Add pacman/Arch Linux package detection support for Linux antivirus check
The Linux antivirus check currently relies on package-inventory tables (deb_packages, rpm_packages, etc. via osquery), which have no equivalent for pacman-based distributions (Arch Linux, Manjaro, EndeavourOS, Omarchy, and others). As a result, any antivirus solution installed via pacman — including ClamAV, which is on your supported list — can never be detected, regardless of whether it's correctly installed and running. We verified this on an Omarchy (Arch-based) device: ClamAV was installed, running, and actively detecting malware (confirmed via EICAR test), and the underlying osquery processes table showed clamd/freshclam running correctly — but no pacman_packages table exists for the compliance check to query against, so the device was flagged as having no antivirus.

BryanK about 8 hours ago
Secfix agent
Feature Request
Add pacman/Arch Linux package detection support for Linux antivirus check
The Linux antivirus check currently relies on package-inventory tables (deb_packages, rpm_packages, etc. via osquery), which have no equivalent for pacman-based distributions (Arch Linux, Manjaro, EndeavourOS, Omarchy, and others). As a result, any antivirus solution installed via pacman — including ClamAV, which is on your supported list — can never be detected, regardless of whether it's correctly installed and running. We verified this on an Omarchy (Arch-based) device: ClamAV was installed, running, and actively detecting malware (confirmed via EICAR test), and the underlying osquery processes table showed clamd/freshclam running correctly — but no pacman_packages table exists for the compliance check to query against, so the device was flagged as having no antivirus.

BryanK about 8 hours ago
Secfix agent
Feature Request
Slack Integration for Actions & Notifications
Introduce a Slack integration that allows users to receive notifications and complete relevant Secfix actions directly from Slack. Examples: Vendor Management: Notify users when a vendor review is due and allow them to approve it directly in Slack. Policies: Notify employees about policies requiring review/acknowledgement and allow them to acknowledge them in Slack. Training: Send reminders for outstanding security/compliance training. More generally, allow users to interact with relevant Secfix workflows directly from Slack. Expected Benefit Higher completion rates, faster responses, and less context switching between Slack, email, and Secfix.

olivier.welscher 8 days ago
Feature Request
Slack Integration for Actions & Notifications
Introduce a Slack integration that allows users to receive notifications and complete relevant Secfix actions directly from Slack. Examples: Vendor Management: Notify users when a vendor review is due and allow them to approve it directly in Slack. Policies: Notify employees about policies requiring review/acknowledgement and allow them to acknowledge them in Slack. Training: Send reminders for outstanding security/compliance training. More generally, allow users to interact with relevant Secfix workflows directly from Slack. Expected Benefit Higher completion rates, faster responses, and less context switching between Slack, email, and Secfix.

olivier.welscher 8 days ago
Feature Request
Under Review
Add applications detected by Secfix Agent to Vendor List
Allow customers to add applications detected by the Secfix Agent directly to the Vendor List. Customers could mark a detected application as approved and add it to the Vendor List with one click. Benefit: This would avoid manually recreating the list of applications already detected by the Secfix Agent.

m.gross 9 days ago
Feature Request
Under Review
Add applications detected by Secfix Agent to Vendor List
Allow customers to add applications detected by the Secfix Agent directly to the Vendor List. Customers could mark a detected application as approved and add it to the Vendor List with one click. Benefit: This would avoid manually recreating the list of applications already detected by the Secfix Agent.

m.gross 9 days ago
Feature Request
PCI DSS 4: Partial Visibility of Framework Requirements
With version 4, PCI DSS now allows partial audits. Therefore it would be nice to have some (static) switches for not displaying the requirements, which are not in focus for an audit. This would also help with the overall fulfill degree. Switches would be appreciated for both, a whole Requirement section as well as a single line.

