InfraTrace360 v9 is here — a redesigned Control Room interface, one-click online updates and two-step sign-in for every account. See what's new

IT Governance & ISO Compliance

Everything you need for IT compliance in one place

Track exceptions, incidents, policies, vendors, employees, and more from a single dashboard. InfraTrace360 makes ISO compliance simple, auditable, and affordable.

26+
Compliance Modules
Zero
External Dependencies
On-Prem
Full Data Control
InfraTrace360
InfraTrace360 interactive dashboard
86% ISO 27001 readiness
Expiry alert3 vendor contracts due within 10 days
Two-step sign-inEnforced for every account

Especially built for

  • IT Governance
  • &
  • ISO Compliance
  • English & Arabic (RTL)
Powerful Features

Everything you need for audit readiness

InfraTrace360 provides a complete toolkit to manage IT governance, track compliance, and pass audits with confidence

ID

Interactive Dashboard

A live overview of your compliance posture with clickable donut charts and KPIs — click any segment to drill straight into the matching records.

RR

Risk Register

A full risk register with 1–5 likelihood and impact scoring that auto-calculates a risk score and priority, plus controls, triggers, response strategy and review dates.

Inline Editing

Update records inline with ease — no more tedious one‑by‑one edits. Save valuable time and focus on the tasks that truly matter.

Attachments Everywhere

Attach supporting files to any record in any module — employees, incidents, risks, vendors, service accounts and more — for complete evidence trails.

Custom Fields

Add custom text, number, date, select, yes-no or file-upload fields to any module, and change a field's type any time. Tailor the system to your exact needs.

DD

Import & Export

Bulk import records from XLSX or PDF files. Export any module's data — every export is logged — to share with auditors or stakeholders.

Full Audit Log

Every create, update, delete, import and export is logged with a before/after diff, timestamp, IP address and username. Ready for compliance reviews.

DM

Dark Mode

Reduce eye strain with a built-in dark theme. Persisted in your browser preferences for a consistent experience..

Backups & In-App Updates

Update the whole app by uploading a ZIP from the admin panel, with automatic backups so you can always roll back — no server access needed.

AI-Powered

Built-in AI Document Analysis

A self-contained analysis engine reads your policies and procedures and scores how well each one aligns with ISO 27001, ISO 20000 and ISO 22301 — running entirely on your own server, with no external AI service, no API keys, and no data ever leaving your hosting.

On-Demand Analysis

Analyse any document with one click. The engine extracts the text from Word, PDF, Excel and more, then scores its content against each standard's requirements — instantly, one file at a time, with a live progress indicator.

Smart ISO Tag Suggestions

For every document, the engine determines the best-fit standard from its content and suggests the right ISO tag — so untagged files get classified automatically, and you apply the suggestion with a single click.

Mis-Tag Detection

If a document is tagged for one standard but its content matches another, the system flags it as a possible mis-tag and recommends a correction — helping you catch filing mistakes before an audit does.

Automatic Metadata Extraction

The engine reads the version, reference number, approval date, status, classification and approver name printed inside each document, and offers them as one-click fills for the fields that are still empty.

100% self-hosted · your documents never leave your server

Measure & Report

Prove it, don't just document it

Certification asks two things beyond your documents: that you measure how the system performs, and that management reviews it. InfraTrace360 does both from the records you already keep.

98

KPIs ready to use

Pre-filled performance measures across ISO 27001, ISO 20000 and ISO 22301 — incidents, patching, penetration testing, access reviews, backups, service levels, continuity exercises and more. Each one names the clause or control it evidences.

You enter the figure. That's it.

Every KPI carries its own target and knows whether higher or lower is better. Type the measured value and the result — met or not met — is worked out for you, then rolled up per standard.

The management review, generated

One click produces the review pack: document readiness, KPI results for the period, the risk picture, incidents, and a plain summary of what needs attention — laid out in the order the standard asks for, ready to print or save as PDF.

Built for the audit conversation

Findings are stated plainly — KPIs that missed target, risks past their review date, documents still missing — with every section labelled so standard-specific figures are never confused with organisation-wide ones.

Threat Intelligence

World Monitor — see threats before they reach you

Governance is not only about what happens inside your organisation. World Monitor brings trusted, reputable security feeds into one place and — where relevant — checks them against your organisation, so exposure surfaces early. Everything opens safely inside the platform for reference only.

Pwned Passwords

Browse known data breaches and instantly see whether your organisation appears among them, with matching entries clearly flagged.

Dark Web

Focus on breaches sourced from information-stealing malware and stealer logs — the credential dumps traded on dark-web markets — with the same organisation check.

CVE Catalogue

Review vulnerabilities being actively exploited in the wild, including those tied to known ransomware campaigns, with remediation due dates and guidance.

Playbook Alerts

See the latest malicious web addresses and malware samples observed in the wild. Dangerous links are shown safely disarmed, so they can never be opened by accident.

Reputable open feeds, malicious links disarmed for safe reading, and a live count of items reported today on every feed.

New in v9

Security and operations, built in

The things auditors ask about and administrators worry about now ship with the platform — no plugins, no extra services, nothing to wire together.

