Quick answers

Frequently asked questions

Straightforward answers to common account, module and support questions.

How do I log in?
Go to the PurpleWASP login page, enter your email address and password, then complete two-factor authentication when it is required. Use the password reset link if you no longer know your password.
What modules are available?
PurpleWASP supports Policy Management, Risk Management, Asset Management and Compliance Management, together with supporting capabilities such as quizzes, reporting, messaging, notifications and PurpAI assistance.
Where can I find items assigned to me?
Start with your dashboard and notifications, then open the relevant module. Your view depends on your role and may include policy acknowledgements, approval requests, risk actions, asset responsibilities or evidence tasks.
How do I create a policy?
A Policy Manager can create a policy from a template or blank record, complete its metadata and content, then submit it through the configured review and approval workflow before publication and assignment.
How do I add and assess a risk?
Create the scenario in the risk register, assign an owner and category, then complete the appropriate CIA or FAIR assessment. Add controls and actions before recording whether the exposure will be reduced or handled through a risk exception.

Follow the detailed guide.

How do I import assets?
Use the current asset import template and validate required fields before uploading. Check owner and custodian identities, date formats, blank rows and duplicate technical identifiers. Test a small sample before a large import.
How does compliance evidence work?
Evidence is attached to the relevant control, obligation or audit request with enough information for a reviewer to understand its source, period, owner and purpose. The same evidence should only be reused where it genuinely supports each mapped requirement.
What roles exist in PurpleWASP?
Principal roles include Admin, Approver, Module Manager and User. Module Managers may be responsible for policies, risks, assets or compliance. Administrators can map system permissions to organisation-specific roles.
How do licensing limits work?
Plans may differ by seat count, module access, reporting, integrations and support. Administrators should review inactive accounts and current usage before requesting more seats or modules.
How do I contact support?
Use the support contact page. Include the affected module, record ID, timestamp, screenshots, steps to reproduce and the complete error message. Remove unnecessary sensitive data.