Got an idea for how to improve Secfix?

Share it with us, and upvote other users' ideas.

MCP server for the Secfix platform

We would like to connect an AI assistant to the platform and programmatically pull compliance data. Problem / use case: The customer is preparing for ISO certification. They want to pull platform data — policies, controls, and related artifacts — into their AI workflow, then auto-generate a detailed requirements-and-preparation plan for the cert. They also want to push the output into Jira (e.g., create a ticket documenting the requirements and prep plan). Today this is manual. Proposed capability: An MCP server that exposes Secfix data (policies, controls, frameworks, evidence) as queryable resources/tools for MCP-compatible AI clients. Read access at minimum; optionally write/action support for downstream integrations (e.g., creating Jira tickets from generated plans).

Srinivas Sambari 20 days ago

1
💡

Feature Request

Wiz Integration | CNAPP (Cloud-Native Application Protection Platform)

We use Wiz as our cloud security platform and would like to see a native integration with Secfix. Wiz already contains relevant cloud security posture, monitoring, and control evidence, so being able to sync this information automatically into Secfix would reduce manual evidence collection and make audit preparation more efficient. This would also help us demonstrate our cloud security controls more clearly during ISO 27001 audits. We’ve also noticed that similar compliance automation platforms already support Wiz integrations, so having this available in Secfix would provide significant additional value for teams using modern cloud security tooling.

Matt Sleeman about 2 months ago

💡

Feature Request

Vendor Discovery Page – Surfacing New/Unreviewed Vendors More Clearly

Title: Vendor Discovery Page – Surfacing New/Unreviewed Vendors More Clearly Description: The current "Discover Vendors" tab shows all vendors in a single list, including those already ignored. With 144 vendors in total—over 130 of which have been ignored—it's difficult to tell at a glance whether any new vendors require review. Proposed Solution: The optimal improvement would be to split the tab into two separate views: A "Discovered Vendors" tab (or equivalent) showing only unreviewed/un-ignored vendors A separate "Ignored Vendors" tab for vendors already dismissed This would allow users to immediately see how many vendors need attention without scrolling through a long mixed list. Alternative / Minimum Viable Improvement: If a full tab split isn't feasible, sorting the list by status (new vs. ignored) would also help—but only if a visible "New" badge or count indicator is shown in the header, so users are alerted without having to open the tab at all. User Impact: This change would make the Vendor page significantly more actionable for users managing large vendor lists, reducing the effort required to stay on top of new additions.

Melita Mujičić about 1 month ago

1
💡

Feature Request