Notes from the Aquil team
Product updates, practical ISMS guidance and lessons from building security tooling for real organizations.
How to get ISO 27001 certified (step by step)
The path to ISO 27001 certification, step by step: management mandate, a tight scope, gap analysis, the risk assessment, your SoA, internal audit and the two-stage external audit, with realistic timelines and costs.
Read articleWhy we added an AI embedding model (and where it runs)
We added text-embedding-3-small so Aquil can find your documents by meaning, not just by keyword. It runs in our own Azure region in Sweden, your text is never sent to OpenAI, and only a numeric vector is ever stored.
Read articleNIS2 vs ISO 27001: what's the difference?
One is binding EU law, the other a voluntary standard, yet they overlap more than they differ. How NIS2 relates to ISO 27001, and how to use one to satisfy the other.
Read articleCybersäkerhetslagen är här – en praktisk checklista för NIS2 i Sverige
Den nya cybersäkerhetslagen gör NIS2 till svensk lag och omfattar långt fler verksamheter än tidigare. Vilka berörs, vad kräver lagen och var börjar man? En praktisk checklista i sex steg.
Read articleThe Statement of Applicability (SoA): what it is and how to write one
What the Statement of Applicability is, why ISO 27001 certification hinges on it, what every row must contain, how it connects to your risk assessment, and how to keep it current instead of rebuilding it before every audit.
Read articleLet AI agents into your ISMS without handing over the keys
AI agents are good at exactly the work an ISMS is full of: drafting reports, walking through procedures, updating registers. The hard part was always access. Aquil's API and MCP service makes an agent a faithful stand-in for you, never a superset of you.
Read articleHow to run an ISO 27001 gap analysis (free template)
A practical guide to the ISO 27001 gap analysis, with a free Excel template covering clauses 4–10 and all 93 Annex A controls: how to run it, prioritize the gaps, and turn the result into a plan.
Read articleKnow in minutes whether you can win the deal
A procurement questionnaire lands and its security section quietly decides whether you can even bid. Instead of forwarding it to compliance and waiting days, get an honest per-requirement verdict the same day.
Read articleAnswer once, reuse everywhere: the capability ledger for service providers
Software and service providers answer the same security questions forever: one ISO audit, every customer's procurement questionnaire, the next framework. Answer each one once and reuse it everywhere.
Read articleCompliance you can prove
Auditors want evidence, a name against it, and a date. How Aquil's capability ledger turns compliance into answers you can actually prove, and keeps proving them as evidence ages.
Read articleHow Aquil keeps teams in sync: inside the process workflow engine
Security work is a team sport: incident response, onboarding and supplier reviews all cross team boundaries. How Aquil turns process diagrams into executable workflows, with handoffs that don't drop the ball.
Read articleYour gap analysis should be a living thing
A gap analysis in a spreadsheet is out of date the day after the workshop. How the Compliance Assistant keeps all 93 Annex A controls (and the frameworks next to them) continuously current.
Read articleStop writing your ISMS from a blank page
Policies shouldn't start in an empty document. How AI-assisted drafting, honest document conversion and built-in ownership turn ISMS documentation into a habit instead of a project.
Read article