable risk scenarios and compliance deliverables — in a fraction of the time of a consulting firm.

Your IT context Architecture context, dependencies, environments
IT asset inventory Applications, servers, databases, cloud
Company profile & context Sector, size, regulations
analysis
AI Engine
Sovereign analysis engine · ISO 27005 method
generates
ISO 27005 risk scenarios 3–5 scenarios per asset
Action plans & Compliance G·P·D·R, PDF/PPTX/XLSX exports
Financial impact Annual financial exposure, ROI
Demo video — 90 seconds
1 Upload a document
2 AI generates a scenario
3 Matrix updated
4 PDF export
P. PHISHIA phishia.fr ↗

Expert support
beyond the tool

Galea is more than software. With our Phishia support service, a team of cybersecurity engineers guides you through your GRC journey: initial audit, configuration, training and quarterly reviews.

Initial audit & ISO 27005 scoping

A Phishia consultant runs your 5 workshops with you, leveraging Galea's AI

Training & awareness

Training sessions: platform usage, cyber best practices, phishing simulation

Quarterly review & board reporting

Review of your posture every 3 months, preparation of reports for management

Discover phishia.fr Request a support quote
Phishia Support
PhaseInitial audit
Duration2–4 weeks
ConsultantSenior ISO 27005
Target certificationISO 27001
Included in the support package:

Initial audit, guided ISO 27005 risk assessment, team training, 4 quarterly reviews, certification preparation, priority support.

Calculate your savings with Galea

Estimate the current cost of your cybersecurity and discover how much you could save.

Estimated annual savings
470 000 €
Estimated traditional cost 770 000 €/yr
Cost with Galea 300 000 €/yr
Request a personalised demo

A plan adapted to your cyber maturity

Start for free, scale as your needs grow.

SMEs & startups
Essential
To structure your GRC approach
1 000€/month
  • ISO 27005 AI — 50 analyses/month
  • 3 frameworks (ISO, NIS2, GDPR)
  • Risk register + 4x4 matrix
  • Action plans + PDF/XLSX exports
  • 5 users
Get started
Enterprise
Advanced
Custom deployment
On request
  • Everything in Standard +
  • Unlimited TPRM suppliers
  • REST API + on-premise
  • 99.9% SLA + account manager
  • Unlimited users
Request a quote
Free trial — No credit card

Ready to secure your organisation?

Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.

Already a customer? Go to the platform