Skip to content

Authored by: Dan DeCloss

Posted on: September 15, 2026

PlexTrac by Brinqa: What is changing and what is not

A letter to our community on supercharging offensive security validation while keeping our core promise intact.

By Dan DeCloss — Founder & Chief Customer Brand Officer

When we launched PlexTrac, we set out to build a platform by offensive security practitioners, for offensive security practitioners. We wanted to eliminate the manual pain of reporting, streamline engagement management, and make sure that security assessments led directly to real risk reduction. Our mission has always been to help security teams win the right battles. That means we have to help teams pick the right battles to fight. That journey led us to the acquisition by Brinqa. Naturally in these times of transition, some honest questions arise. What happens to the PlexTrac platform I rely on every day? Is anything changing?

I want to answer those questions clearly and directly. Here is what is staying the same, what we are investing in, and how combining forces with Brinqa opens up game-changing opportunities for both PlexTrac and Brinqa customers.

What Isn’t Changing: Our Commitment to You

First and foremost: PlexTrac is not going away.

PlexTrac will continue operating as a standalone offering, delivering the exact core experience, speed, and workflows you rely on today. With this acquisition it allows us to invest more resources into the proactive security management workflows that have been our foundation.  Areas of focus include:

  • Deployment Options: Whether you run PlexTrac in our multi-tenant cloud SaaS, a dedicated private hosted instance, or rely on our client-hosted, air-gapped Docker deployments for offline testing, all deployment models remain fully supported and active.
  • Built for Practitioners: Our dedication to offensive security teams, penetration testers, and purple teamers remains unchanged. We are maintaining the focus on making reporting frictionless and engagement execution seamless.
  • Your Trusted Workflows: Your templates, finding libraries, runbooks, and current integrations are here to stay and will continue to be fully supported.

Joining Brinqa gives our team a larger foundation to ensure that hands-on, human-validated offensive security expertise continues to sit at the center of enterprise cybersecurity.

What We’re Investing In: Accelerating the Foundational Product

Rather than slowing down, our joint team is pouring fresh engineering resources into the core PlexTrac platform. We are actively focusing on key feature areas to make your daily workflow faster and more intuitive. Here is a sample of what’s coming:

1. Full Engagement Lifecycle Management

Our commitment is to help automate as much of the engagement management process as possible. We’re starting with the ability to support custom intake forms for scheduling engagements. Our scheduling module will now support your ability to request any information you need to scope and prepare for engagements. During the engagement there will be a custom notes section for freeform notes that don’t need to be in the report itself. And finally, we’ll be supporting the full automation of the retest lifecycle. 

2. Agentic Retest Validation

We’ve always supported the tracking and remediation lifecycle as a core part of our offering. This allows teams to have real-time visibility into the status of any finding and who is responsible for remediation. Once a finding has been closed as fixed, testers still have the responsibility of validating several items including whether the fix actually worked, and will the issue recur. We’re going to be launching an agentic validation solution that will automatically validate whether the closed items are actually fixed or not. Furthermore, this agent will be able to test for recurrence to ensure the same issues don’t keep getting reported.

3. Attack Path Visualization 

We will be improving the ability for testers to document their attack paths with a revolutionized attack path builder. This bridges the gap between the number of findings in a report versus their linkage in the attack chain. Improving this visualization enhances the value and impact of the report and provides clear visibility into which findings to prioritize.

4. Integrations

Importing data from multiple sources has been a key tenet of our platform from day one. We’re committed to expanding those data sources and tapping into the integrations that Brinqa already supports. This will further enhance testing teams abilities to scope engagements and highlight risks coming from various sources within the enterprise. 

What IS Changing: Closing the CTEM Loop

What is changing is the value you can deliver to your organization or client base. By integrating PlexTrac into Brinqa, we are closing the Continuous Threat Exposure Management (CTEM) loop—connecting offensive validation directly with enterprise exposure data.

Turning Reports into Live Exposure Intelligence

A vulnerability marked “closed” in a ticketing system is just a status update. A vulnerability confirmed closed through validated retesting is proof.

Through our enhanced PlexTrac-to-Brinqa connectors, human-validated exploitability and attack-chain evidence flow natively into Brinqa’s CyberRisk Graph. This enables organizations to:

  • Automatically suppress or reduce risk scores where testers confirm an exposure is not exploitable in practice.
  • Prioritize pentest and offensive resources on the critical business exposures that actually matter.
  • Pass retest requests automatically back to offensive teams as fixes are deployed, creating a continuous feedback loop.

The Road Ahead

This acquisition creates the largest standalone vendor in Unified Exposure Management, bringing together two recognized platforms. Our mission remains the same and the joint solution brings to the market what is desperately needed–a single source of truth for all of your cyber risk and a platform that facilitates the entire exposure management lifecycle.

We are excited to share these updates with you as new features roll out over the coming months. Thank you for being a part of the PlexTrac community, the best is truly yet to come!


Have questions about upcoming updates or want to see the new capabilities in action? Reach out to your customer success team or visit www.brinqa.com/plextrac.

Dan DeCloss
Dan DeCloss PlexTrac Founder/CTO Dan has over 15 years of experience in cybersecurity. Dan started his career in the Department of Defense and then moved on to consulting where he worked for various companies. Prior to PlexTrac, Dan was the Director of Cybersecurity for Scentsy where he and his team built the security program out of its infancy into a best-in-class program. Dan has a master’s degree in Computer Science from the Naval Postgraduate School with an emphasis in Information Security. Additionally, Dan holds the OSCP and CISSP certifications.

Liked what you saw? We’ve got more content for you

Ask, Analyze, and Act with PlexTrac MCP

Security teams are already experimenting with AI. They use it to summarize technical information, improve remediation guidance, prepare executive communications, and analyze complex datasets. But when it comes to using AI with live exposure data, many teams have stopped short. Getting useful answers often means exporting findings, copying sensitive information into another tool, manually removing...

How PlexTrac Helps MSSPs Build Recurring Revenue

Selling one-time pentests is hard to grow on. The market is crowded, the work is commoditized, and every engagement ends with a PDF and a quiet client until the next sale. The providers growing predictable revenue are shifting clients to continuous threat exposure management (CTEM), the operating model Gartner has made the reference point for...

Request a Demo

PlexTrac supercharges the efforts of cybersecurity teams of any size in the battle against attackers.

See the platform in action for your environment and use case.