Got an idea for how to improve Secfix?

Share it with us, and upvote other users' ideas.

Wiz Integration | CNAPP (Cloud-Native Application Protection Platform)

We use Wiz as our cloud security platform and would like to see a native integration with Secfix. Wiz already contains relevant cloud security posture, monitoring, and control evidence, so being able to sync this information automatically into Secfix would reduce manual evidence collection and make audit preparation more efficient. This would also help us demonstrate our cloud security controls more clearly during ISO 27001 audits. We’ve also noticed that similar compliance automation platforms already support Wiz integrations, so having this available in Secfix would provide significant additional value for teams using modern cloud security tooling.

Matt Sleeman 6 days ago

💡

Feature Request

Enable vendor version & change history

Currently, I need to maintain external spreadsheets for vendor reviews because Secfix does not provide visibility into: what changed, who changed it, when the change happened. Any update overwrites the previous state, making it difficult to track changes and prepare audit evidence. This is especially inefficient in environments with multiple vendor owners across different departments, where many people are responsible for maintaining vendor information and changes happen frequently. Requested Functionality I would like vendor entries to include version history/change tracking similar to policy version history. For each vendor, it should be possible to see: timestamp of the change, user who made the change, changed fields, previous value, new value. Key fields: vendor owner, contact person, authentication method (MFA/SSO), processed data, risk level, certification status, active/inactive status. Expected Outcome This would allow us to: conduct vendor reviews fully inside Secfix, reduce reliance on external spreadsheets, improve audit traceability, simplify evidence collection, better manage reviews across multiple vendor owners.

Jan Wagner about 2 hours ago

💡

Feature Request

Optional "Reports to" Requirement for Externals/ Contractors

Currently, automated checks require all employees/users to have an assigned owner/manager. This creates issues for external employees and contractors (e.g. external developers), who: work inside the company environment, should still complete compliance-related tasks such as Security Awareness Training and Policy Acceptance, but often do not have a formal internal manager/owner within the organization. At the moment, customers are forced to assign arbitrary HR or IT users as owners purely to satisfy the automated check requirements. Introduce a new configurable setting on employee groups tasks: Ownership/ Reports to required (enabled/disabled)

Frank Tiex about 20 hours ago

💡

Feature Request

Automatic Data Sync for Maintenance PSR

Enable the Maintenance PSR to automatically pull and reflect updates from other relevant sections (e.g., Risk Register, Vendor Reviews) to reduce manual work and ensure consistency. Introduce automatic synchronization between the Maintenance PSR and other key modules: When the Risk Register is reviewed, this should automatically update the corresponding task/status in the Maintenance PSR When a quarterly vendor review is completed, the related task in the Maintenance PSR should be automatically marked as completed Expected Benefits Eliminate repetitive manual updates Improve data consistency across the platform Save time for users managing ongoing ISO 27001 compliance Reduce risk of missing required maintenance actions

Jan Wagner 19 days ago

💡

Feature Request

Provide secure development trainings

Some of our customers and prospects are increasingly asking whether our engineers have completed secure coding training. This topic is becoming more relevant for companies, especially in the context of security frameworks and customer security requirements. To help address these requests, it would be very valuable if Secfix could provide a secure coding training directly within the Secfix platform. Ideally, this training would be targeted at developers and aligned with relevant security best practices and frameworks (e.g., ISO 27002). Having such training available in the platform would help us demonstrate that our engineers are trained in secure development practices and make it easier to meet security expectations from customers and prospects.

Andreas Offermann 2 months ago

💡

Feature Request