Skip to content
RiskTrace
Launching soon

Trace risk.
Reduce impact.

RiskTrace is the cyber risk and GRC platform built around the tabletop. A risk register in business language, controls mapped once across frameworks, exercises that produce evidence, and board reporting from the same data.

One email when sign-up opens. No mailing list, no follow-ups.

Data hosted in Canada English and French AI off by default
Executive overview · Harbour Health Authority
Illustrative

Risk heat map

1
2
1
1
3
2
1
1
4
1
2
2
23 open risks5 high

Framework coverage

ISO/IEC 2700178%
SOC 264%
NIST CSF 2.071%
ISO/IEC 4200142%

Mapped once to a common control set.

Next exercise

Third-party outage at the EHR vendor

Thu 22 Oct · 9 participants · scenario v2 (FR available)

Board brief

Q3 v3 approved by CISO

Tagged PDF · 14 pages · 2 versions kept

Built by practitioners

The platform our consultants run engagements on, released as a product.

RiskTrace comes from Frontier Cyber, a Vancouver security consultancy. Every module exists because a client needed it in a real engagement: the register the board could read, the exercise that found the gap, the brief that went to the audit committee.

  • Canadian data residency

    Hosted in a Canadian region with a per-tenant region model.

  • English and French

    Product and scenario content in both official languages.

  • Your keys, your storage

    Bring your own encryption keys and evidence storage.

  • API first, MCP included

    Everything the screen does, your tools can do too.

The platform

One system of record for risk, controls, exercises and the board.

Each part feeds the others. A gap found in an exercise becomes a risk, the risk points at a control, and the control shows up in the board brief with its evidence attached.

Risk register

A register your executives can read without a translator.

Capture risks the way the business talks about them, score them consistently, assign owners and treatments, and trace every risk to the controls, exercises and incidents that touch it.

  • Business language first

    Scenario, impact and likelihood are written for the people who own the decision, with the technical detail one click deeper.

  • Drafts stay drafts

    AI and imports propose; a person approves. Proposals sit in a review queue and never write to the approved register on their own.

  • Traceability built in

    Each risk links to the controls that treat it, the exercises that tested it and the incidents that proved it, so the register is evidence rather than a spreadsheet.

More on risk register
Risk register
Illustrative
RiskDomainScoreLinks
Ransomware halts clinic scheduling for 48hOperationsHigh3
Payroll vendor breach exposes staff dataThird partyHigh2
Loss of MFA on legacy VPNAccessMedium2
Backups untested for finance systemResilienceMedium1
Phishing against executive assistantsPeopleLow1

Heat map

1
2
1
1
3
2
1
1
4
1
2
2

Likelihood against impact, 23 open risks.

Controls and frameworks

Map once. Report against every framework you answer to.

A framework catalog and a common control set let you implement a control one time and show coverage for each standard, with policies versioned and approved alongside.

  • Common control set

    Controls map to framework requirements, so a change shows up in every coverage view at the same time.

  • Policies with a lifecycle

    Versioned policies, approvals and acceptance tracking, starting from templates written by practitioners.

  • Coverage you can defend

    Coverage views show what is implemented, what is evidenced and what is still a gap, by framework and by business unit.

More on controls and frameworks
Controls and frameworks
Illustrative

Coverage by framework

ISO/IEC 2700178%
SOC 264%
NIST CSF 2.071%
ISO/IEC 4200142%

Control

AC-07 Multi-factor authentication for remote access

Implemented · Evidenced by Exercise TT-14 · Owner IT Ops

ISO 27001 A.8.5
SOC 2 CC6.1
NIST CSF PR.AA-03
HIPAA 164.312(d)

Tabletop exercises

The tabletop is the core of the platform, not an add-on.

RiskTrace grew out of the exercises our consultants run. Build a scenario from the library, run it with the room, record decisions and gaps, and feed the findings straight back into risks, controls and playbooks.

  • Scenario library

    Reviewed scenarios move from draft to published, in English and French, and can be tailored to your sector and systems.

  • Run it in the room

    Injects, questions, timed decisions and participant responses are captured as the exercise happens.

  • Evidence, not minutes

    Every exercise produces a record: who took part, what was decided, which gaps were found and which risks and controls they map to.

More on tabletop exercises
Tabletop · Ransomware in a regional health authority
Illustrative
  1. 09:00Help desk reports encrypted file sharesInject
  2. 09:12Decision: isolate the finance VLANDecision
  3. 09:25Ransom note names the data takenInject
  4. 09:31Gap: no out-of-band contact list for executivesGap
  5. 09:40Decision: notify cyber insurer within 2 hoursDecision

In the room

JMAKRPSLDN

Outputs

  • 2 decisions recorded
  • 1 gap → new risk
  • Record exported

Third-party risk

Know which suppliers matter and whether they are ready.

