Continuous Vulnerability Management

One platform from scanner signal to remediated asset.

CVMS unifies multi-scanner intake, CMDB-aware routing, governed AI agents, and audit-ready reporting in a single, air-gappable platform — built for regulated enterprises that cannot afford a SaaS dependency on their security telemetry.

  • Air-gap ready. Runs entirely on your infrastructure — Docker Compose, Kubernetes, or bare metal.
  • Governed AI. Every agent decision is signed, replayable, and policy-bounded.
  • CMDB-native. Vulnerabilities resolve to owners, support groups, and business units in one click.
cvms.local — Security Overview
CVMS security overview dashboard with severity rings, remediation pipeline, and KPI tiles

Built against the controls of

  • NIS2
  • DORA
  • NIST SP 800-40 r4
  • ISO/IEC 27001
  • PCI DSS 4.0
  • SOX
  • SWIFT CSP
  • KNF (Rekomendacja D)
  • EBA ICT/Security
  • HIPAA
Approach

A new operating model for vulnerability response

CVMS treats vulnerability management as an engineered workflow, not a ticket queue. Detection, enrichment, decisioning, routing, and verification are first-class, observable steps — each one auditable, each one optimised for your risk appetite.

Governed AI agents

Every recommendation — from triage to vendor-advisory ingestion — runs inside a policy-bounded agent runtime. State-changing actions require explicit approval and produce a signed decision-log entry.

Multi-scanner consolidation

Qualys, Tenable, Rapid7, OpenVAS, Trivy, container and SBOM feeds normalised into a single vulnerability of record — deduplicated, scored, and joined to your CMDB on ingest.

Code-owned workflows

SLA bands, escalation rules, and approval chains live in version control. No drag-and-drop opacity, no vendor lock-in, no surprise behavioural changes after a SaaS update.

Platform

Five surfaces, one signed audit trail

Every screen in CVMS reads from and writes to the same hash-chained ledger. A finding you triage in the dashboard, an exception you approve in the agent panel, and a control you sign off in the compliance view all share one immutable history.

Operations

Security Overview — one glance, real posture

Total-asset, total-vulnerability, critical, overdue, exploit-known, and remediation-state KPIs computed from the live ledger. Severity ring and remediation funnel are click-through filters — no separate query language, no exported CSV round trips.

  • Asset and vulnerability status quick-filters wired into every tile
  • Average CVSS, KEV-flagged, and EPSS-prioritised counters refreshed per scan cycle
  • Trend chart drills down to the originating finding in two clicks
CVMS security overview with KPI tiles, severity risk profile and remediation pipeline
SLA & Remediation

SLA bands you can defend in an audit

Open items grouped by SLA band — on-track, at-risk, breached, unknown — with median and p90 time-to-remediate per severity. The aging heatmap exposes the items quietly drifting past their patch window before they become incidents.

  • Per-band, per-severity matrix with one-click CSV export
  • Top owners by SLA breaches — routes accountability, not blame
  • New-breach feed for the last 30 days, scoped to your team
CVMS SLA and remediation view with band breakdown and aging heatmap
Executive connection

Scanner data + CMDB + support group, in one view

CVMS closes the gap most platforms leave open: from a single CVE finding, a support engineer sees the host, the owner, the business unit, the asset criticality, the environment, and the exact remediation path — without opening another system.

Vulnerability detail — CVE-2021-44228
CVMS vulnerability detail showing CVE, asset, owner, support group, and remediation steps

Everything a support engineer needs — on one tab

The Overview tab joins the scanner record (CVE, QID, CVSS, status) with the CMDB record (hostname, IP, owner email, business unit, criticality, environment) and the operational record (support group, lifecycle state, ticket linkage).

Scanner record
CVE, QID, CVSS vector, KEV / EPSS flags, first / last detection
CMDB join
Hostname, IP, owner, business unit, criticality, environment, location
Routing
Support group, on-call schedule, escalation policy, change window
Action surface
Assign, change status, request exception, generate remediation, attach evidence

Result: a Tier-2 engineer can act on a critical finding without leaving the page — mean-time-to-acknowledge collapses from hours to minutes.

