The security register, finally built for the work.

Stop forcing observations into spreadsheets that were never built for it. SecurityTrackr automates the cumbersome parts of security work. It drafts your findings, runs the risk math, and writes the board report, so your team's hours go to decisions, not paperwork. AI at every step because it earns its place there, not bolted on as a chatbot.

01Built for the agentic era

Security posture management, brought into the agentic era.

Claude, ChatGPT, Copilot, Gemini, or an agent you run yourself can already work where security changes first appear. Connect that agent over MCP and let it run on your schedule. SecurityTrackr gives the work a governed home instead of leaving it in a chat, an inbox, or somebody's memory.

This is not another scanner. It is the record that lets agents do the reading, filing, and follow-through across security observation management, while people stay responsible for the decisions that matter.

  1. 01

    Your agent sees the change

    It finds a new issue or update to an open observation where the work already happens: emails, files, and Teams chat, as well as scan results, vendor notes, and pentest reports.

  2. 02

    It keeps the record current

    The agent can prepare new observations, update existing records, run fresh risk assessments, and create detailed reports from the live data in your register.

  3. 03

    What you get

    An always-current security register that shows your real security position, rather than the last time somebody found an hour to update a spreadsheet.

A conversation that starts with the real data

The agent has the register context it needs, so it can answer useful questions instead of guessing from whatever is in the current chat.

  1. Hey, do we have any issues with our backups?

  2. securitytrackr · mcp
    Tool call:search_observations
    query:
    "backup restore testing"
    status:
    "open"

    Result:7 results · match_mode: precise

  3. Yes. There are seven related observations in the register, covering backup, business continuity, and restore testing. What would you like to know?

  4. Make a board status update. I need to argue for funding to replace our ageing cloud backup platform.

  5. securitytrackr · mcp
    Tool call:get_observation
    observation_id:
    "cmg2r7k40003x8v1qb4d9lz2h"

    Result:OBS-014 · risk High · Mitigating · 3 recommendations

    Tool call:list_observation_evidence
    observation_id:
    "cmg2r7k40003x8v1qb4d9lz2h"

    Result:4 files · latest restore test 2026-03-11

  6. I'll make the PowerPoint from the live register: the current risk, the restore-testing gaps, the case for replacement, and the funding decision needed from the board.

SecurityTrackr supplies the current, governed data. Your agent makes the deck in the tools your team already uses.

Humans decide. The team decides what to mitigate, accept, and close; the agent does the heavy lifting, with duplicate review and an audit trail behind every change.

Why SecurityTrackr

One shared security brain for the whole team.

Every finding, decision, and control in one place, captured in clear, consistent language the whole team can act on, not locked in one person's head or buried in a spreadsheet tab.

Automate the busywork

AI drafts each finding, scores likelihood and impact, maps it to NIST CSF and ISO 27002, and writes the report. The tedious scaffolding is handled, so your time goes to the calls only a human should make.

One source of truth

Observations are written in plain, consistent language and gathered in one register. New hires, auditors, and execs all read the same clear picture. Shared knowledge, not tribal memory.

An AI teammate that explains

Don't follow a finding? Ask the AI Advisor. It has the full context of every observation and explains the risk, the fix, and the why in terms anyone on the team can act on.

01How it works

From a one-line note to a board-ready finding.

The real interface, not a screenshot. It walks through making an observation on its own. Hover to pause, or click a tab to explore.

SecurityTrackrWhat you'll be working in.

What did you find?

Just describe what you found. The AI drafts the title and the rest of the structured finding.

Your Observation464 of 2,000

Describe what you found in your own words. The AI will use this to write the formal finding.

i need a security observation on the fact that our company has not implemented dnssec on its domains. our websites hosts mainly informational web pages, but has individual web pages that handles customer uploaded documents, sometimes containing sensitive data. We are afraid that customers may be sitting on insecure networks and have traffic towards our websites intercepted. Our websites generally has HTTPS enabled and are redirecting all HTTP traffic to HTTPS.

Additional context

Optional

The more context you provide, the more precise and relevant the AI-generated observation will be.

Affected Systems / Assets0 of 2,000

List all systems, services, or assets involved.

e.g. FortiGate VPN Gateway (192.168.1.1), Azure AD (Production)
Existing Mitigating Controls0 of 2,000

Describe any controls already in place. The AI will factor these into its risk assessment.

e.g. VPN only accessible from corporate network, MFA enforced
Cancel
Generate Draft
EU data residency · AES-256 at rest · Mandatory MFA

Get started in minutes.

