PSIRT operations · product security

From report to response. One place to do it right.

REMEDiS gives your PSIRT one operating record for every report—so teams can establish impact, coordinate response, and show why each decision was made.

Product teams shipping software, devices, or services

How it works

What happens to a report.

Receive

Reports arrive through your channel and stay intact—from attachment to evidence-linked review.

Evaluate

PSIRTling proposes product, release, component, and SBOM context for your team to confirm.

Coordinate

Everyone works from one case: owner, deadline, evidence, and the next decision.

Disclose

Prepare reviewed advisories and customer notices with the evidence needed for coordination.

Why now

Product security is part of shipping.

Customers and regulators expect a response you can reconstruct.

Keep reports, scope, owners, decisions, and timing together.

Who it's for

Built for the people who answer the report.

PSIRT and product security

Run intake, cases, and disclosure without losing the thread.

Engineering

Know what is affected, who owns it, and when it is due.

Leadership, legal, and customers

Get the record: what was known, decided, and shipped, and when.

Start with one product. Expand to teams, integrations, and assurance as you grow.

Need help building the program, not just the tool? REMEDiS also designs PSIRT programs and runs readiness exercises.

Talk to a PSIRT expert

Get started

Let’s get started.

Start with your website, repository, or package. PSIRTling suggests the setup details for you to review; ownership can wait.

Tell us what you ship website, repository, or package · optional

Choose context Review suggested details Create account

Add a website, repository, or package—or skip it and start with your account.

Compare another source

Add another link to compare both sources side by side. If they disagree, both stay visible for you to decide.

Use a website, repository, or package page for public context—not a workspace connection. A claimed domain never blocks your account. Have an invitation?

A quick security check protects this lookup; it does not verify ownership.

Release · current

What’s new in REMEDiS

Review context

Correct this context item

Your correction stays a proposal until an authorized operator reviews it. The original observation remains preserved.

REMEDiS Security Product-security response, as a service. Services

Review proposal

Record your decision

This records a human review outcome. It does not change the cited evidence or grant ownership.

Decide report

Accept operational ownership?

Your decision stays human-controlled. The original report and evidence remain preserved; accepting prepares a case proposal, while rejecting does not delete the report.

Withdraw prepared action

Revoke this acceptance proposal?

Revocation prevents this pending proposal from being confirmed. It does not alter the preserved report or any existing case.

Human determination

Record what this case represents

PSIRTling relationship review

Relate this case to another case

This records a human-reviewed relationship. It never merges cases, changes ownership, or closes a response. For a duplicate, record the current case as Duplicate first.

Operational plan

Update accountable case state

PSRP v2.5 stages are explicit. A stage describes response progression, not proof that a fix, delivery, publication, or legal obligation is complete. Closing is stricter: no next action, open or blocked work, active disclosure approval, unresolved correspondence, or warning/breached internal deadline.

Least-privilege invitation

Invite a product-security teammate

The recipient must authenticate as this exact email identity. Initial invitations cannot grant ownership.

Owner review

Record an access decision

Workspace access

Ask the workspace owner for access.

Your account is ready, but this site or project is already connected to another workspace. Send a request for the workspace owner to review. Approval creates an invitation; it does not add access automatically.

The owner may issue a different invitation role.

Immediate authority change

Revoke workspace membership?

The member's identity session may remain valid, but workspace authorization will fail on its next request. Historical audit attribution remains intact.

Evidence-backed case work

Add a question, remediation task, or verification

This is an accountable work record, not a visual card position. Completion requires a resolution, cited evidence, and completed dependencies.

Must finish first

Post-disclosure learning

Retain what this closed response taught the program

Closed case · tenant-local human record

This is reviewable program evidence, not a model input, training example, automatic reuse rule, knowledge-graph assertion, or shared learning contribution. A correction creates a new revision; it does not rewrite the prior record. Neither revision claims remediation or disclosure succeeded.

Exact disclosure checkpoint

Prepare an independently reviewed package

This records approval evidence only. It does not send, publish, file, or prove delivery. Destinations are declared, not verified.

Independent package review

Decide this exact checkpoint

Compare the exact content, declared destinations, evidence, expiry, and package hash. Approval is not execution or legal sign-off.

Package SHA-256
Exact content
Declared destinations
Evidence
Request rationale
Expires

Researcher correspondence

Authorize an evidence-backed message

Review the exact text. Authorization creates an immutable tenant record; submission is attempted once to prevent duplicate mail. “Provider accepted” is not proof of delivery.

Product knowledge

Register an exact shipped release

Release impact

Determine exact product scope

Select every release examined. Unselected releases remain outside this decision—not implicitly unaffected.

Portable decision record

Export an immutable case dossier

TLP:RED

The JSON dossier preserves the current case, its single-case RVO snapshot, relationship history, local disclosure-authority history, source report, product scope, evidence manifest, correspondence, clocks, and relevant audit trail. A local delivery authority is not evidence of a send, delivery, or acknowledgement. Attachment bytes remain separately encrypted and are bound by digest. The tenant hash chain is inspectable, but externally signed checkpoints are not yet claimed.

Provenance

Source evidence

Review the records that inform this view. Evidence is inspectable; decisions remain with your team.

New account · Step 1 of 3

Create your REMEDiS account.

Use any email you can open. Add a website, repository, or package if you want PSIRTling to prepare your starting profile. Ownership can wait.

Already have a REMEDiS account? Use Email sign-in here. We’ll add this device without creating another account.

Account access · workspace later Your account comes first. Add a website, repository, or package for PSIRTling to review; connect a workspace only when you are ready.

  1. 01Verify email
  2. 02Create passkey
  3. 03Review context

We’ll email a setup link. Your account comes first.

Project connection

Keep the project separate from company ownership.

For an open-source project, package, or product without a conventional company website, REMEDiS keeps the project connection separate from company ownership. Review the project now, keep your account and saved setup unbound, and connect the project through a governed workspace step when your team is ready.

  1. 01
    Review the exact project

    Use a canonical repository, package, or release coordinate as source context.

  2. 02
    Keep context separate

    PSIRTling can suggest product details, but a public link or package name is not ownership proof.

  3. 03
    Connect it later

    Your team can start the governed project-identity verification step after the account is ready.

What this does not do: claim an entire organization, execute project content, or grant disclosure or integration write authority.

Existing account · return here

Sign in to REMEDiS.

Returning to REMEDiS? Start with email sign-in to sign in and add this device. Passkeys are optional; your workspace connection stays unchanged.

Account recovery

Create a new passkey.

Use one of the recovery codes you saved when your account was created. We’ll verify it once, then let you register a replacement passkey on this device.

Operator guide

Keep the response moving without losing control.

PSIRTling summarizes cited records. Review the evidence, then decide what happens next.

  1. 01
    Preserve

    Keep the original report and supporting material as evidence.

  2. 02
    Evaluate

    Check quality, duplication, scope, source freshness, and the questions still open.

  3. 03
    Coordinate

    Connect products, releases, components, owners, and accountable work.

  4. 04
    Decide

    Record the human determination, rationale, and next action.

  5. 05
    Disclose and learn

    Prepare reviewed communication and retain what the response taught the program.

PSIRTling’s boundary: it can organize, draft, and explain. An authorized person must confirm tenant truth or authorize an external effect.

Account security

Keep your sign-in recoverable.

Review the passkeys on this account and keep recovery codes available. Credential changes require a fresh authenticated session and never change workspace membership.

Passkeys

Only names and timestamps are shown; private key material never leaves your device.

Recovery codes

Regenerating codes invalidates the previous set and signs you out so the new set is protected.