Governed AI agents
Every recommendation — from triage to vendor-advisory ingestion — runs inside a policy-bounded agent runtime. State-changing actions require explicit approval and produce a signed decision-log entry.
CVMS unifies multi-scanner intake, CMDB-aware routing, governed AI agents, and audit-ready reporting in a single, air-gappable platform — built for regulated enterprises that cannot afford a SaaS dependency on their security telemetry.
Built against the controls of
CVMS treats vulnerability management as an engineered workflow, not a ticket queue. Detection, enrichment, decisioning, routing, and verification are first-class, observable steps — each one auditable, each one optimised for your risk appetite.
Every recommendation — from triage to vendor-advisory ingestion — runs inside a policy-bounded agent runtime. State-changing actions require explicit approval and produce a signed decision-log entry.
Qualys, Tenable, Rapid7, OpenVAS, Trivy, container and SBOM feeds normalised into a single vulnerability of record — deduplicated, scored, and joined to your CMDB on ingest.
SLA bands, escalation rules, and approval chains live in version control. No drag-and-drop opacity, no vendor lock-in, no surprise behavioural changes after a SaaS update.
Every screen in CVMS reads from and writes to the same hash-chained ledger. A finding you triage in the dashboard, an exception you approve in the agent panel, and a control you sign off in the compliance view all share one immutable history.
Total-asset, total-vulnerability, critical, overdue, exploit-known, and remediation-state KPIs computed from the live ledger. Severity ring and remediation funnel are click-through filters — no separate query language, no exported CSV round trips.
Open items grouped by SLA band — on-track, at-risk, breached, unknown — with median and p90 time-to-remediate per severity. The aging heatmap exposes the items quietly drifting past their patch window before they become incidents.
CVMS closes the gap most platforms leave open: from a single CVE finding, a support engineer sees the host, the owner, the business unit, the asset criticality, the environment, and the exact remediation path — without opening another system.
The Overview tab joins the scanner record (CVE, QID, CVSS, status) with the CMDB record (hostname, IP, owner email, business unit, criticality, environment) and the operational record (support group, lifecycle state, ticket linkage).
Result: a Tier-2 engineer can act on a critical finding without leaving the page — mean-time-to-acknowledge collapses from hours to minutes.
The AI Remediation tab fetches vendor advisories on demand (only the URL leaves your environment), extracts patch-set and KB references, and generates an impact summary, a step-by-step plan, and a runnable script — tailored to the asset’s OS and package manager.
Every output is tied to the originating finding, signed, and replayable. If an analyst overrides the AI, that override is part of the audit trail too.
The Reports module turns the live ledger into the four artefacts a regulated enterprise actually needs — an executive summary, a per-framework compliance report, vulnerability trends, and a per-asset technical report — with PDF and Excel export from every tab.
Pick a framework. Pick a scope. Pick a window. CVMS produces a deterministic, reproducible artefact — same inputs always yield the same output, with the ledger hash printed on the cover page so an auditor can verify provenance.
CVMS compares any two scans — from the same scanner or across scanners — and produces a clean delta: what was fixed, what is new, what regressed, what drifted in severity. No more side-by-side spreadsheets.
Findings present in scan A, absent in scan B — with the asset, CVE, and resolving remediation chain attached.
First-seen findings, automatically routed to the support group based on CMDB ownership and SLA band.
Closed in a prior scan, re-detected today — raised as priority and linked to the original remediation record.
CVSS or KEV status changed between scans — surfaced before the SLA band silently shifts.
+ NEW jenkins-ci CVE-2026-1144 CVSS 9.1 KEV route → DevOps
+ NEW payments-api-03 CVE-2026-0998 CVSS 8.7 -- route → PaymentsSRE
- FIXED db-prod-12 CVE-2025-44801 CVSS 9.8 -- closed by CHG0042118
- FIXED web-edge-07 CVE-2025-32801 CVSS 7.5 -- closed by CHG0042120
~ DRIFT k8s-node-04 CVE-2025-12044 7.5 → 9.1 KEV+ re-banded: at-risk
! REGRESS warehouse-app-22 CVE-2024-99100 CVSS 8.2 -- re-opened, priority
delta_summary: fixed=128 new=37 regressed=4 drift=9 ledger=ok signature=valid
PCI DSS, SWIFT, SOX, NIS2, DORA — all modelled as scoped controls over the same asset graph. The Audit Evidence Wizard packs the entire chain (finding → CMDB → ticket → signature) into a single deliverable.
Each framework card shows live posture: assets in scope, open violations, severity distribution, and the immediate next action. Click a violation, land on the originating vulnerability, see the entire remediation history.
CVMS isolates data the way regulators expect: by business unit, by environment, by support group, and by classification — with row-level enforcement at the database, the API, and the UI. A user only ever sees what their role and scope permit.
Each business unit, subsidiary, or environment can be its own logical tenant. Row-level security ensures a Treasury analyst never sees a Retail asset, even via a crafted API call.
Findings carry classification labels (Public, Internal, Restricted, Regulated). PII fields are pseudonymised by default; un-mask requires a justified, signed action recorded in the audit log.
Deploy a single platform with regional shards (EU, UK, US, APAC). Data never crosses a boundary unless an explicit, logged replication policy permits it — helpful for GDPR, Schrems II, and DORA Article 28.
CVMS treats its own attack surface as a first-class concern. Authentication, authorisation, transport, secrets, and supply chain are hardened against the same threat models the platform helps you defend against.
CVMS scales horizontally on commodity infrastructure. The same binary that runs on a developer laptop runs at multi-million-asset scale — we just add workers, shards, and replicas. No "enterprise edition" rewrite, no licence-tier feature gates.
Vulnerability management is a budget line, a regulator’s checklist, and an operational drag — all at once. CVMS shrinks all three by collapsing the toolchain, automating the busywork, and producing the artefacts you used to assemble by hand.
CMDB-aware routing puts the right finding in front of the right support group in seconds, with a ready-to-run remediation plan attached. No more triage backlog.
Deterministic reports, signed evidence packs, and a queryable ledger replace weeks of spreadsheet wrangling before each PCI / NIS2 / SOX audit.
One platform replaces the typical stack of scanner UI + ticketing exports + BI dashboard + manual evidence binder — with a lower licence cost than any single piece.
Every state change is signed and time-stamped. Auditors stop asking "can you prove" and start asking "can you export".
Your scanner output, asset inventory, and remediation history never leave your environment. Reduces third-party risk filings, supports DORA Article 28 ICT-provider scrutiny, and removes a class of breach exposure entirely.
Code-owned workflows, open data model, on-prem deployment. If we ever stop being the right partner, your data, history, and processes stay with you — nothing is hostage.
A pragmatic, code-first stack chosen for auditability, longevity, and air-gap deployment — not for vendor stickiness.
CVMS implements the five preparatory phases of NIST’s enterprise patch-management guidance as first-class platform capabilities.
We work with security, risk, and platform teams in regulated industries — financial services, healthcare, public sector, and critical infrastructure. Tell us about your scanner stack, CMDB, and compliance scope; we’ll respond with a tailored briefing.