Skip to content

Features · 15 modules

Everything your IR team needs. Nothing they don’t.

From first alert to final report — CyberGoBag covers every phase of incident response with purpose-built tools that work together. Every module is included — there are no add-ons to buy later.

01Incident response

Command and control when chaos strikes.

Six integrated modules that cover detection through closure. Every action logged, every decision tracked.

01

Incident management

Full lifecycle incident tracking from declaration to closure. Assign commanders, set severity, track SLAs, and coordinate your response from a single board.

Severity classification · SLA tracking · Commander assignment · Custom workflows

02

War room & communication

Real-time collaboration when it matters most. Dedicated war rooms per incident, direct messages, voice and video calls — all in one place, all auditable.

Incident war rooms · Voice/video (Daily.co) · AI summaries · Read receipts

03

Task management

Break response into actionable tasks. Assign to team members, set priorities, track completion. Kanban boards give your commander instant visibility.

Kanban board · Priority levels · Assignment · Progress tracking

04

FortKnoxx evidence vault

Tamper-evident evidence storage with SHA-256 hashing and chain of custody tracking. Break-glass BCP ensures access even during worst-case scenarios.

SHA-256 integrity · Chain of custody · Break-glass BCP · Regulatory hold

05

Playbooks

NIST, SANS, ISO-aligned response procedures. Visual step-by-step execution with per-user progress tracking. Never miss a critical step.

NIST/SANS/ISO · Visual editor · Progress tracking · Auto-assignment

06

Post-incident reviews

Structured PIR workflow with AI-assisted timeline reconstruction. Extract lessons learned, track improvement actions, prevent recurrence.

AI timeline · 5 whys analysis · Action tracking · Report generation

02Preparation & readiness

Build your response capability before you need it.

On-call rotations, tabletop exercises, and maturity assessments — everything your team needs to be ready when the call comes.

07

Crisis readiness

Build your incident response capability before you need it. On-call schedules, escalation policies, and communication plans — all connected.

On-call rotations · Escalation tiers · Communication plans · Severity routing

08

Tabletop exercises

AI-generated scenarios that test your team’s response. Run timed exercises with a reactive AI adversary and capture every decision as you go.

AI scenarios · Timed exercises · Adversary AI · Decision capture

09

Readiness assessments

Measure your incident response maturity against industry frameworks. Identify gaps, track progress, demonstrate improvement to leadership.

Maturity scoring · Gap analysis · Trend tracking · Board reports

03Administration & compliance

Stay compliant without the compliance overhead.

Automated regulatory tracking and tenant administration with complete audit trails — plus a marketplace for IR vendors, in development.

10

Regulatory tracking

GDPR, HIPAA, CCPA, NIS2 — automatic deadline calculation from incident declaration. AI drafts regulatory notifications. You review and approve.

Auto-deadlines · AI drafting · Multi-framework · Audit trail

11

Tenant administration

Multi-tenant architecture with database-level isolation. Custom roles, granular security policies, and complete audit logging.

Multi-tenant · RBAC · Audit logs

12

IR marketplace

Coming soon

Coming soon: connect with pre-vetted incident response vendors — DFIR, counsel, forensics — and manage retainers, engagements, and deliverables from inside the incident. In development; not yet available to customers.

Vendor directory · Retainer management · Engagement tracking

04Platform

Intelligent infrastructure, built for the worst day.

AI assistance, mobile access, and out-of-band architecture — the foundation that makes everything else possible.

13

AI-powered

AI that helps, not hinders. Smart incident declaration, war room summarization, regulatory compliance drafting, and post-incident analysis.

Smart declaration · War room summaries · Compliance drafting · PIR analysis

14

Mobile app — commander on call

Beta

A native iOS & Android app for the 3am page — rolling out in beta now. Push alerts deep-link straight into the incident. Walk the playbook step-by-step, drop into the war room, and complete tasks from your phone, protected by biometric lock. The responsive web app remains the fully-supported experience.

iOS & Android (beta) · Push + deep links · Playbook on phone · War room access · Biometric lock · Offline-aware

15

Out-of-band architecture

When your primary systems are compromised, CyberGoBag keeps running. Fully independent infrastructure ensures your response tools are always available.

Independent infra · Separate auth · Always available · Zero trust

See CyberGoBag in action.

Request a demo and we’ll provision a seeded test environment for you to run a mock breach in.

AES-256-GCM evidence vault · Out-of-band architecture