Exposure normalisation
Findings from every scanner become one deduplicated exposure queue, so the same CVE on one host is one item.
Protect and Harden
Ranks exposures on real exploit signal, writes the remediation as code against your own patterns, and drives it through your orchestrator reversibly.
What it does
Reads findings, decides what matters, authors the fix, and drives your orchestrator to closure.
Findings from every scanner become one deduplicated exposure queue, so the same CVE on one host is one item.
KEV membership, EPSS probability, reachability, and asset criticality, not CVSS on its own.
The remediation is written against your own patterns, so it looks like something your team would have written.
Kestra, Automox, or Ansible through Semaphore. The agent drives what you already run.
Every remediation class has an approval requirement and an SLA, and the queue shows what is breaching.
The fix is verified after execution, and the rollback path is recorded before it runs.
How it works
Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.
How it works
See
Scanner output is normalised, deduplicated, and enriched with asset ownership and reachability.
Decide
Each exposure is scored on KEV, EPSS, reachability, and criticality, then banded into act, attend, or track.
Act
The fix is authored, approved where required, executed by your orchestrator, verified, and recorded with its rollback.
Command Center
Governance
What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.
Normalises and deduplicates findings, scores and ranks exposures, authors fixes, and executes remediation classes you have pre-approved.
Anything touching production outside a pre-approved class, and any fix without a recorded rollback, waits for an owner.
Every scoring decision with its drivers, the authored fix, the approval, the orchestrator run, the verification, and the rollback path.