All systems

Cyber

In productionPublic repository

Live threat intelligence, and an ISMS workspace behind a login

Why it exists

Two halves of the same job. The public half watches what is being exploited right now; the private half is where an organisation's controls, risks and evidence actually live.

Who gets in

Magic-link sign-in, but access is a request an operator approves; approval is re-read from the database on every request rather than trusted from the session, so revoking it takes effect on the next navigation

Inside the system

Threat intel HUD &mapAppISMS workspaceAppRequest, approval,then sign-inServiceFeed aggregatorService93 Annex AcontrolsServiceStatement ofApplicability exportServiceCommitted fallbacksnapshotDataControls, risks &sessionsDataPublic threatfeedsExternalTransactionalemailExternalFallback refresh —run by handScheduled
Hover a box to trace what it talks to. Dashed outlines are things outside my control.