Skip to content

Protect and Harden

VERA Vulnerability Remediation

Ranks exposures on real exploit signal, writes the remediation as code against your own patterns, and drives it through your orchestrator reversibly.

Audience
Vulnerability management
Headline
Time to remediation
Sources
Scanners, KEV, EPSS, CMDB
Output
Executed fixes

What it does

Inside VERA

Reads findings, decides what matters, authors the fix, and drives your orchestrator to closure.

Exposure normalisation

Findings from every scanner become one deduplicated exposure queue, so the same CVE on one host is one item.

Real exploit-signal scoring

KEV membership, EPSS probability, reachability, and asset criticality, not CVSS on its own.

Fix authored as code

The remediation is written against your own patterns, so it looks like something your team would have written.

Your orchestrator executes it

Kestra, Automox, or Ansible through Semaphore. The agent drives what you already run.

Approval gates and SLAs

Every remediation class has an approval requirement and an SLA, and the queue shows what is breaching.

Verified and reversible

The fix is verified after execution, and the rollback path is recorded before it runs.

How it works

See, decide, act.

Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.

  1. See

    Every finding, deduplicated

    Scanner output is normalised, deduplicated, and enriched with asset ownership and reachability.

    • Qualys VMDR
    • Tenable and Nessus
    • Rapid7 InsightVM
    • Nucleus aggregated findings
    • ServiceNow CMDB ownership
  2. Decide

    Ranked on what will actually be exploited

    Each exposure is scored on KEV, EPSS, reachability, and criticality, then banded into act, attend, or track.

    • In the CISA KEV catalogue
    • EPSS above 0.9
    • Reachable from the internet
    • On a business-critical asset
  3. Act

    Fixed, verified, reversible

    The fix is authored, approved where required, executed by your orchestrator, verified, and recorded with its rollback.

    • Patch dispatched through Automox
    • Ansible run through Semaphore
    • Config change through a Kestra flow
    • Post-fix verification scan
1 / 3

Governance

How VERA is governed

What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.

What it does on its own

Normalises and deduplicates findings, scores and ranks exposures, authors fixes, and executes remediation classes you have pre-approved.

What always waits for a person

Anything touching production outside a pre-approved class, and any fix without a recorded rollback, waits for an owner.

What it records

Every scoring decision with its drivers, the authored fix, the approval, the orchestrator run, the verification, and the rollback path.

Book a demo

See VERA on your own data.