REMEDiS Security · PSIRT operations

Turn public signals into decisions you can prove.

REMEDiS gives modern PSIRTs a trusted operating record—from first report to coordinated disclosure—without hiding judgment behind automation.

Read-only discovery protected by anti-abuse verification. Nothing becomes a fact until your team confirms it.

Source-linkedTenant-isolatedPasskey securedAudit ready

Review proposal

Record your decision

Decide report

Accept operational ownership?

Withdraw prepared action

Revoke this acceptance proposal?

Revocation prevents this pending proposal from being confirmed. It does not alter the preserved report or any existing case.

Human determination

Record what this case represents

Operational plan

Update accountable case state

Least-privilege invitation

Invite a product-security teammate

The recipient must authenticate as this exact email identity. Initial invitations cannot grant ownership.

Immediate authority change

Revoke workspace membership?

The member's identity session may remain valid, but workspace authorization will fail on its next request. Historical audit attribution remains intact.

Evidence-backed case work

Add a question, remediation task, or verification

This is an accountable work record, not a visual card position. Completion requires a resolution, cited evidence, and completed dependencies.

Must finish first

Exact disclosure checkpoint

Prepare an independently reviewed package

This records approval evidence only. It does not send, publish, file, or prove delivery. Destinations are declared, not verified.

Independent package review

Decide this exact checkpoint

Compare the exact content, declared destinations, evidence, expiry, and package hash. Approval is not execution or legal sign-off.

Package SHA-256
Exact content
Declared destinations
Evidence
Request rationale
Expires

Researcher correspondence

Authorize an evidence-backed message

Review the exact text. Authorization creates an immutable tenant record; submission is attempted once to prevent duplicate mail. “Provider accepted” is not proof of delivery.

Product knowledge

Register an exact shipped release

Release impact

Determine exact product scope

Select every release examined. Unselected releases remain outside this decision—not implicitly unaffected.

Portable decision record

Export an immutable case dossier

TLP:RED

The JSON dossier preserves the current case, source report, product scope, evidence manifest, correspondence, clocks, and relevant audit trail. Attachment bytes remain separately encrypted and are bound by digest. The tenant hash chain is inspectable, but externally signed checkpoints are not yet claimed.

Provenance

Source evidence