Response coordination Institution-led

Secvisogram

Creates and edits machine-readable CSAF security advisories in a web interface for coordinated publication and exchange of vulnerability information.

By German Federal Office for Information Security (BSI) · Germany

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Response coordination
Developer or maintainer
German Federal Office for Information Security (BSI)
Recorded country
Germany
Product model
Open source
Deployment
Self-hosted
Software license
MIT
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

BSI's official repository identifies Secvisogram as its CSAF web editor; BSI is a German federal institution based in Bonn.

Reported capabilities

  • CSAF 2.0 and 2.1 advisory editor
  • Web-based validation and editing
  • Self-deployment documentation

Scope and limits

This is an advisory authoring and validation editor, not a vulnerability scanner or managed disclosure service. A demo URL alone is not treated as generally available hosted service.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    README identifies BSI Secvisogram as a CSAF 2.0/2.1 web editor, with documentation to run the application in a self-hosted environment.

    Read source
  2. origin / country

    Repository belongs to official BSI project organization, whose page lists the German federal office in Bonn.

    Read source
  3. license

    Actual root license is MIT, with BSI copyright.

    Read source
  4. maintenance

    Upstream default-branch Atom feed records a commit on 2026-06-23; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.

An incident response case management workflow