Planned
Automate Security documents of vendors
Regarding the bigger vendors (Google, AWS, Microsoft, Jira, etc.), automate the Security documents (ISO certificates, DPAs, etc.). Looking for those manually and choosing the right one can be a pain.

aj about 1 month ago
Feature Request
Planned
Automate Security documents of vendors
Regarding the bigger vendors (Google, AWS, Microsoft, Jira, etc.), automate the Security documents (ISO certificates, DPAs, etc.). Looking for those manually and choosing the right one can be a pain.

aj about 1 month ago
Feature Request
Slack Integration for Actions & Notifications
Introduce a Slack integration that allows users to receive notifications and complete relevant Secfix actions directly from Slack. Examples: Vendor Management: Notify users when a vendor review is due and allow them to approve it directly in Slack. Policies: Notify employees about policies requiring review/acknowledgement and allow them to acknowledge them in Slack. Training: Send reminders for outstanding security/compliance training. More generally, allow users to interact with relevant Secfix workflows directly from Slack. Expected Benefit Higher completion rates, faster responses, and less context switching between Slack, email, and Secfix.

olivier.welscher 1 day ago
Feature Request
Slack Integration for Actions & Notifications
Introduce a Slack integration that allows users to receive notifications and complete relevant Secfix actions directly from Slack. Examples: Vendor Management: Notify users when a vendor review is due and allow them to approve it directly in Slack. Policies: Notify employees about policies requiring review/acknowledgement and allow them to acknowledge them in Slack. Training: Send reminders for outstanding security/compliance training. More generally, allow users to interact with relevant Secfix workflows directly from Slack. Expected Benefit Higher completion rates, faster responses, and less context switching between Slack, email, and Secfix.

olivier.welscher 1 day ago
Feature Request
Under Review
Add applications detected by Secfix Agent to Vendor List
Allow customers to add applications detected by the Secfix Agent directly to the Vendor List. Customers could mark a detected application as approved and add it to the Vendor List with one click. Benefit: This would avoid manually recreating the list of applications already detected by the Secfix Agent.

m.gross 2 days ago
Feature Request
Under Review
Add applications detected by Secfix Agent to Vendor List
Allow customers to add applications detected by the Secfix Agent directly to the Vendor List. Customers could mark a detected application as approved and add it to the Vendor List with one click. Benefit: This would avoid manually recreating the list of applications already detected by the Secfix Agent.

m.gross 2 days ago
Feature Request
Planned
Option to open Evidences in a new tab from list views
No way to open-in-new-tab from evidences lists (or similar). Clicking into an item and going back resets scroll position to the top, losing place in a long list of evidences.

Melita Mujičić 29 days ago
Manual evidence
Feature Request
Planned
Option to open Evidences in a new tab from list views
No way to open-in-new-tab from evidences lists (or similar). Clicking into an item and going back resets scroll position to the top, losing place in a long list of evidences.

Melita Mujičić 29 days ago
Manual evidence
Feature Request
Show passed checks as well as failed resources
Currently, failed checks show which resources didn't match, but passing checks show nothing. Usees need to the ability to seewhat was actually checked to prove scope to auditors (e.g., which AWS account/regions were checked for "CloudTrail enabled in all regions," which employees were in scope for security training).

Melita Mujičić 29 days ago
Automated tasks
Feature Request
Show passed checks as well as failed resources
Currently, failed checks show which resources didn't match, but passing checks show nothing. Usees need to the ability to seewhat was actually checked to prove scope to auditors (e.g., which AWS account/regions were checked for "CloudTrail enabled in all regions," which employees were in scope for security training).

Melita Mujičić 29 days ago
Automated tasks
Feature Request
Ability to align annual evidence renewals to a single review date
Allow admins to define a single annual review date per framework for annual evidence renewals. Instead of calculating renewal dates based on each piece of evidence’s last upload date, all annual evidence could become due at a configurable interval before the review date (e.g., 1 month). This would prevent evidence renewal dates from being scattered across several weeks and make it easier to prepare for internal and external audits in one planned review cycle.