Frank Tiex 1 day ago
Frameworks page
Feature Request
PCI DSS 4: Partial Visibility of Framework Requirements
With version 4, PCI DSS now allows partial audits. Therefore it would be nice to have some (static) switches for not displaying the requirements, which are not in focus for an audit. This would also help with the overall fulfill degree. Switches would be appreciated for both, a whole Requirement section as well as a single line.

Frank Tiex 1 day ago
Frameworks page
Feature Request
Sorting on the Employees page
The Employees page comes with filtering, but does not have a sorting option like e.g. Computers. Is this by intention or got it lost accidentally? Especially sorting by Date would be helpful.

Frank Tiex 1 day ago
Employees
Feature Request
Sorting on the Employees page
The Employees page comes with filtering, but does not have a sorting option like e.g. Computers. Is this by intention or got it lost accidentally? Especially sorting by Date would be helpful.

Frank Tiex 1 day ago
Employees
Feature Request
Assign Roles & Permissions to User Groups
Platform permissions can currently only be assigned individually, which makes access management cumbersome for larger teams. Requested Functionality Allow roles & permissions to be assigned to groups, so all group members automatically inherit the assigned role. A role assigned directly to an individual user should override the group-level role. Example: Top Management → Admin or ISMS Governance Council → Admin. This would make access management much more scalable and easier to maintain.

Michael Wachter 1 day ago
Feature Request
Assign Roles & Permissions to User Groups
Platform permissions can currently only be assigned individually, which makes access management cumbersome for larger teams. Requested Functionality Allow roles & permissions to be assigned to groups, so all group members automatically inherit the assigned role. A role assigned directly to an individual user should override the group-level role. Example: Top Management → Admin or ISMS Governance Council → Admin. This would make access management much more scalable and easier to maintain.

Michael Wachter 1 day ago
Feature Request
Planned
Option to open Evidences in a new tab from list views
No way to open-in-new-tab from evidences lists (or similar). Clicking into an item and going back resets scroll position to the top, losing place in a long list of evidences.

Melita Mujičić about 1 month ago
Manual evidence
Feature Request
Planned
Option to open Evidences in a new tab from list views
No way to open-in-new-tab from evidences lists (or similar). Clicking into an item and going back resets scroll position to the top, losing place in a long list of evidences.

Melita Mujičić about 1 month ago
Manual evidence
Feature Request
Planned
Automate Security documents of vendors
Regarding the bigger vendors (Google, AWS, Microsoft, Jira, etc.), automate the Security documents (ISO certificates, DPAs, etc.). Looking for those manually and choosing the right one can be a pain.

aj about 2 months ago
Feature Request
Planned
Automate Security documents of vendors
Regarding the bigger vendors (Google, AWS, Microsoft, Jira, etc.), automate the Security documents (ISO certificates, DPAs, etc.). Looking for those manually and choosing the right one can be a pain.

aj about 2 months ago
Feature Request
Show passed checks as well as failed resources
Currently, failed checks show which resources didn't match, but passing checks show nothing. Usees need to the ability to seewhat was actually checked to prove scope to auditors (e.g., which AWS account/regions were checked for "CloudTrail enabled in all regions," which employees were in scope for security training).

Melita Mujičić about 1 month ago
Automated tasks
Feature Request
Show passed checks as well as failed resources
Currently, failed checks show which resources didn't match, but passing checks show nothing. Usees need to the ability to seewhat was actually checked to prove scope to auditors (e.g., which AWS account/regions were checked for "CloudTrail enabled in all regions," which employees were in scope for security training).

Melita Mujičić about 1 month ago
Automated tasks
Feature Request
Ability to align annual evidence renewals to a single review date
Allow admins to define a single annual review date per framework for annual evidence renewals. Instead of calculating renewal dates based on each piece of evidence’s last upload date, all annual evidence could become due at a configurable interval before the review date (e.g., 1 month). This would prevent evidence renewal dates from being scattered across several weeks and make it easier to prepare for internal and external audits in one planned review cycle.

