Skip to content

Protect and Harden

Read findings, decide what matters, author the fix, and drive it to closure.

Autonomous vulnerability remediation: exposure triage, real exploit-signal scoring, fix-as-code, and reversible rollout.

What this category delivers

Three outcomes, not a feature list.

01

Rank on real exploit signal

KEV membership and EPSS probability, weighted against whether the asset is actually reachable.

02

Get the fix written for you

The remediation is authored as code against your own patterns, not described in a ticket.

03

Roll it out reversibly

Your orchestrator executes it, the result is verified, and the rollback is recorded before it runs.

The agents

1 agent in Protect and Harden

Each one owns its job end to end, with its own pipeline, its own integrations, and its own workspace.

Protect and Harden

VERA Vulnerability Remediation

Ranks exposures on real exploit signal, writes the remediation as code against your own patterns, and drives it through your orchestrator reversibly.

  • Exposure normalisation. Findings from every scanner become one deduplicated exposure queue, so the same CVE on one host is one item.
  • Real exploit-signal scoring. KEV membership, EPSS probability, reachability, and asset criticality, not CVSS on its own.
  • Fix authored as code. The remediation is written against your own patterns, so it looks like something your team would have written.
  • Your orchestrator executes it. Kestra, Automox, or Ansible through Semaphore. The agent drives what you already run.