Inventory vendors, discover them from your identity provider, run questionnaire campaigns through an external respondent portal, and track incident readiness, continuity and service levels for critical parties.

  • Discovery and inventory

    Pull vendors from your identity provider and other connectors, with the option to keep or hide historical discovery data.

  • Questionnaire campaigns

    Send, chase and score questionnaires; respondents answer through a secure portal without needing an account.

  • Readiness for critical parties

    Track IR readiness, BCP and DR posture, SLAs and uptime for the parties your operations depend on.

More on third-party risk
Third-party risk
Illustrative
VendorTierReadinessReview
Northstar PayrollCritical
92
Due
Cascade Cloud EHRCritical
88
Current
Pacific Print ServicesLow
54
Current
Summit IdentityHigh
95
Current
Tideline AnalyticsMedium
61
Overdue

And the rest of the programme

Incident readiness, reporting, AI governance and partner operations.

Incident readiness

Keep playbooks current, run the war room from the same system that holds your risks and contacts, and produce the readiness attestation that insurers, customers and boards request.

  • Playbooks tied to scenarios
  • War room
  • Attestation pack
Read more

Board and executive reporting

Executive risk overviews, programme coverage and versioned board briefs are generated from live data, exported as accessible PDFs, and kept as a record of what the board was told and when.

  • Versioned reports
  • Programme view
  • Accessible output
Read more

AI, API and integrations

AI processing is off until you turn it on. When you do, it runs through a Canadian-region endpoint by default, or your own provider keys, and every suggestion lands in a review queue. The public API and MCP server expose the platform to your tooling and agents.

  • Off by default, your choice of provider
  • Proposals behind review
  • API first, MCP included
Read more

Partners and multi-tenancy

A partner dashboard, managed tenants, sandbox environments and partner branding let a consultancy or MSSP run programmes for many customers, buying units in a pool or allocating them per customer.

  • Managed tenants
  • Your brand in front
  • Units, pooled or per customer
Read more

Frameworks

Map a control once. Answer to every framework.

A common control set sits underneath the framework catalog, so one implemented control counts everywhere it applies.

IN

ISO/IEC 27001

Information security management system.

UN

SOC 2

Trust Services Criteria for service organisations.

UN

NIST CSF 2.0

Cybersecurity Framework, including the Govern function.

IN

ISO/IEC 42001

AI management system.

UN

HIPAA

US health privacy and security rules.

EU

GDPR

EU data protection regulation.

CA

Canadian privacy

PIPEDA and provincial privacy law.

Proposals · awaiting review
Illustrative
New risk

Third-party outage at Cascade Cloud EHR

From exercise TT-14 transcript

Approve with reasonEditDismiss
Control change

Add out-of-band contacts to IR playbook

From gap G-07

Approve with reasonEditDismiss

AI settings

Processing
RegionCanada
KeysYour own
Writes directlyNever

AI, on your terms

AI that proposes. People who decide.

AI processing is off for every new account until you turn it on. When you do, it runs through a Canadian-region endpoint by default or through your own provider keys, and everything it produces is a proposal with a review queue in front of it.

  • Off by default

    Enabled per account in the setup wizard.

  • Canadian endpoint

    Or bring your own provider and keys.

  • Human approval

    Approve with a recorded reason, or dismiss.

  • Never writes directly

    Agents create proposals, not records.

Who it is for

Designed for the people who carry the risk.

Security leaders

For CISOs and vCISOs who report to a board and need the programme to show its work.

  • A register the board reads. Risks in business language, traced to controls and exercises.
  • Exercises as evidence. Every tabletop produces a record of decisions, gaps and follow-ups.
  • Coverage across frameworks. Implement once, report against ISO 27001, SOC 2 and NIST CSF 2.0.

Consultancies and MSSPs

For firms that run risk programmes for many clients and want a platform, not a folder of templates.

  • One console, many clients. Managed tenants with database-enforced separation.
  • Your brand on the output. Partner branding on reports and the client experience.
  • Flexible commercials. Pooled or per-client unit allocation, billed to you.

Boards and executives

For directors and executives who want to see the programme, not a point in time.

  • Consistent quarter to quarter. Versioned reports with the same structure every time.
  • Plain language. Risk written for decision makers, with detail available on request.
  • Accessible by default. Tagged PDF export and screen-reader support.
Launching soon

Trace risk. Reduce impact.

RiskTrace is in build. Leave your work email and you will get one message when the doors open.

One email when sign-up opens. No mailing list, no follow-ups.

FAQ

Questions, answered plainly

Short answers now; the full documentation ships with the product.