AI observation drafting
Enter a title and a short note. AI drafts a complete observation with risk rating, likelihood and impact, NIST CSF mapping, and actionable recommendations.
Stop forcing observations into spreadsheets that were never built for it. SecurityTrackr automates the cumbersome parts of security work. It drafts your findings, runs the risk math, and writes the board report, so your team's hours go to decisions, not paperwork. AI at every step because it earns its place there, not bolted on as a chatbot.
Claude, ChatGPT, Copilot, Gemini, or an agent you run yourself can already work where security changes first appear. Connect that agent over MCP and let it run on your schedule. SecurityTrackr gives the work a governed home instead of leaving it in a chat, an inbox, or somebody's memory.
This is not another scanner. It is the record that lets agents do the reading, filing, and follow-through across security observation management, while people stay responsible for the decisions that matter.
It finds a new issue or update to an open observation where the work already happens: emails, files, and Teams chat, as well as scan results, vendor notes, and pentest reports.
The agent can prepare new observations, update existing records, run fresh risk assessments, and create detailed reports from the live data in your register.
An always-current security register that shows your real security position, rather than the last time somebody found an hour to update a spreadsheet.
The agent has the register context it needs, so it can answer useful questions instead of guessing from whatever is in the current chat.
Hey, do we have any issues with our backups?
search_observationsResult:7 results · match_mode: precise
Yes. There are seven related observations in the register, covering backup, business continuity, and restore testing. What would you like to know?
Make a board status update. I need to argue for funding to replace our ageing cloud backup platform.
get_observationResult:OBS-014 · risk High · Mitigating · 3 recommendations
list_observation_evidenceResult:4 files · latest restore test 2026-03-11
I'll make the PowerPoint from the live register: the current risk, the restore-testing gaps, the case for replacement, and the funding decision needed from the board.
SecurityTrackr supplies the current, governed data. Your agent makes the deck in the tools your team already uses.
Humans decide. The team decides what to mitigate, accept, and close; the agent does the heavy lifting, with duplicate review and an audit trail behind every change.
Every finding, decision, and control in one place, captured in clear, consistent language the whole team can act on, not locked in one person's head or buried in a spreadsheet tab.
AI drafts each finding, scores likelihood and impact, maps it to NIST CSF and ISO 27002, and writes the report. The tedious scaffolding is handled, so your time goes to the calls only a human should make.
Observations are written in plain, consistent language and gathered in one register. New hires, auditors, and execs all read the same clear picture. Shared knowledge, not tribal memory.
Don't follow a finding? Ask the AI Advisor. It has the full context of every observation and explains the risk, the fix, and the why in terms anyone on the team can act on.
The real interface, not a screenshot. It walks through making an observation on its own. Hover to pause, or click a tab to explore.
Just describe what you found. The AI drafts the title and the rest of the structured finding.
Describe what you found in your own words. The AI will use this to write the formal finding.
The more context you provide, the more precise and relevant the AI-generated observation will be.
List all systems, services, or assets involved.
Describe any controls already in place. The AI will factor these into its risk assessment.
No complex setup. No lengthy onboarding. A security register that's ready when you are.
Create a free account in seconds. No credit card, no payment required. Add your organisation details and invite your team.
Add observations manually, bulk-import from CSV or a PDF pentest report, or pull in your organisation's public internet exposures from OSINT sources. AI drafts each one with risk, likelihood, impact, recommendations, and framework mappings.
Decide Mitigate or Accept on each observation, track recommendations to completion, and generate branded PDF reports (Executive Summary, Risk Register, Mitigation Progress, or NIST CSF Compliance) with audience-specific narratives drafted by AI.
From drafting and risk analysis to integrations, diagrams, treatment tracking, and audience-specific reports. Each capability shipped because it measurably accelerates the work, not because an LLM happened to be available.
Free forever, no credit card. Everything here carries over into Pro.
Enter a title and a short note. AI drafts a complete observation with risk rating, likelihood and impact, NIST CSF mapping, and actionable recommendations.
Select a field on an observation and let AI sharpen it into tighter summaries and clearer recommendations. Guide the AI with custom instructions.
After implementing controls or closing out recommendations, let AI re-score likelihood, impact, and residual risk. Review the proposed changes side-by-side before applying.
Before a new observation is finalized, AI compares it semantically against your existing library and flags likely duplicates by keywords, categories, and meaning, not just exact matches.
Link observations with named relations: related to, part of, worsens, depends on. As you create, manually or in bulk, AI spots existing findings that connect, explains why, and keeps that justification on the link for both sides to see.
Your company profile (industry, country, known domains and IP ranges, and a short background) rides along in every AI prompt, so drafts, risk scoring, and recommendations come back grounded in your environment, not generic boilerplate.