Bart Slaets 15 days ago
Feature Request
Ability to align annual evidence renewals to a single review date
Allow admins to define a single annual review date per framework for annual evidence renewals. Instead of calculating renewal dates based on each piece of evidence’s last upload date, all annual evidence could become due at a configurable interval before the review date (e.g., 1 month). This would prevent evidence renewal dates from being scattered across several weeks and make it easier to prepare for internal and external audits in one planned review cycle.

Bart Slaets 15 days ago
Feature Request
Role: Policy Approver
I have Management people, which has to approve policies. Now I have to assign “Editor” authorization for doing that. I need a separate role for this. Further, they are collaborator as well, so the role should have these authorizations as well.

Martin Trachsel 21 days ago
Risk register
Feature Request
Role: Policy Approver
I have Management people, which has to approve policies. Now I have to assign “Editor” authorization for doing that. I need a separate role for this. Further, they are collaborator as well, so the role should have these authorizations as well.

Martin Trachsel 21 days ago
Risk register
Feature Request
Detection of Standard Password Manager for macOS
macOS comes by default with an own password safe named “Passwords” or in German “Passwörter”. That’s why we do not preinstall an additional password safe before laptop provisioning. It would be nice, if the Apple password safe was also detected by Secfix. It can be found in the Intune list.

Frank Tiex about 1 month ago
Automated tasks
Feature Request
Detection of Standard Password Manager for macOS
macOS comes by default with an own password safe named “Passwords” or in German “Passwörter”. That’s why we do not preinstall an additional password safe before laptop provisioning. It would be nice, if the Apple password safe was also detected by Secfix. It can be found in the Intune list.

Frank Tiex about 1 month ago
Automated tasks
Feature Request
Sync mobile devices from Intune
Sync and check mobile devices(company phones) from Intune, like Computers in Secfix, so that we can follow their compliance status directly on Secfix.

jochem.baud 24 days ago
Feature Request
Sync mobile devices from Intune
Sync and check mobile devices(company phones) from Intune, like Computers in Secfix, so that we can follow their compliance status directly on Secfix.

jochem.baud 24 days ago
Feature Request
MCP server for the Secfix platform
We would like to connect an AI assistant to the platform and programmatically pull compliance data. Problem / use case: The customer is preparing for ISO certification. They want to pull platform data — policies, controls, and related artifacts — into their AI workflow, then auto-generate a detailed requirements-and-preparation plan for the cert. They also want to push the output into Jira (e.g., create a ticket documenting the requirements and prep plan). Today this is manual. Proposed capability: An MCP server that exposes Secfix data (policies, controls, frameworks, evidence) as queryable resources/tools for MCP-compatible AI clients. Read access at minimum; optionally write/action support for downstream integrations (e.g., creating Jira tickets from generated plans).

Srinivas Sambari 3 months ago
Feature Request
MCP server for the Secfix platform
We would like to connect an AI assistant to the platform and programmatically pull compliance data. Problem / use case: The customer is preparing for ISO certification. They want to pull platform data — policies, controls, and related artifacts — into their AI workflow, then auto-generate a detailed requirements-and-preparation plan for the cert. They also want to push the output into Jira (e.g., create a ticket documenting the requirements and prep plan). Today this is manual. Proposed capability: An MCP server that exposes Secfix data (policies, controls, frameworks, evidence) as queryable resources/tools for MCP-compatible AI clients. Read access at minimum; optionally write/action support for downstream integrations (e.g., creating Jira tickets from generated plans).

Srinivas Sambari 3 months ago
Feature Request
Office visitor log
Is it not possible to map the "Office visitor log" in your platform? So authorized users per location could access a corresponding web form in Secfix and register users. That would save a lot of work and would be traceable without alteration.

Jens V about 1 month ago
Feature Request
Office visitor log
Is it not possible to map the "Office visitor log" in your platform? So authorized users per location could access a corresponding web form in Secfix and register users. That would save a lot of work and would be traceable without alteration.

Jens V about 1 month ago
Feature Request