The Control Room interface

Version 9 is a complete visual renovation: a fixed command rail, a frosted top bar with a live signal line, IBM Plex typography in English and Arabic, dashboards that draw themselves in, and bottom-sheet dialogs on phones. Light and dark themes, and it respects “reduce motion”.

Two-step sign-in for everyone

Every account confirms a six-digit code from Microsoft Authenticator, Google Authenticator or any TOTP app. Admins can reset a lost phone, and every enrolment and failed code is written to the audit log.

SIEM / SOC detections

Pull detections from any SIEM with a REST endpoint — nested, Wazuh-style data included — review them by severity, and turn one into an incident with a single click.

Active Directory

Connect LDAP / Active Directory to see directory accounts next to your registers, with a health indicator and an activity log for every connector.

Expiry alerts that send themselves

A daily HTML digest of exceptions, service accounts, guests, vendor contracts and calendar tasks that are about to expire or already overdue — sent over the Mailtrap API, with no SMTP ports and no cron job to set up.

One-click online updates

Check for a new version from Settings and apply it in place. A full backup is taken first, and your configuration, uploads and backups are never touched.

English and Arabic, side by side

Every screen, export and audit entry is available in Arabic with a mirrored right-to-left layout — while phone numbers, e-mails and codes keep their left-to-right order.

Runs where you already host
  • cPanel / Apache shared hosting
  • Windows Server with IIS
  • PHP 7.4 or newer
  • MySQL or MariaDB
  • No Composer, Node or Docker
26 Compliance Modules

Complete coverage for ISO 27001, 20000 & 22301

InfraTrace360 helps you operate and evidence 30+ ISO 27001:2022 Annex A controls across access management, asset inventory, supplier security, incident and risk management, and audit logging

Employees

Full employee register with status, department, manager, and photo tracking (add or remove photos any time)

Exceptions

Security exceptions with justifications, expiry dates, and file attachments

Incidents

Incident register with severity, action taken, and lessons learned

RR

Risk Register

Risk register with likelihood/impact scoring, auto-calculated priority, controls, response strategy and review dates

AI

Assets Inventory

Track devices by IP, hostname, owner, location, and operating system

DI

Document Inventory

All documents with classification, version control, and file storage such as policies and procedures

Vendors

Vendor management with contracts, NDA tracking, criticality, status and monitoring frequency

App Access

Employee-application role mapping with login IDs, grant dates and status tracking

Service Accounts

Service account inventory with expiry monitoring and login restriction

IC

ISMS Calendar

Smart calendar organizes infosec tasks, audits, and committee activities

User Access Certification

Single-page audit view combining access, exceptions, and assets per employee

Applications

Master application registry with assignable roles for access control matrices

Expiring Soon

Proactive alerts for expiring exceptions, contracts, and service accounts

Guests

External personnel and contractor register with sponsor, host and expiry tracking

Approved Apps

Whitelist of approved software with versions, approver and least-privilege notes

Audit Log

Complete activity trail of every create, update, delete, import and export

KPI Measurement

Performance measures for all three standards, pre-filled with 98 KPIs tied to their clause. Enter the figure — met or not met is worked out from the target

Management Review

Generates the management review pack from your live records, structured to the inputs the standard requires, ready to print or save as PDF

World Monitor

Outside-in threat intelligence, grouped in one place — data breaches, dark-web credential leaks, actively exploited vulnerabilities and live malware activity, with a daily count on each feed

Pwned Passwords

Browse known data breaches and instantly see whether your organisation appears among them, with matching entries clearly flagged

Dark Web

Focus on breaches sourced from information-stealing malware and stealer logs — the credential dumps traded on dark-web markets — with the same organisation check

CVE Catalogue

Review vulnerabilities being actively exploited in the wild, including those tied to known ransomware campaigns, with remediation due dates and guidance

Playbook Alerts

See the latest malicious web addresses and malware samples observed in the wild — dangerous links shown safely disarmed so they can never be opened by accident

Compliance Readiness

Per-standard readiness dashboards for ISO 27001, ISO 20000 and ISO 22301 — met, partial and missing documents scored from your library, with duplicate merging

Active Directory

Directory accounts from LDAP / Active Directory listed alongside your registers, with connector health and an activity log

SIEM / SOC

Real-time detections pulled from your SIEM with severity filters and auto-refresh — convert any detection into an incident in one click

See it in action

A clean, fast interface your whole team will actually use

Every module shares the same crisp layout — sortable tables, inline editing, status filters, and file attachments — so there is nothing new to learn as you move between them

Interactive dashboard

Interactive dashboard

Clickable donut charts and KPI cards — click any segment to drill straight into the matching records.

Risk Register

Risk Register

Likelihood × impact scoring with auto-calculated priority, controls, response strategy and review dates.

