About

A small startup in Denmark, fixing the list nobody owns.

This is why we started, and what we think happens to security work next, as more of it stops being done by people.

01Why we started

Every organisation writes the same list. Almost none of them have a home for it.

SecurityTrackr ApS is an early-stage company in Denmark. Small team, we build it ourselves, customer data stays in the EU.

Before it was a company it was an annoyance. Every organisation that takes security seriously writes the same list: what is wrong, how bad it is, who is dealing with it. It ends up in a spreadsheet, or a ticket project bent out of shape, or a wiki page that was accurate four months ago.

Registers do not go stale because people are careless. They go stale because keeping one current means writing: a risk statement, a likelihood and impact with reasoning behind them, a recommendation someone can act on. Most of an hour per finding, forever.

That is a language problem, which is what these models are good at, so that is where we put the AI. The model writes. It does not decide. Whether a risk is acceptable, who owns it, and when it closes stay human calls with a name attached.

02What happens next

Your assistant already reads the mail. It should be able to update the register.

More and more people run an AI assistant across their working day, the way you would brief a secretary. It goes through the ops channel, the pentest report that landed on Friday, the memo from Tuesday's meeting. It already sees most of what changes about your security posture, days before anyone gets round to writing it down.

That is the shift we are building for: agents doing the cumbersome part, the filing and the updating, while the register underneath stays something you can hand an auditor. Compliance kept without anyone keeping it by hand.

The same gap shows up wherever agents work. One can find a real vulnerability, ship the patch, and close it overnight, leaving no observation, no severity anyone agreed with, and nothing in the compliance tool. Ask what you had exposed last quarter and the record was never created.

We do not scan, monitor, or modify anyone's systems, and we are not trying to. What is missing was never another scanner. It is the record, and somewhere an agent can put one.

Obs011, three months later
  1. 1
    09:14 · ops channel

    Operations post that DNSSEC is live: DS records published at the registrar for every customer-facing zone.

  2. 2
    Your assistant

    Reads it on the same pass it reads everything else. Nobody forwards it, nobody writes a ticket.

  3. 3
    SecurityTrackr

    Matches it to Obs011, already open, rather than filing a second observation about the same thing.

  4. 4
    Your register

    The DNSSEC recommendation is marked done, with the message as evidence and an audit-log line naming the agent.

Nobody opened the tool. The audit trail is intact anyway.

Obs011 is the observation drafted in the demo on the home page. Its other recommendation, the CAA records, is still open, so the observation is too.

Replace the spreadsheet. Start your security register today.

Free to use. No credit card required. Set up in minutes.

Create free account