Generate architecture, attack-path, or Lockheed kill-chain diagrams for any observation. The AI grounds each diagram in the documented systems and controls. Refine with comments and export to PNG.
Drop in a CSV of findings and AI enriches each row into a complete observation. Parsing happens in your browser (the file bytes never leave your machine), with background duplicate detection across the batch.
Decide Mitigate or Accept on every observation. Track recommendations through Open, In Progress, and Completed. When all reach a terminal state, the observation auto-moves to Mitigated. Completed work rolls into a separate Deployed Controls list.
Search matches more than titles. It indexes affected systems, the full observation text, and the AI-generated keywords behind each finding. Light stemming maps singular to plural, so you surface the right observation by meaning and context, not exact wording.
Every sign-in, change, export, and team action is captured with the user, IP address, and timestamp. Included on every plan, viewable in-app and exportable as CSV for compliance reviews and internal governance.
Unlocked on the €19.95 / seat / mo Pro plan.
Pro routes generative AI features through markedly more capable models, for sharper observation drafts, deeper risk analysis, and stronger recommendations. A quality lift across the whole app, not just a single feature.
Open a multi-turn chat grounded in a specific observation. Ask follow-up questions, request remediation strategies, or drill into technical details. The advisor always has the full context.
Bring in the internet-exposed services that public OSINT sources have already indexed for your organisation's IP ranges. SecurityTrackr reads existing public data, it never probes or scans systems itself. AI converts each exposure into a fully-drafted observation with risk, likelihood, impact, and recommendations.
Upload a pentest or audit report (PDF) and AI extracts the individual findings (title, risk, affected systems, description). Review, select, and import only the ones you want.
Four polished templates (Executive Summary, Risk Register, Mitigation Progress, and NIST CSF Compliance Mapping), each with an audience-specific narrative drafted by AI. Live data, filterable by period, risk, status, or assignee. PDF download.
Assign observations to specific team members and leave comments in a thread to follow up on a finding or capture your own notes. Owner and member roles keep responsibility clear.
The managed Advanced AI tier defaults to Anthropic (Claude) in the US under our DPA and Zero Data Retention agreement. Switch in one click to Mistral (EU data centres, also DPA + ZDR) when data residency matters, or to OpenAI (GPT-5.6) when GPT is your house standard. No key to manage.
Route every generative AI request through your own OpenAI, Anthropic, or Mistral account, so findings run under the data-processing terms, retention, and region you agreed directly with that provider. Semantic-matching embeddings remain on a separate platform-managed path when enabled. The key is stored encrypted under your per-org key.
Connect Microsoft Entra ID, Okta, Google, or any OIDC provider so the team signs in with corporate credentials. Enforce SSO-only login and auto-provision new members as they join.
Connect agents, scripts, and custom integrations through the versioned REST API or the OAuth-authenticated MCP server. Use direct API calls for automation, or MCP tools for agent clients that need to work with the register.
Start free and upgrade when you need more. No hidden fees.
For small teams getting started. Built-in AI included, no setup or API key needed.
Advanced AI included by default, powered by Anthropic (Claude) for markedly richer drafting, deeper risk analysis, multi-turn Security Advisor chat, and audience-specific report narratives, processed under our DPA and Zero Data Retention agreement with no training on your data. Need EU residency or prefer GPT? Switch the managed tier to Mistral (EU data centres, DPA + zero data retention) or OpenAI (GPT-5.6) in one click. REST API and agentic (MCP) integrations, team collaboration, and SSO.
Both tiers run on shared infrastructure with data logically separated through encryption and access controls. All data is stored in EU data centres.
Questions about plans, seats, or invoicing? Contact sales.
We built SecurityTrackr because we needed it ourselves. Your findings are protected with the same rigour you bring to your own assessments.
Sensitive observation fields, uploaded files, and API keys are encrypted with a key unique to your organisation. SecurityTrackr staff have no interface for browsing or decrypting customer content, and raw database or object-storage access reveals ciphertext only. The only operator-assisted path is the GDPR data export that SecurityTrackr is legally required to facilitate; it releases data only after the customer supplies a one-time authorisation code sent to their registered email address.
TOTP-based MFA is required for every account, with no opt-out. Sign-in is protected with an extra layer of defence by default.
All customer data stored by SecurityTrackr is kept in EU-jurisdiction data centres. Uploaded files are encrypted before entering object storage. AI processing location and retention depend on the provider selected by the customer and are disclosed separately.
Every login, change, and export is logged. Download audit logs as CSV for compliance reviews and internal governance.
Every uploaded evidence file is checked against VirusTotal’s malware-reputation database (by SHA-256 hash only, so the file itself never leaves our infrastructure) before it can be downloaded. Flagged attachments are blocked from download.
Free to use. No credit card required. Set up in minutes.
Create free account