Planned
15Committed and queued
Option to open Evidences in a new tab from list views
No way to open-in-new-tab from evidences lists (or similar). Clicking into an item and going back resets scroll position to the top, losing place in a long list of evidences.
Automate Security documents of vendors
Regarding the bigger vendors (Google, AWS, Microsoft, Jira, etc.), automate the Security documents (ISO certificates, DPAs, etc.). Looking for those manually and choosing the right one can be a pain.
Feature Request: Include Vendor Address Information in Vendor Export
Proposed Solution Add vendor address information (or at minimum vendor location/country) to the Vendor Export. Problem We frequently use the Vendor Export as part of security questionnaires, customer onboarding processes, and audit preparations. While the current export provides a list of vendors, it does not include vendor address/location information. Many customer due diligence and security review questionnaires require not only the vendor name but also information about where the vendor is located. As a result, we currently have to manually open each vendor record and copy the address information into the exported vendor list.
Expand Vendors to include Partners and other third parties
Problem The current Vendors section is limited in scope and suggests that only software vendors should be listed. In practice, organizations work with different types of third parties, such as: infrastructure providers, partners involved in collaborative development, customers participating in joint projects. These entities are currently not clearly represented in the Vendors section, although they are relevant from a risk and compliance perspective. Proposed solution Rename Vendors to Vendors & Partners, or extend the section to explicitly support different third-party types (e.g. vendor, partner, customer, infrastructure provider). Benefits More accurate representation of third-party relationships Better coverage of non-software and collaborative partners Improved clarity and usability for customers
Create Tasks in Linear
Even though I connected Linear as part of the ticketing integrations, Jira seems to be the only available options to automatically create and links tasks from SecFix.
Sync due dates of treatment tasks with the due dates in the linked ticket
The best case would be to update the ticket in Jira, and this should sync the due date in the risk register if the ticket is linked.
Onboarding tasks expiry date
Currently, there’s no way for admins to see when an onboarding task is about to expire. It would be helpful to display expiry dates, so admins can proactively remind employees to complete their tasks before the deadline.
Structure and grouping of vendors
Commenting on behalf of Jan W. - at the moment our Customers do not have a good overview over the vendors. The vendors are currently sorted by owners, risk level or status. As soon as the vendor number grows, there is no way to sort them by their category. Customer is suggesting to structure the risk scenarios by: creating departments; assigning labels; grouping. Use case: A SMB with multiple departments and multiple vendors needs a good overview over the vendors. Adding for instance grouping or labeling by departments will help our customers to assign vendor to the right category - for instance banking, internal communication etc. This helps customers structure the work on the platform and manage the vendor ownership more efficiently.
Automated Vendor Risk Assessments
The addition of Automated Vendor Risk Assessments to the Vendor Management module would be great to have. This feature should allow for systematic evaluation of vendor security and compliance risks without manual intervention. Key functionalities: Ability to send automated risk assessment forms to vendors. Standardized risk scoring based on responses. Integration with vendor profiles for tracking and reporting. This enhancement would improve efficiency, reduce manual workload, and ensure a more consistent vendor risk evaluation process.
Add custom fields to vendors
It would be great to have the ability to add custom fields to vendors. This would allow us to track important details such as: Has the contract been signed? Do they delete data within six months? Where is their data located? Where do they process their data?
Building Now
3Actively being built
Rename "remediate" button for automated checks to prevent confusion
I would like to share a small usability suggestion regarding the Secfix interface. For findings such as the Microsoft 365 checks, the action button is currently labeled "Remediate". Initially, both a colleague and I were hesitant to click it because it sounded like it would immediately apply changes to our environment. In practice, the button opens guidance and remediation instructions rather than performing the remediation itself. For that reason, a label such as "Instructions", "View Instructions", or "Review Remediation Steps" may better reflect the actual behaviour and help avoid confusion.
Bulk action on HRIS connections scope review - Merge HR data
For the employees who didn’t have a match, adding employees from the HRIS sync takes three clicks each, with waiting for things to load in between. I'm working through a backlog right now and it adds up fast. In UI I cannot modify anything anyways, fields are locked so I feel I am doing unnecessary work that could be just done in bulk. What I'd like: Checkboxes on each row plus a select-all (right side would work well). Tick everything, untick what I don't need, then run one action: Add employee/s Mark out of scope
Add custom manual evidence records to list
We'd like to manually add evidence records to prove that we're actually generating "records of access request issues tracked". Since Secfix doesn't provide Clickup integration yet and we can't turn some ticketing-system-related tasks green, we would then add proof for that on the manual evidence list. I'm referring to the automated tasks called "Records of access requests issues tracked" and "Records of security issues being tracked" in my example.
Completed
151Recently shipped
Security Awareness Training: Subtitles in more languages
Hello, To train all people, we'd need the security awareness training to also be available in Portuguese. This is usually done via YouTube Studio → video → Subtitles → Languages. Machine-translated captions are completely acceptable on our end. If that doesn't work for SecFix, we could instead provide proper translated caption tracks in Portuguese, which would give a more precise, non-machine alternative. Please let us know how you'd like to proceed, so we can start using the SecFix training in other languages effectively. As a quicker interim solution, we will provide a full bilingual document with all questions and answers both in English and Portuguese, so our users can view the videos first, and then choose the options themselves. Best regards, Petru Faurescu
Sorting on the Employees page
The Employees page comes with filtering, but does not have a sorting option like e.g. Computers. Is this by intention or got it lost accidentally? Especially sorting by Date would be helpful.
Devolutions Passwort Manager in Secfix Computer aufnehmen
Der Secfix Agent prüft die PC’s. Devolutions Workspace wurde umbenannt in Devolutions Password Manager. Diesen bitte zusätzlich aufnehmen
Recognize Devolutions Workspace as password manager
https://devolutions.net/workspace/
Export functionality for Access Review data
Context / problem: Currently, we cannot export the access review data (list of users & permissions) from the platform. This creates friction especially for larger customers like us. Customer impact: Manually copying the data into the access review template is time-consuming and error-prone. Proposed solution: Introduce an export functionality (e.g. CSV/Excel) for access review data directly from the Access section.
Option to sort the Vendors list by "Data stored"
This could be helpful to find all PII-related software quickly.
Show Owner Info on mouseover
it would be helpful, if on the Vendors and Inventory page the owner info is shown already when moving the mouse over the bubble, as it is already implemented for the risk register. Today you need to click on the bubble and then the name is partially covered by the edit dialog.
Ability to undo "mark as not a person" action on employees page
I think if we (an admin) mark someone as "not a person", there should be an option to also "unmark" them. It can be done by mistake, or for testing, and it needs to be reversible.
Ability to see all accounts that an employee has signed up for
I recently switched from another tool to Secfix, so I'm looking for a feature they offer, and I wish I had a screenshot to show you. Somehow, they are able to list all of the SaaS accounts that an email in our domain has signed up for. For example, instead of just Google, I know that x person has access to ChatGPT, Cursor, Atlassian, Docker, Microsoft, Notion, Zoom, Figma, etc., etc. I want to access this information for every employee instantly. It is very helpful for access reviews as required for SOC2 compliance.
Manual Evidences: Manual Status Change & "Work in Progress"
When adding files to a manual evidence, the status is automatically set to “Completed” although in some cases, not all documents or links were added yet. Therefore it would be helpful to be able to change back the status manually and also to have a third status “Work in Progress” to mark this and not to loose overview.