Skip to content
RiskTrace

Platform

Launching soon

Everything a risk programme needs, in one system that remembers.

RiskTrace connects the register, the controls, the exercises and the board brief so a finding in one place shows up everywhere it matters. Below is each part of the platform and how it works.

How it fits together

A finding travels through the whole programme.

Nothing in RiskTrace is a standalone list. Each record links forward to what it causes and back to what proved it.

  1. 01

    Exercise

    A tabletop surfaces a gap.

  2. 02

    Risk

    The gap becomes a risk someone owns.

  3. 03

    Control

    The risk points at the control that treats it.

  4. 04

    Third parties

    Suppliers that matter are tracked against it.

  5. 05

    Readiness

    Playbooks and the war room are tested against it.

  6. 06

    Board brief

    The board sees it, with the evidence attached.

Risk register

A register your executives can read without a translator.

Capture risks the way the business talks about them, score them consistently, assign owners and treatments, and trace every risk to the controls, exercises and incidents that touch it.

  • Business language first

    Scenario, impact and likelihood are written for the people who own the decision, with the technical detail one click deeper.

  • Drafts stay drafts

    AI and imports propose; a person approves. Proposals sit in a review queue and never write to the approved register on their own.

  • Traceability built in

    Each risk links to the controls that treat it, the exercises that tested it and the incidents that proved it, so the register is evidence rather than a spreadsheet.

Risk register
Illustrative
RiskDomainScoreLinks
Ransomware halts clinic scheduling for 48hOperationsHigh3
Payroll vendor breach exposes staff dataThird partyHigh2
Loss of MFA on legacy VPNAccessMedium2
Backups untested for finance systemResilienceMedium1
Phishing against executive assistantsPeopleLow1

Heat map

1
2
1
1
3
2
1
1
4
1
2
2

Likelihood against impact, 23 open risks.

Controls and frameworks

Map once. Report against every framework you answer to.

A framework catalog and a common control set let you implement a control one time and show coverage for each standard, with policies versioned and approved alongside.

  • Common control set

    Controls map to framework requirements, so a change shows up in every coverage view at the same time.

  • Policies with a lifecycle

    Versioned policies, approvals and acceptance tracking, starting from templates written by practitioners.

  • Coverage you can defend

    Coverage views show what is implemented, what is evidenced and what is still a gap, by framework and by business unit.

Controls and frameworks
Illustrative

Coverage by framework

ISO/IEC 2700178%
SOC 264%
NIST CSF 2.071%
ISO/IEC 4200142%

Control

AC-07 Multi-factor authentication for remote access

Implemented · Evidenced by Exercise TT-14 · Owner IT Ops

ISO 27001 A.8.5
SOC 2 CC6.1
NIST CSF PR.AA-03
HIPAA 164.312(d)

Tabletop exercises

The tabletop is the core of the platform, not an add-on.

RiskTrace grew out of the exercises our consultants run. Build a scenario from the library, run it with the room, record decisions and gaps, and feed the findings straight back into risks, controls and playbooks.

  • Scenario library

    Reviewed scenarios move from draft to published, in English and French, and can be tailored to your sector and systems.

  • Run it in the room

    Injects, questions, timed decisions and participant responses are captured as the exercise happens.

  • Evidence, not minutes

    Every exercise produces a record: who took part, what was decided, which gaps were found and which risks and controls they map to.

Tabletop · Ransomware in a regional health authority
Illustrative
  1. 09:00Help desk reports encrypted file sharesInject
  2. 09:12Decision: isolate the finance VLANDecision
  3. 09:25Ransom note names the data takenInject
  4. 09:31Gap: no out-of-band contact list for executivesGap
  5. 09:40Decision: notify cyber insurer within 2 hoursDecision

In the room

JMAKRPSLDN

Outputs

  • 2 decisions recorded
  • 1 gap → new risk
  • Record exported

Incident readiness

Be ready before the incident, and organised during it.

Keep playbooks current, run the war room from the same system that holds your risks and contacts, and produce the readiness attestation that insurers, customers and boards request.

  • Playbooks tied to scenarios

    Each playbook links to the exercise that tested it and the risks it exists to contain.

  • War room

    Timeline, roles, decisions and communications in one place while an incident is live.

  • Attestation pack

    Assemble the readiness evidence an insurer or customer asks for from records you already keep.

War room · INC-0042
Illustrative
Incident commanderS. LeeActive
CommunicationsA. KhanActive
Legal and privacyR. PatelStanding by
Insurer notified08:52Done

Playbook

Ransomware containment

Tested in TT-14 · 3 steps open

2h 14m since declaration

Third-party risk

Know which suppliers matter and whether they are ready.

