Copla is a GRC and compliance automation platform focused on ICT and cyber regulation such as DORA, NIS2, ISO 27001, the EU AI Act and the Cyber Resilience Act. The platform covers compliance, risk, vendor and document management, an ISMS, incident management and DORA incident reporting, plus a DORA Register of Information with XBRL-CSV export. AI assists with drafting risks and policies, while human CISOs review the work in a service the vendor calls "CISO as a Service". Copla is sold as a subscription to an online platform and targets regulated European firms.
Copla is based in Vilnius, Lithuania. According to the vendor's help centre, Copla Registry data is stored in the European Economic Area, in Lithuania and in Frankfurt am Main, on Amazon Web Services infrastructure, and is not moved outside the EEA without documented client instruction. AWS is a US company, which some organisations treat as a jurisdiction consideration. Copla reports ISO/IEC 27001:2022 certification. No self-hosted or open-source edition is described. These details cover the register; confirm whether other modules are hosted the same way.