Catch phishing, malware, and unauthorized access reports the moment they happen — one structured form your whole company can reach in 8 seconds.
A structured cybersecurity incident report form built for SOC, IT, and security teams. Anyone in the company can log a suspected phishing email, lost laptop, or strange account activity in under a minute, and the right responder gets pinged before the attacker moves.
15 fields — customize any field or add new ones with AI.
Need different fields?
Tell the AI what to change — "add a budget dropdown" or "remove phone number" — and it edits the form instantly. Every field type above can be added, removed, or relabeled through the chat interface.
Everything you need to launch this form in minutes, share it with your team, and collect submissions reliably.
Critical and High submissions trigger an immediate Slack ping to your SOC channel via webhook; Low and Informational go to a daily digest so analysts aren't paged for spam reports.
Reporters drop .eml files, screenshots, and log snippets straight into the form — no more lost attachments or 12MB inbox limits stripping the headers you actually needed.
A dedicated indicators-of-compromise field keeps URLs, IPs, and hashes in one place, ready to paste into your SIEM or threat-intel platform without parsing free-form prose.
Toggle the reporter-name fields to optional so employees can flag suspected internal misuse without putting their name on the ticket — important for insider-threat programs.
Every submission is logged with detection time, submission time, and reporter identity, giving you the chain-of-custody record SOC 2 and cyber-insurance reviewers ask for.
A laptop is the worst place to report a lost laptop. The form works on any phone, so a sales rep at an airport can log a stolen device before they've even reached the gate.
Click "Use this template free." Flexform loads the form instantly — no account needed to preview.
Type what you want to change in the chat: fields to add or remove, rename labels, change field types, or rearrange pages.
Link to Slack or Google Sheets with one click, then embed on your site or share the link.
Pin the form link in your "Report Phishing" Outlook button or Slack /phish command. Employees paste the suspicious email, attach the .eml, and the SOC has everything it needs to pull headers and block the sender — usually before a second user clicks the link.
A laptop goes missing on a business trip. The employee opens the form on their phone, marks "Lost/Stolen Device," and severity routes the report straight to IT so the device can be wiped via MDM and the corresponding accounts force-logged-out within the hour.
When a user notices logins from a country they've never visited or an MFA prompt they didn't request, the form captures timestamp, location, and the account in question — exactly the inputs your IR runbook needs to start an investigation.
A SaaS vendor emails to say they've had a security event. Your vendor manager logs it on the same form with vendor name, affected data, and notification timestamps, giving compliance the audit trail required for breach-notification clocks.
Run a duplicate version of the form with reporter identity optional. HR and security share the inbox so concerns about data exfiltration or policy violations have a private, structured channel that isn't the CISO's personal email.
Managed-security providers can spin up one form per client, embed it on the client portal, and route each submission to the right SOC queue based on which form was used — no shared inbox, no misrouted tickets.
Connect this form to your existing tools with no middleware. Every submission triggers your workflow automatically.
Data appears in your CRM or spreadsheet within 1–2 seconds of submission — no cron jobs, no delays.
Route submissions to different Slack channels, HubSpot pipelines, or Airtable bases based on field values.
Pre-fill form fields with CRM data for returning visitors. Update existing records instead of creating duplicates.
Yes. The cybersecurity incident report template, the share link, and the Slack and Google Sheets integrations are all on the free plan. You can run it indefinitely without entering a credit card — most small security teams never need to upgrade.
Wire the form to your paging tool — PagerDuty, Opsgenie, or a Slack channel monitored by on-call — using the webhook integration. You can filter on the severity field so only High and Critical submissions trigger a page, and the rest land in a daily digest. Most teams have this set up in about 20 minutes.
Yes. Mark the reporter name and email fields as optional, or duplicate the form into a separate anonymous version for insider-threat use. The form still records submission timestamps and any IOCs, which is usually enough for the SOC to validate.
The evidence field accepts screenshots (PNG, JPG), email source files (.eml, .msg), PDFs, and most log formats (.txt, .csv, .json). Individual files can be up to 25MB on the free plan, which covers full email headers and most log excerpts.
It captures the data points those frameworks expect: detection timestamp, reporter, affected systems, severity, and actions taken. Auditors generally want the form plus a documented response procedure, so pair it with your incident-response runbook. We've had customers use it as their primary intake mechanism through clean SOC 2 Type II audits.
Yes, and you don't need to touch JSON. Open the form in the editor, tell the AI "change the incident type options to Phishing, Malware, Unauthorized Access, Data Loss, Policy Violation, Physical Security, and Other," and it rewrites the field. You can do the same for severity tiers if you use Low/Medium/High/Critical instead of a numeric scale.
Yes. FlexForm ships a Kotlin Multiplatform SDK that renders the same form natively on Android and iOS, so you can put incident reporting one tap from the home screen of your employee app. Submissions flow through the same Slack and webhook routing you set up for the web version.
Submissions are stored in your FlexForm workspace and accessible only to the team members you invite. You can also push them straight to your own systems via webhook and skip the FlexForm-stored copy if your security policy requires data minimization. Workspace access supports role-based permissions so SOC analysts and GRC reviewers can see different views.
Confidential workplace harassment report with anonymity option and witness fields. Customize with AI, route to HR confidentially — free.
Document workplace injuries with date, location, body part, witnesses and first-aid given. Customize with AI, route to HR + Safety — free.
A free document review and approval form template with file uploads, reviewer assignment, and e-signature. Share a link, route approvals through Slack.
Open the template, customize with AI, connect your tools, and publish — in under 5 minutes.
No signup required · Free forever plan