For teams accountable for product-security response

The operating system for product-security response.

REMEDiS is being built for the moment a vulnerability report becomes a product, customer, and business decision. It brings the full PSIRT lifecycle—intake, triage, mitigation coordination, disclosure, and learning—into one accountable workspace.

Start with one clear response record. Grow into AI-assisted analysis and connected workflows without giving up control of critical decisions.

Built for PSIRT leadsClear work for engineeringEvidence for stakeholdersAI with accountable control

Why REMEDiS

The work your PSIRT carries should not live in six systems.

When a vulnerability arrives, the response crosses product, engineering, legal, communications, researchers, deadlines, and evidence. REMEDiS is being built to make that work legible, coordinated, and defensible from first contact through closure.

01

Run a program, not a ticket queue

Keep intake, evaluation, determination, mitigation, disclosure, and learning connected to the same accountable response record.

02

Give every team the right context

Surface the next decision, owner, deadline, blocker, and evidence instead of making people reconstruct the case across tools.

03

Use AI without losing accountability

Prepare analysis, drafts, and coordination from bounded evidence while people remain responsible for consequential decisions and external actions.

Built for the people who are accountable

One response. The right view for everyone who has to move it forward.

REMEDiS starts with the product-security lead and gives every collaborating team the context it needs without fragmenting the record.

PSIRT & product-security leads

Own intake, decisions, deadlines, and disclosure with a program record that does not depend on a single expert, inbox, or spreadsheet.

Product & engineering leaders

Give teams a specific response context—scope, ownership, requested work, and timing—without turning product security into another opaque queue.

Security, legal & executive stakeholders

See the rationale, approvals, risk, and release status needed to stand behind a response when customers, auditors, or regulators ask.

Early-access exploration

See whether REMEDiS fits the program you are building.

Use your company domain to preview limited public program signals. It is a read-only starting point for a guided workspace; your team reviews every proposal before it becomes program truth.

Protected, read-only discovery. A public signal is never treated as your program's truth without review.

Review proposal

Record your decision

Decide report

Accept operational ownership?

Withdraw prepared action

Revoke this acceptance proposal?

Revocation prevents this pending proposal from being confirmed. It does not alter the preserved report or any existing case.

Human determination

Record what this case represents

Operational plan

Update accountable case state

Resolved records internal disposition. Closing is stricter: no next action, open or blocked work, active disclosure approval, unresolved correspondence, or warning/breached internal deadline.

Least-privilege invitation

Invite a product-security teammate

The recipient must authenticate as this exact email identity. Initial invitations cannot grant ownership.

Immediate authority change

Revoke workspace membership?

The member's identity session may remain valid, but workspace authorization will fail on its next request. Historical audit attribution remains intact.

Evidence-backed case work

Add a question, remediation task, or verification

This is an accountable work record, not a visual card position. Completion requires a resolution, cited evidence, and completed dependencies.

Must finish first

Exact disclosure checkpoint

Prepare an independently reviewed package

This records approval evidence only. It does not send, publish, file, or prove delivery. Destinations are declared, not verified.

Independent package review

Decide this exact checkpoint

Compare the exact content, declared destinations, evidence, expiry, and package hash. Approval is not execution or legal sign-off.

Package SHA-256
Exact content
Declared destinations
Evidence
Request rationale
Expires

Researcher correspondence

Authorize an evidence-backed message

Review the exact text. Authorization creates an immutable tenant record; submission is attempted once to prevent duplicate mail. “Provider accepted” is not proof of delivery.

Product knowledge

Register an exact shipped release

Release impact

Determine exact product scope

Select every release examined. Unselected releases remain outside this decision—not implicitly unaffected.

Portable decision record

Export an immutable case dossier

TLP:RED

The JSON dossier preserves the current case, source report, product scope, evidence manifest, correspondence, clocks, and relevant audit trail. Attachment bytes remain separately encrypted and are bound by digest. The tenant hash chain is inspectable, but externally signed checkpoints are not yet claimed.

Provenance

Source evidence