Employees
Employees
Arabic Interface
Arabic Interface
Calendar View 
Calendar View 
Internal Messages
Internal Messages

Click any screenshot to enlarge it

Multi-Standard Ready

Built for compliance, from the ground up

Every feature in InfraTrace360 is designed with ISO requirements

Multi-Standard Control Coverage
  • A.5.9 - Inventory of information & associated assets
  • A.5.12 - Classification of information
  • A.5.15 - Access control
  • A.5.16 - Identity management
  • A.5.18 - Access rights (provisioning & review)
  • A.5.19 - Information security in supplier relationships
  • A.5.22 - Monitoring & review of supplier services
  • A.5.24 - Incident management planning & preparation
  • A.5.25 - Assessment & decision on security events
  • A.5.26 - Response to information security incidents
  • A.5.27 - Learning from incidents
  • A.5.28 - Collection of evidence
  • A.5.37 - Documented operating procedures
  • More available in the control coverage link below...

No more spreadsheet chaos

Organizations waste countless hours managing compliance through scattered spreadsheets, email threads, and disparate tools. InfraTrace360 unifies everything in one purpose-built system.

With full audit trails, role-based access, and customizable fields, you can adapt the platform to any compliance framework while maintaining rigorous documentation standards.

  • Pre-configured registers mapped to ISO 27001, 20000 & 22301
  • Per-standard readiness dashboards scored from your documents
  • File attachments for evidence collection and audit trails
  • Export-ready reports for external auditors
  • Email notifications for expiring items and critical events
Why InfraTrace360

Built different. On purpose.

Unlike other bloated platforms, InfraTrace360 is lightweight and can work on Linux, Windows and even Mac

Arabic Enabled

The first and only Arabic-enabled platform for ISO compliance and information security in the region, built to empower organizations with clarity, confidence, and compliance.

Full Data Ownership

On-Prem means your data stays on your servers. No third-party processing, no data leaks, no monthly overages.

Built-in Ai Engine

It reads the version, reference number, approval date, status, classification and approver name inside documents, and helps you filling for the fields automatically.

In-App Updates

Upload a ZIP file and update directly from the admin panel. Automatic backups ensure you can always roll back.

Role-Based Access

SuperAdmin, Admin, Data Entry, and User roles with granular permission control. Restrict tabs per user or role.

No Learning Curve

Intuitive interface with inline editing, drag-and-drop column management, and a clean, familiar spreadsheet-like layout.

Subscription Plans

Simple, transparent pricing

No hidden fees, no per-user charges, no surprise overages
One subscription plan covers your entire organization

Basic

Core people, vendor and exception tracking for small teams.

$4,999/yr
annually
Get Started
  • Dashboard with live charts
  • Employees & Guests
  • Service Accounts
  • Vendors
  • Exceptions register
  • File attachments on every record
  • Audit log
  • Import / Export (XLSX & CSV)
  • Up to 3 admin users
  • Email support
  • Asset Inventory, Applications & App Access
  • Incidents & Expiring Soon
  • System updates from the admin panel
  • SMTP email, integrations & branding
Enterprise

Full access to every module, integrations and branding.

$8,999/yr
annually
Get Started
  • Everything in Professional, plus:
  • Ai Document Analyzer
  • Risk Register with scoring
  • Calendar & recurring compliance tasks
  • Document Inventory
  • Approved Apps whitelist
  • User Access Certification (with PDF export)
  • Active Directory / LDAP & Webhook/REST integrations
  • Custom branding (logo & colors)
  • Domain & fingerprint license binding
  • Premium support (24hr response)

Every plan includes a 14-day money-back guarantee.

FAQ

Frequently asked questions

Can't find what you need? Send us a message and we'll answer within one business day.

Get Quotation

InfraTrace360 platform works on any web server that supports PHP 7.4+ running minimum on 1 Core CPU, 1 GB RAM, 5 GB storage and 1 MySQL database.

If you are planing to host it online, you can get your own online hosting plan from our certified partner HostingOthers.com with very low prices starting from $6.99 per month

Yes, this is a great choice! our support team can install it on your premises with the help of your IT department for no additional charges within Kuwait or remotly if your business is based on different country. with this choise, your data never leaves your server.

Absolutely. Export your data as XLSX from your systems, then use the built-in import feature to load it into InfraTrace360. The column headers will guide you through the mapping process.

The application becomes read-only. You can still view and reach all your data. To re-enable writes (create, edit, delete, import), simply get in touch to renew your license.

You can renew your license by contacting us via the contact us form.

Yes. we are located in Kuwait. If you needed any help with our platform, our team will be glad to assist you.

Yes. Admins can add custom fields (text, number, date, dropdown, yes/no) to any module. You can also rename any built-in field label. Changes update everywhere — forms, tables, exports, and print views.

Yes. Every account signs in with a password plus a six-digit code from an authenticator app such as Microsoft Authenticator or Google Authenticator. Setup is a one-time QR scan, and an admin can reset it if a phone is lost or replaced.

Yes. The whole application — screens, exports and the audit log — switches between English and Arabic, with a fully mirrored right-to-left layout.

Yes. The same package installs on Windows Server with IIS as well as on cPanel/Apache. The installer detects the web server and writes the matching protection rules for you.

Ready to take control of your compliance?

Join hundreds of organizations that use InfraTrace360 to manage IT governance, pass audits, and stay ISO compliant

Chat with us