A review queue for threat models, dependency CVEs, and pen-test findings — every security concern triaged, owned, and verified fixed.
Engineering teams running security reviews without a dedicated AppSec tool.
Quick answer
The Security review template is a ready-made workspace for Engineering teams running security reviews without a dedicated AppSec tool.
Security review template in short
Included when you apply it
Applying this template creates the 1 board below — with every list — and pre-loads 3 sample issues, all yours to edit. The automation rules further down are suggestions you can wire up next; they aren't created for you yet.
A preview of how this template lays out — the boards, their custom workflow states, and where the sample issues land. WIP caps show a badge.
Security
Critical CVE in the image-processing dependency
Threat-model the new public API surface
Pen-test finding: missing rate limit on auth endpoint
These rules aren't created when you apply the template — they're recipes you can wire up in Settings → Automations once your board exists.
When
Issue labeled 'cve' with critical severity
Then
Escalate to the security lead and set a 48-hour SLA
When
Finding moves to 'Verifying'
Then
Request sign-off from the reviewer before it can close
Ready to spin this up?
Sign-up takes seconds. We build this template's boards, lists, and sample issues in your new workspace, all yours to edit.
FAQ
Sprint planning
A cycle-driven sprint board with WIP limits, estimates, and PR-linked issues — the default starter pack for product engineering teams.
View templateBug triage
An intake-to-resolution pipeline that separates triage from active fixing, with severity labels and reproduction notes on every card.
View templateRelease checklist
A repeatable release runbook as a sub-issue tree — cut, verify, ship, announce — so nothing ships half-checked.
View template