Trace risk.
Reduce impact.
RiskTrace is the cyber risk and GRC platform built around the tabletop. A risk register in business language, controls mapped once across frameworks, exercises that produce evidence, and board reporting from the same data.
Risk heat map
Framework coverage
Mapped once to a common control set.
Next exercise
Third-party outage at the EHR vendor
Thu 22 Oct · 9 participants · scenario v2 (FR available)
Board brief
Q3 v3 approved by CISO
Tagged PDF · 14 pages · 2 versions kept
Built by practitioners
The platform our consultants run engagements on, released as a product.
RiskTrace comes from Frontier Cyber, a Vancouver security consultancy. Every module exists because a client needed it in a real engagement: the register the board could read, the exercise that found the gap, the brief that went to the audit committee.
Canadian data residency
Hosted in a Canadian region with a per-tenant region model.
English and French
Product and scenario content in both official languages.
Your keys, your storage
Bring your own encryption keys and evidence storage.
API first, MCP included
Everything the screen does, your tools can do too.
The platform
One system of record for risk, controls, exercises and the board.
Each part feeds the others. A gap found in an exercise becomes a risk, the risk points at a control, and the control shows up in the board brief with its evidence attached.
Risk register
A register your executives can read without a translator.
Capture risks the way the business talks about them, score them consistently, assign owners and treatments, and trace every risk to the controls, exercises and incidents that touch it.
Business language first
Scenario, impact and likelihood are written for the people who own the decision, with the technical detail one click deeper.
Drafts stay drafts
AI and imports propose; a person approves. Proposals sit in a review queue and never write to the approved register on their own.
Traceability built in
Each risk links to the controls that treat it, the exercises that tested it and the incidents that proved it, so the register is evidence rather than a spreadsheet.
Heat map
Likelihood against impact, 23 open risks.
Controls and frameworks
Map once. Report against every framework you answer to.
A framework catalog and a common control set let you implement a control one time and show coverage for each standard, with policies versioned and approved alongside.
Common control set
Controls map to framework requirements, so a change shows up in every coverage view at the same time.
Policies with a lifecycle
Versioned policies, approvals and acceptance tracking, starting from templates written by practitioners.
Coverage you can defend
Coverage views show what is implemented, what is evidenced and what is still a gap, by framework and by business unit.
Coverage by framework
Control
AC-07 Multi-factor authentication for remote access
Implemented · Evidenced by Exercise TT-14 · Owner IT Ops
Tabletop exercises
The tabletop is the core of the platform, not an add-on.
RiskTrace grew out of the exercises our consultants run. Build a scenario from the library, run it with the room, record decisions and gaps, and feed the findings straight back into risks, controls and playbooks.
Scenario library
Reviewed scenarios move from draft to published, in English and French, and can be tailored to your sector and systems.
Run it in the room
Injects, questions, timed decisions and participant responses are captured as the exercise happens.
Evidence, not minutes
Every exercise produces a record: who took part, what was decided, which gaps were found and which risks and controls they map to.
- 09:00Help desk reports encrypted file sharesInject
- 09:12Decision: isolate the finance VLANDecision
- 09:25Ransom note names the data takenInject
- 09:31Gap: no out-of-band contact list for executivesGap
- 09:40Decision: notify cyber insurer within 2 hoursDecision
In the room
Outputs
- 2 decisions recorded
- 1 gap → new risk
- Record exported
Third-party risk
Know which suppliers matter and whether they are ready.
Inventory vendors, discover them from your identity provider, run questionnaire campaigns through an external respondent portal, and track incident readiness, continuity and service levels for critical parties.
Discovery and inventory
Pull vendors from your identity provider and other connectors, with the option to keep or hide historical discovery data.
Questionnaire campaigns
Send, chase and score questionnaires; respondents answer through a secure portal without needing an account.
Readiness for critical parties
Track IR readiness, BCP and DR posture, SLAs and uptime for the parties your operations depend on.
And the rest of the programme
Incident readiness, reporting, AI governance and partner operations.
Incident readiness
Keep playbooks current, run the war room from the same system that holds your risks and contacts, and produce the readiness attestation that insurers, customers and boards request.
- Playbooks tied to scenarios
- War room
- Attestation pack
Board and executive reporting
Executive risk overviews, programme coverage and versioned board briefs are generated from live data, exported as accessible PDFs, and kept as a record of what the board was told and when.
- Versioned reports
- Programme view
- Accessible output
AI, API and integrations
AI processing is off until you turn it on. When you do, it runs through a Canadian-region endpoint by default, or your own provider keys, and every suggestion lands in a review queue. The public API and MCP server expose the platform to your tooling and agents.
- Off by default, your choice of provider
- Proposals behind review
- API first, MCP included
Partners and multi-tenancy
A partner dashboard, managed tenants, sandbox environments and partner branding let a consultancy or MSSP run programmes for many customers, buying units in a pool or allocating them per customer.
- Managed tenants
- Your brand in front
- Units, pooled or per customer
Frameworks
Map a control once. Answer to every framework.
A common control set sits underneath the framework catalog, so one implemented control counts everywhere it applies.
ISO/IEC 27001
Information security management system.
SOC 2
Trust Services Criteria for service organisations.
NIST CSF 2.0
Cybersecurity Framework, including the Govern function.
ISO/IEC 42001
AI management system.
HIPAA
US health privacy and security rules.
GDPR
EU data protection regulation.
Canadian privacy
PIPEDA and provincial privacy law.
Third-party outage at Cascade Cloud EHR
From exercise TT-14 transcript
Add out-of-band contacts to IR playbook
From gap G-07
AI settings
AI, on your terms
AI that proposes. People who decide.
AI processing is off for every new account until you turn it on. When you do, it runs through a Canadian-region endpoint by default or through your own provider keys, and everything it produces is a proposal with a review queue in front of it.
Off by default
Enabled per account in the setup wizard.
Canadian endpoint
Or bring your own provider and keys.
Human approval
Approve with a recorded reason, or dismiss.
Never writes directly
Agents create proposals, not records.
Who it is for
Designed for the people who carry the risk.
Security leaders
For CISOs and vCISOs who report to a board and need the programme to show its work.
- A register the board reads. Risks in business language, traced to controls and exercises.
- Exercises as evidence. Every tabletop produces a record of decisions, gaps and follow-ups.
- Coverage across frameworks. Implement once, report against ISO 27001, SOC 2 and NIST CSF 2.0.
Consultancies and MSSPs
For firms that run risk programmes for many clients and want a platform, not a folder of templates.
- One console, many clients. Managed tenants with database-enforced separation.
- Your brand on the output. Partner branding on reports and the client experience.
- Flexible commercials. Pooled or per-client unit allocation, billed to you.
Boards and executives
For directors and executives who want to see the programme, not a point in time.
- Consistent quarter to quarter. Versioned reports with the same structure every time.
- Plain language. Risk written for decision makers, with detail available on request.
- Accessible by default. Tagged PDF export and screen-reader support.
Trace risk. Reduce impact.
RiskTrace is in build. Leave your work email and you will get one message when the doors open.
FAQ
Questions, answered plainly
Short answers now; the full documentation ships with the product.