No complex setup. No lengthy onboarding. A security register that's ready when you are.

  1. Step 01

    Sign up and set up your organisation

    Create a free account in seconds. No credit card, no payment required. Add your organisation details and invite your team.

  2. Step 02

    Register your findings

    Add observations manually, bulk-import from CSV or a PDF pentest report, or pull in your organisation's public internet exposures from OSINT sources. AI drafts each one with risk, likelihood, impact, recommendations, and framework mappings.

  3. Step 03

    Treat, track, and report

    Decide Mitigate or Accept on each observation, track recommendations to completion, and generate branded PDF reports (Executive Summary, Risk Register, Mitigation Progress, or NIST CSF Compliance) with audience-specific narratives drafted by AI.

02Features

AI pulls its weight throughout the register.

From drafting and risk analysis to integrations, diagrams, treatment tracking, and audience-specific reports. Each capability shipped because it measurably accelerates the work, not because an LLM happened to be available.

Included on Free

Free forever, no credit card. Everything here carries over into Pro.

01

AI observation drafting

Enter a title and a short note. AI drafts a complete observation with risk rating, likelihood and impact, NIST CSF mapping, and actionable recommendations.

02

AI field enhancement

Select a field on an observation and let AI sharpen it into tighter summaries and clearer recommendations. Guide the AI with custom instructions.

03

AI risk reassessment

After implementing controls or closing out recommendations, let AI re-score likelihood, impact, and residual risk. Review the proposed changes side-by-side before applying.

04

AI duplicate detection

Before a new observation is finalized, AI compares it semantically against your existing library and flags likely duplicates by keywords, categories, and meaning, not just exact matches.

05

AI-suggested related observations

Link observations with named relations: related to, part of, worsens, depends on. As you create, manually or in bulk, AI spots existing findings that connect, explains why, and keeps that justification on the link for both sides to see.

06

Organisation context

Your company profile (industry, country, known domains and IP ranges, and a short background) rides along in every AI prompt, so drafts, risk scoring, and recommendations come back grounded in your environment, not generic boilerplate.

07

AI Mermaid diagrams

Generate architecture, attack-path, or Lockheed kill-chain diagrams for any observation. The AI grounds each diagram in the documented systems and controls. Refine with comments and export to PNG.

08

CSV bulk import

Drop in a CSV of findings and AI enriches each row into a complete observation. Parsing happens in your browser (the file bytes never leave your machine), with background duplicate detection across the batch.

09

Risk treatment workflow

Decide Mitigate or Accept on every observation. Track recommendations through Open, In Progress, and Completed. When all reach a terminal state, the observation auto-moves to Mitigated. Completed work rolls into a separate Deployed Controls list.

10

Navigate your security register

Search matches more than titles. It indexes affected systems, the full observation text, and the AI-generated keywords behind each finding. Light stemming maps singular to plural, so you surface the right observation by meaning and context, not exact wording.

11

Audit log

Every sign-in, change, export, and team action is captured with the user, IP address, and timestamp. Included on every plan, viewable in-app and exportable as CSV for compliance reviews and internal governance.

Pro only

Unlocked on the €19.95 / seat / mo Pro plan.

01

Advanced AI models

Pro routes generative AI features through markedly more capable models, for sharper observation drafts, deeper risk analysis, and stronger recommendations. A quality lift across the whole app, not just a single feature.

02

AI security advisor

Open a multi-turn chat grounded in a specific observation. Ask follow-up questions, request remediation strategies, or drill into technical details. The advisor always has the full context.

03

OSINT import

Bring in the internet-exposed services that public OSINT sources have already indexed for your organisation's IP ranges. SecurityTrackr reads existing public data, it never probes or scans systems itself. AI converts each exposure into a fully-drafted observation with risk, likelihood, impact, and recommendations.

04

PDF report import

Upload a pentest or audit report (PDF) and AI extracts the individual findings (title, risk, affected systems, description). Review, select, and import only the ones you want.

05

AI-written report builder

Four polished templates (Executive Summary, Risk Register, Mitigation Progress, and NIST CSF Compliance Mapping), each with an audience-specific narrative drafted by AI. Live data, filterable by period, risk, status, or assignee. PDF download.

06

Team collaboration

Assign observations to specific team members and leave comments in a thread to follow up on a finding or capture your own notes. Owner and member roles keep responsibility clear.

07

Choose your managed AI provider

The managed Advanced AI tier defaults to Anthropic (Claude) in the US under our DPA and Zero Data Retention agreement. Switch in one click to Mistral (EU data centres, also DPA + ZDR) when data residency matters, or to OpenAI (GPT-5.6) when GPT is your house standard. No key to manage.