Inventory vendors, discover them from your identity provider, run questionnaire campaigns through an external respondent portal, and track incident readiness, continuity and service levels for critical parties.

  • Discovery and inventory

    Pull vendors from your identity provider and other connectors, with the option to keep or hide historical discovery data.

  • Questionnaire campaigns

    Send, chase and score questionnaires; respondents answer through a secure portal without needing an account.

  • Readiness for critical parties

    Track IR readiness, BCP and DR posture, SLAs and uptime for the parties your operations depend on.

Third-party risk
Illustrative
VendorTierReadinessReview
Northstar PayrollCritical
92
Due
Cascade Cloud EHRCritical
88
Current
Pacific Print ServicesLow
54
Current
Summit IdentityHigh
95
Current
Tideline AnalyticsMedium
61
Overdue

Board reporting

The board brief comes from the system of record, not a slide deck.

Executive risk overviews, programme coverage and versioned board briefs are generated from live data, exported as accessible PDFs, and kept as a record of what the board was told and when.

  • Versioned reports

    Every report is a version with an author and a date, so you can show exactly what was presented.

  • Programme view

    A twelve-month exercise calendar and coverage view show the board the programme, not only the point in time.

  • Accessible output

    Tagged PDF export and keyboard and screen-reader support are part of the product, not an afterthought.

Board brief · Q3 2026 · v3
Illustrative

Programme coverage

Top risks this quarter

  • Ransomware on clinical systemsHigh
  • Payroll vendor exposureHigh
  • Legacy VPN accessMedium

Exercises

4 run, 2 scheduled, 1 gap open from TT-14

AI, API and integrations

AI that stays in its lane. An API that does everything the screen does.

AI processing is off until you turn it on. When you do, it runs through a Canadian-region endpoint by default, or your own provider keys, and every suggestion lands in a review queue. The public API and MCP server expose the platform to your tooling and agents.

  • Off by default, your choice of provider

    Enable AI per account, pick the provider, and bring your own keys if you prefer. The default endpoint is in Canada.

  • Proposals behind review

    AI and automation create proposals. People approve them, with a recorded reason, before anything becomes an approved record.

  • API first, MCP included

    Nearly everything in the product is available through the REST API and the MCP server, with OAuth and scoped keys.

Proposals · awaiting review
Illustrative
New risk

Third-party outage at Cascade Cloud EHR

From exercise TT-14 transcript

Approve with reasonEditDismiss
Control change

Add out-of-band contacts to IR playbook

From gap G-07

Approve with reasonEditDismiss

AI settings

Processing
RegionCanada
KeysYour own
Writes directlyNever

Partners and multi-tenancy

Built for the consultancies and MSSPs who run programmes for others.

A partner dashboard, managed tenants, sandbox environments and partner branding let a consultancy or MSSP run programmes for many customers, buying units in a pool or allocating them per customer.

  • Managed tenants

    Create and manage customer tenants from one place, with separation enforced in the database.

  • Your brand in front

    Partner branding on reports and the customer experience, with a sandbox for demonstrations and onboarding.

  • Units, pooled or per customer

    Buy units and allocate them across customers, or dedicate them per tenant, with usage visible to you.

Partner console · Northwind Advisory
Illustrative
Harbour Health AuthorityActive

64 of 100 units used this quarter

Coastal Credit UnionActive

38 of 100 units used this quarter

City of AlderbrookOnboarding

12 of 100 units used this quarter

Sandbox · demoSandbox

0 of 100 units used this quarter

Foundations

Built on choices you would make yourself.

The platform decisions that shape every module.

Tenant isolation in the database

Every table carries the tenant, and row-level security enforces the boundary where the data lives, not only in the application.

Your keys and your storage

Bring your own encryption keys, and point evidence and documents at your own cloud storage when policy requires it.

Approvals with a reason

Separation of duties defaults to reason mode: self-approval is allowed only with a recorded reason, and every approval is audited.

API first

The screen is one client of the API. A public REST API and an MCP server with OAuth let your tooling and agents do the same work.

Content as signed packs

Frameworks, policy templates and scenarios ship as signed content packs, so updates arrive without a code deployment.

English and French

The product, scenario overlays and reports work in both official languages, with fr-CA selectable per tenant.

Launching soon

See it before anyone else.

Leave a work email and you will get one message when the doors open, plus early access for teams that ask for it.

One email when sign-up opens. No mailing list, no follow-ups.