Threat intelligence evidence for SOC 2, ISO 27001 & NIS2
Threat intelligence monitoring evidence, ready before the audit asks.
TrawlSec turns continuous threat intel monitoring into the audit trail your auditor wants: findings, reviewer sign-off, and an exportable report mapped to your controls — not a scramble the week before the audit.
From finding to signed-off report
This workflow is the compliance artifact — every step leaves a record an auditor can follow.
Findings
TrawlSec continuously monitors threat intel feeds and advisories, matching every finding to the assets you actually run so nothing relevant is missed and nothing irrelevant makes the cut.
Review
A reviewer works each finding to a disposition — confirmed, ignored, or false positive — with a timestamp and reasoning captured automatically.
Sign-off
Once a reviewer closes out a period, that review is locked in as the record. No spreadsheets to reconstruct after the fact.
Exportable report
Every review period compiles into a clean report your auditor can read on its own — the artifact for SOC 2 CC7.2/CC7.3, ISO 27001 A.5.7, and NIS2 Article 21(2)(e) vulnerability-handling evidence requests.
Built for the evidence, not just the feed
Continuous monitoring, mapped to your assets
Threat intelligence findings are matched to the assets you actually run, so what lands in front of your reviewer is relevant — not a raw feed dump.
A reviewer trail auditors recognize
Every disposition — confirmed, ignored, false positive — is logged with who, when, and why, building the review history auditors expect to see.
Sign-off, not just triage
Review periods close with an explicit sign-off, so there is a clear record that threat intelligence monitoring actually happened on schedule.
Reports built for the ask
Export a report scoped to the control and period an auditor is asking about, ready to hand over without a week of reconstructing it from tickets and Slack.
Sources monitored
Live today — matched against the assets you tell TrawlSec you run.
NVD
The US National Vulnerability Database (nvd.nist.gov) — the standard CVE source most teams already track.
EUVD
ENISA's European Union Vulnerability Database — the EU's own CVE-equivalent, launched under NIS2.
Custom RSS/Atom feeds
Point TrawlSec at any advisory or security news feed your team already tracks.
Pricing
Start free, upgrade as your team and asset inventory grow.
On the roadmap
More sources to monitor, and more ways to get findings out of TrawlSec.
Webhooks
Push findings into Slack, Jira, or your own systems as they land, instead of only reviewing them in-app.
Public API
Pull your findings into your own tooling with a token-authenticated, read-only API.
AI-assisted matching
A second-pass check on top of keyword matching that filters out unrelated CVEs before they ever reach your review queue.
AI-assisted deduplication
Recognize when NVD, EUVD, and your RSS feeds are all reporting the same underlying vulnerability, so you review it once instead of once per source.
Subscribe for news
We're in beta and building in the open. Leave your email for product updates.