08

Bring your own AI key (BYOK)

Route every generative AI request through your own OpenAI, Anthropic, or Mistral account, so findings run under the data-processing terms, retention, and region you agreed directly with that provider. Semantic-matching embeddings remain on a separate platform-managed path when enabled. The key is stored encrypted under your per-org key.

09

Single sign-on (SSO)

Connect Microsoft Entra ID, Okta, Google, or any OIDC provider so the team signs in with corporate credentials. Enforce SSO-only login and auto-provision new members as they join.

10

REST API and agentic (MCP) integrations

Connect agents, scripts, and custom integrations through the versioned REST API or the OAuth-authenticated MCP server. Use direct API calls for automation, or MCP tools for agent clients that need to work with the register.

03Pricing

Free or Pro. Nothing else to pick.

Start free and upgrade when you need more. No hidden fees.

Free

Free forever

For small teams getting started. Built-in AI included, no setup or API key needed.

  • 1 user
  • 10 observations
  • 25 MB of evidence uploads
  • Built-in AI that works out of the box, no setup or API key needed (lighter-weight model; Advanced AI on Pro for richer analysis)
  • AI drafting, field enhancement, and risk reassessment
  • AI Mermaid diagrams (architecture, attack path, kill chain)
  • AI duplicate detection
  • Risk treatment workflow with Mitigate / Accept and Deployed Controls
  • Audit log, mandatory MFA, AES-256 encryption
Start free
Most popular

Pro

€19.95/ seat / mo

Advanced AI included by default, powered by Anthropic (Claude) for markedly richer drafting, deeper risk analysis, multi-turn Security Advisor chat, and audience-specific report narratives, processed under our DPA and Zero Data Retention agreement with no training on your data. Need EU residency or prefer GPT? Switch the managed tier to Mistral (EU data centres, DPA + zero data retention) or OpenAI (GPT-5.6) in one click. REST API and agentic (MCP) integrations, team collaboration, and SSO.

  • Advanced AI included, markedly richer drafting and analysis than the built-in tier
  • AI Security Advisor (multi-turn, observation-aware chat)
  • AI-written report builder (Executive Summary, Risk Register, Mitigation Progress, and NIST CSF Compliance Mapping templates)
  • REST API and agentic (MCP) integrations
  • Team collaboration (invites, owner / member roles, comments, and observation assignment)
  • SSO with Entra ID, Okta, Google, and custom OIDC providers
  • Unlimited observations and 2 GB of evidence storage per seat
  • Advanced AI on Anthropic (Claude) by default, processed under our DPA + Zero Data Retention agreement with no training on your data — or switch to Mistral for EU data residency (EU data centres, DPA + ZDR) or OpenAI (GPT-5.6)
  • Optional BYOK for uncapped AI usage and full control of your data-processing terms
  • Priority support
Upgrade to Pro

Both tiers run on shared infrastructure with data logically separated through encryption and access controls. All data is stored in EU data centres.

Questions about plans, seats, or invoicing? Contact sales.

04Security

Built by security professionals, for security professionals.

We built SecurityTrackr because we needed it ourselves. Your findings are protected with the same rigour you bring to your own assessments.

  • S-01

    Per-organisation encryption keys

    Sensitive observation fields, uploaded files, and API keys are encrypted with a key unique to your organisation. SecurityTrackr staff have no interface for browsing or decrypting customer content, and raw database or object-storage access reveals ciphertext only. The only operator-assisted path is the GDPR data export that SecurityTrackr is legally required to facilitate; it releases data only after the customer supplies a one-time authorisation code sent to their registered email address.

  • S-02

    Mandatory two-factor authentication

    TOTP-based MFA is required for every account, with no opt-out. Sign-in is protected with an extra layer of defence by default.

  • S-03

    EU data residency

    All customer data stored by SecurityTrackr is kept in EU-jurisdiction data centres. Uploaded files are encrypted before entering object storage. AI processing location and retention depend on the provider selected by the customer and are disclosed separately.

  • S-04

    Full audit trail

    Every login, change, and export is logged. Download audit logs as CSV for compliance reviews and internal governance.

  • S-05

    Evidence file checks

    Every uploaded evidence file is checked against VirusTotal’s malware-reputation database (by SHA-256 hash only, so the file itself never leaves our infrastructure) before it can be downloaded. Flagged attachments are blocked from download.

Replace the spreadsheet. Start your security register today.

Free to use. No credit card required. Set up in minutes.

Create free account