Bart Slaets 7 days ago
Feature Request
Ability to align annual evidence renewals to a single review date
Allow admins to define a single annual review date per framework for annual evidence renewals. Instead of calculating renewal dates based on each piece of evidence’s last upload date, all annual evidence could become due at a configurable interval before the review date (e.g., 1 month). This would prevent evidence renewal dates from being scattered across several weeks and make it easier to prepare for internal and external audits in one planned review cycle.

Bart Slaets 7 days ago
Feature Request
Role: Policy Approver
I have Management people, which has to approve policies. Now I have to assign “Editor” authorization for doing that. I need a separate role for this. Further, they are collaborator as well, so the role should have these authorizations as well.

Martin Trachsel 14 days ago
Risk register
Feature Request
Role: Policy Approver
I have Management people, which has to approve policies. Now I have to assign “Editor” authorization for doing that. I need a separate role for this. Further, they are collaborator as well, so the role should have these authorizations as well.

Martin Trachsel 14 days ago
Risk register
Feature Request
Detection of Standard Password Manager for macOS
macOS comes by default with an own password safe named “Passwords” or in German “Passwörter”. That’s why we do not preinstall an additional password safe before laptop provisioning. It would be nice, if the Apple password safe was also detected by Secfix. It can be found in the Intune list.

Frank Tiex about 1 month ago
Automated tasks
Feature Request
Detection of Standard Password Manager for macOS
macOS comes by default with an own password safe named “Passwords” or in German “Passwörter”. That’s why we do not preinstall an additional password safe before laptop provisioning. It would be nice, if the Apple password safe was also detected by Secfix. It can be found in the Intune list.

Frank Tiex about 1 month ago
Automated tasks
Feature Request
Sync mobile devices from Intune
Sync and check mobile devices(company phones) from Intune, like Computers in Secfix, so that we can follow their compliance status directly on Secfix.

jochem.baud 17 days ago
Feature Request
Sync mobile devices from Intune
Sync and check mobile devices(company phones) from Intune, like Computers in Secfix, so that we can follow their compliance status directly on Secfix.

jochem.baud 17 days ago
Feature Request
MCP server for the Secfix platform
We would like to connect an AI assistant to the platform and programmatically pull compliance data. Problem / use case: The customer is preparing for ISO certification. They want to pull platform data — policies, controls, and related artifacts — into their AI workflow, then auto-generate a detailed requirements-and-preparation plan for the cert. They also want to push the output into Jira (e.g., create a ticket documenting the requirements and prep plan). Today this is manual. Proposed capability: An MCP server that exposes Secfix data (policies, controls, frameworks, evidence) as queryable resources/tools for MCP-compatible AI clients. Read access at minimum; optionally write/action support for downstream integrations (e.g., creating Jira tickets from generated plans).

Srinivas Sambari 2 months ago
Feature Request
MCP server for the Secfix platform
We would like to connect an AI assistant to the platform and programmatically pull compliance data. Problem / use case: The customer is preparing for ISO certification. They want to pull platform data — policies, controls, and related artifacts — into their AI workflow, then auto-generate a detailed requirements-and-preparation plan for the cert. They also want to push the output into Jira (e.g., create a ticket documenting the requirements and prep plan). Today this is manual. Proposed capability: An MCP server that exposes Secfix data (policies, controls, frameworks, evidence) as queryable resources/tools for MCP-compatible AI clients. Read access at minimum; optionally write/action support for downstream integrations (e.g., creating Jira tickets from generated plans).

Srinivas Sambari 2 months ago
Feature Request
Office visitor log
Is it not possible to map the "Office visitor log" in your platform? So authorized users per location could access a corresponding web form in Secfix and register users. That would save a lot of work and would be traceable without alteration.

