Skip to content

Copla

Copla (formerly CyberUpgrade) is a Lithuanian GRC and compliance automation platform that combines AI-driven evidence collection with CISO-as-a-service guidance for frameworks like DORA, NIS2, and ISO 27001.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

Copla, rebranded from CyberUpgrade in 2025, sells compliance and security-program automation to small and mid-sized companies that need to demonstrate adherence to frameworks like DORA, NIS2, ISO 27001, SOC 2, PCI DSS, and MiCA but lack the headcount to run a dedicated GRC function. Its CoreGuardian engine automates evidence collection and continuous control monitoring, while a CoPilot layer uses AI to guide non-specialist staff through remediation and audit-readiness tasks. The company frames this as delivering “a full cybersecurity and compliance department” on a subscription, backed by human CISO guidance rather than software alone.

The company is Vilnius-based, founded in September 2023 by Aurimas Bakas, Andrius Minkevičius, and Nojus Bendoraitis, and closed a €2.5 million seed round backed by Superhero Capital, Specialist VC, FIRSTPICK, and NGL Ventures, followed by a further €650k raise reported in early 2024. Its target customers — SMBs, MSPs, fintechs, and mid-market financial institutions in the EU — are squarely the segment facing new compliance pressure from DORA and NIS2 without the budget for a full internal GRC team or a Big Four compliance retainer.

For CISOs at smaller regulated firms, or those managing compliance across a portfolio of smaller subsidiaries, Copla offers a lower-cost path to audit readiness than hiring dedicated GRC staff, with the tradeoff that its evidence-automation approach is best validated against a company’s own specific regulatory obligations before being relied on for a real audit.

Innovation Matrix Assessment

Innovation Velocity 6/10

Two years from founding to a rebrand plus a product platform covering DORA, NIS2, ISO 27001, SOC 2, PCI DSS, and MiCA indicates a fast-moving early-stage product team, though independent release-cadence data is not available.

Operational Value 5/10

As a two-year-old seed-stage company with a small team, Copla is operationally young; it has closed and delivered on a seed round and a follow-on raise, which is a positive but modest signal of operational maturity.

Market Momentum 6/10

A €2.5M seed round followed by an additional ~€650k raise within about a year, plus a rebrand signaling expanded ambition beyond pure cybersecurity compliance, are independently reported and indicate real investor and market momentum for an early-stage company.

Category Disruption 5/10

AI-assisted GRC automation for SMBs is a genuinely useful lower-cost alternative to traditional compliance consulting, but the compliance-automation category itself (Vanta, Drata, Secureframe, etc.) is increasingly crowded, limiting how disruptive the specific approach is.

Real-World Efficacy 4/10

No independent audit outcomes, named customer case studies, or third-party efficacy validation were found; claims of automating '95% of security tasks' are vendor-stated marketing language rather than independently verified.

Enduring Relevance 7/10

DORA and NIS2 came into force for a large population of EU financial and critical-sector entities that previously had no formal compliance obligation, making automated compliance tooling for exactly this segment highly timely and relevant.

Why CISOs Should Care

CISOs or founders at smaller EU-regulated companies newly in scope for DORA or NIS2 can use Copla to stand up an audit-ready control environment without hiring a dedicated GRC team from scratch.

What Makes It Different

Copla pairs automated evidence collection with human CISO-as-a-service guidance rather than shipping pure self-serve software, and targets EU-specific frameworks (DORA, NIS2, MiCA) that many US-centric compliance automation tools cover less deeply.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A fast-moving, well-funded early-stage entrant addressing a real and newly urgent EU compliance gap for SMBs; still needs more independent proof of audit outcomes before it can be judged on efficacy rather than promise.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: the '95% of security tasks automated' figure and specific efficacy of the AI CoPilot. Independently verifiable: the seed and follow-on funding amounts and investors (reported by Vestbee and Fintech.global) and the 2025 rebrand from CyberUpgrade to Copla (reported by Finovate and PitchBook).

Sources