Threat intelligence evidence for SOC 2, ISO 27001 & NIS2

Threat intelligence monitoring evidence, ready before the audit asks.

TrawlSec turns continuous threat intel monitoring into the audit trail your auditor wants: findings, reviewer sign-off, and an exportable report mapped to your controls — not a scramble the week before the audit.

From finding to signed-off report

This workflow is the compliance artifact — every step leaves a record an auditor can follow.

Findings

TrawlSec continuously monitors threat intel feeds and advisories, matching every finding to the assets you actually run so nothing relevant is missed and nothing irrelevant makes the cut.

Review

A reviewer works each finding to a disposition — confirmed, ignored, or false positive — with a timestamp and reasoning captured automatically.

Sign-off

Once a reviewer closes out a period, that review is locked in as the record. No spreadsheets to reconstruct after the fact.

Exportable report

Every review period compiles into a clean report your auditor can read on its own — the artifact for SOC 2 CC7.2/CC7.3, ISO 27001 A.5.7, and NIS2 Article 21(2)(e) vulnerability-handling evidence requests.

Built for the evidence, not just the feed

Continuous monitoring, mapped to your assets

Threat intelligence findings are matched to the assets you actually run, so what lands in front of your reviewer is relevant — not a raw feed dump.

A reviewer trail auditors recognize

Every disposition — confirmed, ignored, false positive — is logged with who, when, and why, building the review history auditors expect to see.

Sign-off, not just triage

Review periods close with an explicit sign-off, so there is a clear record that threat intelligence monitoring actually happened on schedule.

Reports built for the ask

Export a report scoped to the control and period an auditor is asking about, ready to hand over without a week of reconstructing it from tickets and Slack.

Sources monitored

Live today — matched against the assets you tell TrawlSec you run.

NVD

The US National Vulnerability Database (nvd.nist.gov) — the standard CVE source most teams already track.

EUVD

ENISA's European Union Vulnerability Database — the EU's own CVE-equivalent, launched under NIS2.

Custom RSS/Atom feeds

Point TrawlSec at any advisory or security news feed your team already tracks.

Pricing

Start free, upgrade as your team and asset inventory grow.

On the roadmap

More sources to monitor, and more ways to get findings out of TrawlSec.

Webhooks

Push findings into Slack, Jira, or your own systems as they land, instead of only reviewing them in-app.

Public API

Pull your findings into your own tooling with a token-authenticated, read-only API.

AI-assisted matching

A second-pass check on top of keyword matching that filters out unrelated CVEs before they ever reach your review queue.

AI-assisted deduplication

Recognize when NVD, EUVD, and your RSS feeds are all reporting the same underlying vulnerability, so you review it once instead of once per source.

Subscribe for news

We're in beta and building in the open. Leave your email for product updates.