Jens V 23 days ago
Feature Request
Office visitor log
Is it not possible to map the "Office visitor log" in your platform? So authorized users per location could access a corresponding web form in Secfix and register users. That would save a lot of work and would be traceable without alteration.

Jens V 23 days ago
Feature Request
Ability to deactivate controls from the Frameworks page
Currently, when you mark all evidence/automated tasks as deactivated for a control, it shows the control’s progress 100% even though there are no tasks attached to that specific control. We would like to have the ability to deactivate a control from the framework page when it’s not applicable to us. This way, the auditor does not get confused by looking at the progress percentage, thinking that the check is applicable, and that we have completed all necessary checks.

Hannah-Marie Kleindopff about 1 month ago
Feature Request
Ability to deactivate controls from the Frameworks page
Currently, when you mark all evidence/automated tasks as deactivated for a control, it shows the control’s progress 100% even though there are no tasks attached to that specific control. We would like to have the ability to deactivate a control from the framework page when it’s not applicable to us. This way, the auditor does not get confused by looking at the progress percentage, thinking that the check is applicable, and that we have completed all necessary checks.

Hannah-Marie Kleindopff about 1 month ago
Feature Request
Ability to nest employee groups
We do have several non-consulting groups (marketing and finance, as well as people & development) that would require the same policies. Hence, it would be great to assign the policies to a parent group of these groups.

Michael Wachter about 1 month ago
Feature Request
Ability to nest employee groups
We do have several non-consulting groups (marketing and finance, as well as people & development) that would require the same policies. Hence, it would be great to assign the policies to a parent group of these groups.

Michael Wachter about 1 month ago
Feature Request
Enable Linux NixOS for Secfix Agent
The Secfix Agent should be compatible with Linux NixOS. It currently only works for Linux Debian

max about 1 month ago
Feature Request
Enable Linux NixOS for Secfix Agent
The Secfix Agent should be compatible with Linux NixOS. It currently only works for Linux Debian

max about 1 month ago
Feature Request
Android phones should be registrable just like computers (not just through BYOD)
Description: Currently, personal smartphones (Android and iPhone) can only be used for work via BYOD, which requires manual registration and approval as well as manual checks (PIN/lock screen, automatic lockout within 15 minutes, local storage encryption). It would be much easier if Android phones could be registered and managed in Secfix just like computers (Windows/Linux/macOS), so that compliance could be checked automatically instead of relying on BYOD checks.

Kilian Maier about 1 month ago
Feature Request
Android phones should be registrable just like computers (not just through BYOD)
Description: Currently, personal smartphones (Android and iPhone) can only be used for work via BYOD, which requires manual registration and approval as well as manual checks (PIN/lock screen, automatic lockout within 15 minutes, local storage encryption). It would be much easier if Android phones could be registered and managed in Secfix just like computers (Windows/Linux/macOS), so that compliance could be checked automatically instead of relying on BYOD checks.

Kilian Maier about 1 month ago
Feature Request
Link custom evidence (e.g. policies) to controls
It would be nice to be able to add (supporting) evidence (e.g. linking a policy, ME or AC) to a control. E.g. “We’d like to map POL-04 as evidence under 12.1.1 PCI DSS control, to have the Acceptable Use section also visible for the PCI DSS audit. That's what our auditor knows from the past and was asking for. Sure, having the POL-02 linked to it is the generic approach and totally correct. The POL-04 would simply make it more concrete.”

Frank Tiex 2 months ago
Feature Request
Link custom evidence (e.g. policies) to controls
It would be nice to be able to add (supporting) evidence (e.g. linking a policy, ME or AC) to a control. E.g. “We’d like to map POL-04 as evidence under 12.1.1 PCI DSS control, to have the Acceptable Use section also visible for the PCI DSS audit. That's what our auditor knows from the past and was asking for. Sure, having the POL-02 linked to it is the generic approach and totally correct. The POL-04 would simply make it more concrete.”

Frank Tiex 2 months ago
Feature Request