
Incident Response Documentation Platform
Timeline-first IR documentation with visual report builder, SharePoint auto-sync, and AI-assisted summaries.
IRDoc is a self-hostable, open-core incident response documentation platform for SOC analysts, IR engineers, and MSSPs.
It gives your team one structured workspace to document an incident from first detection to final report - instead of switching between a ticket system, a Word document, and a SharePoint folder.
Core promise: Document incidents the way you actually investigate them - fast, structured, and reportable in one click.
The core above is AGPL-3.0 and free forever. See irdoc.io for details.
Full docs, quick start, and deployment guides: docs.irdoc.io
If you discover a security vulnerability, please report it to [email protected] rather than opening a public issue.
We aim to release patches for critical vulnerabilities within 24 hours of confirmation. See the badges above for our automated scanning (CodeQL, secret scanning, dependency audits, and an OpenSSF Scorecard).
Contributions are welcome. See the contributing guide before opening a PR.
IRDoc's core is free and will stay that way. If your organization relies on it and wants to support ongoing development, you can sponsor via GitHub Sponsors or Ko-fi.
Core (this repository): AGPL-3.0