Public alpha · self-hosted · rough edges expected

Your incident timeline,
self-hosted.

Log detections as they happen, auto-enrich the IOCs, generate the report. Runs on your own infrastructure. The alpha is public now, and still rough in places, that's where you come in.

Docker in <3 min Self-hosted AGPL-3.0 Local AI (Ollama)
IRDoc — Incidents
SEV-1 Phishing, finance team credential harvest INC-2026-0417 OPEN
JM J. Marlowe IOCs 6 Tasks 4/7 Attachments 3
VirusTotal
AbuseIPDB
Shodan
Azure AD / Entra
SharePoint
Ollama / Claude / OpenAI
VirusTotal
AbuseIPDB
Shodan
Azure AD / Entra
SharePoint
Ollama / Claude / OpenAI

Everything your SOC team needs.
Nothing they don't.

From first alert to final report, all in one self-hosted workspace. Free, open-source, yours.

Timeline-First Investigation
Six entry types keep the record structured: detection, analysis, containment, evidence, comms, note. Drag to reorder, paste a screenshot, or paste raw text, any IOCs inside are auto-detected on save.
IOC Auto-Enrichment
Paste any text, IPs, domains, hashes, emails auto-detected. VirusTotal + AbuseIPDB + Shodan fire on add.
Emailattacker@phish.xyz
Domainsupport-verify.xyz
IP185.220.101.47
VT + AbuseIPDB + Shodan
Local AI Reports
Runs Ollama locally. Generates executive summaries and analyst recommendations. No data leaves your network.
Ollama
Report Template Builder
Compose reports from drag-and-drop blocks. Save named templates per audience, management, analysts, legal.
⋮⋮Cover Page
⋮⋮Stat Rowseverity · duration
⋮⋮AI Narrativelocal Ollama
PDF
SharePoint Auto-Sync
Every update regenerates the management brief on SharePoint. 60s debounce, so rapid changes don't fire multiple uploads. Management opens a link, no IRDoc login required.
Last synced 2 min ago
Structured Task Playbooks
Phase-grouped checklists load from the incident template the moment a case opens. Always visible on the right side.
✓
Validate phishing report
✓
Block domain at DNS
Reset 3 compromised accounts
Report Builder

Reports for every audience

Compose reports from drag-and-drop field blocks. Save named templates per audience. Management gets executive language, analysts get full technical depth, legal gets the compliance structure.

Management Brief
Executive summary, stat row, active IOCs, AI narrative, containment actions.
Technical Report
Full timeline, all IOCs with enrichment scores, evidence register, task checklist.
Legal / Compliance
Root cause, detection timeline, affected data, regulatory obligations, preventive actions.
PDF
Report Template Builder — Management Brief Preview ↗
⋮⋮Cover Pagetitle, ref, severity
⋮⋮Stat Rowseverity · duration · users
⋮⋮Executive Summaryincident.exec_summary
⋮⋮AI Narrativelocal Ollama
⋮⋮IOC Tablefilter: active
⋮⋮Timelinefilter: containment

Add Block

Text Block
Evidence Reg.
H Header
── Divider
↵ Page Break

Built in the open.
Alpha is live.

Everything listed as shipped is already in the codebase. The alpha puts it directly in your hands.

Core Incident Workspace
Timeline-first investigation with entry types (detection, analysis, containment), IOC management with auto-enrichment, evidence attachments, structured task playbooks, and investigation graph.
✓ Shipped
Report Builder + Local AI
Drag-and-drop template builder composing reports from field blocks. PDF, DOCX, Markdown export. Local Ollama AI for executive summaries and analyst recommendations, no data leaves your network.
✓ Shipped
SharePoint Auto-Sync
Debounced automatic push to SharePoint on every incident update. Management reads a link, no IRDoc access required.
✓ Shipped
Integrations + Enterprise Auth
VirusTotal, AbuseIPDB, Shodan. OIDC SSO (Entra ID / Azure AD). Inbound webhook API for any ticketing tool.
✓ Shipped
Public Alpha
First public release is live. Self-hosted via Docker Compose in under 3 minutes, or try the hosted demo above. Rough edges are expected, that's what the alpha is for.
Live now
Multi-tenancy + MSSP Mode
Full org isolation, immutable audit log, custom branding, and MSSP-ready architecture for managing multiple clients.
2027