AI Remediation

Quick, actionable, auditable remediation guidance

The AI Remediation tab fetches vendor advisories on demand (only the URL leaves your environment), extracts patch-set and KB references, and generates an impact summary, a step-by-step plan, and a runnable script — tailored to the asset’s OS and package manager.

  • Generate Remediation Plan — impact, prerequisites, ordered steps, verification.
  • Generate Script — idempotent shell / PowerShell / Ansible snippet, ready for change-management.
  • Analyze False Positive — cross-checks scanner evidence against installed package state.
  • Get CVE Intelligence — KEV, EPSS, weaponisation indicators, public exploit references.

Every output is tied to the originating finding, signed, and replayable. If an analyst overrides the AI, that override is part of the audit trail too.

AI remediation plan
CVMS AI remediation panel with vendor-advisory ingestion and generated plan
Report Wizard

From raw posture to board-ready PDF in four clicks

The Reports module turns the live ledger into the four artefacts a regulated enterprise actually needs — an executive summary, a per-framework compliance report, vulnerability trends, and a per-asset technical report — with PDF and Excel export from every tab.

Reports & analytics — PCI DSS
CVMS report wizard generating a PCI DSS compliance report with download buttons

Built around how auditors actually read a report

Pick a framework. Pick a scope. Pick a window. CVMS produces a deterministic, reproducible artefact — same inputs always yield the same output, with the ledger hash printed on the cover page so an auditor can verify provenance.

  • 1
    Choose templateExecutive summary · Compliance report · Vulnerability trends · Technical report
  • 2
    Set framework & scopePCI DSS, NIS2, DORA, SOX, SWIFT, ISO 27001 · tag, BU, environment
  • 3
    Pick the windowLast 7 / 30 / 90 / 365 days, or fully custom · ignore-date toggle for full-history audits
  • 4
    ExportPDF for the board, Excel for the audit working paper, JSON for downstream pipelines
Scan Compare

Did this scan make us safer? Answer in one screen.

CVMS compares any two scans — from the same scanner or across scanners — and produces a clean delta: what was fixed, what is new, what regressed, what drifted in severity. No more side-by-side spreadsheets.

Fixed 128

Findings present in scan A, absent in scan B — with the asset, CVE, and resolving remediation chain attached.

New 37

First-seen findings, automatically routed to the support group based on CMDB ownership and SLA band.

Regressed 4

Closed in a prior scan, re-detected today — raised as priority and linked to the original remediation record.

Severity drift 9

CVSS or KEV status changed between scans — surfaced before the SLA band silently shifts.

Scan compare — Qualys 2026-04-12 vs 2026-04-26
+ NEW       jenkins-ci          CVE-2026-1144   CVSS 9.1   KEV   route → DevOps
+ NEW       payments-api-03     CVE-2026-0998   CVSS 8.7   --    route → PaymentsSRE
- FIXED     db-prod-12          CVE-2025-44801  CVSS 9.8   --    closed by CHG0042118
- FIXED     web-edge-07         CVE-2025-32801  CVSS 7.5   --    closed by CHG0042120
~ DRIFT     k8s-node-04         CVE-2025-12044  7.5 → 9.1 KEV+  re-banded: at-risk
! REGRESS   warehouse-app-22    CVE-2024-99100  CVSS 8.2   --    re-opened, priority
delta_summary: fixed=128 new=37 regressed=4 drift=9   ledger=ok signature=valid
Compliance

Frameworks-as-data, evidence-as-export

PCI DSS, SWIFT, SOX, NIS2, DORA — all modelled as scoped controls over the same asset graph. The Audit Evidence Wizard packs the entire chain (finding → CMDB → ticket → signature) into a single deliverable.

One scope, every framework

Each framework card shows live posture: assets in scope, open violations, severity distribution, and the immediate next action. Click a violation, land on the originating vulnerability, see the entire remediation history.

  • Per-framework scoping rules expressed in code, reviewable in pull requests
  • Audit Evidence Wizard exports a verifiable bundle — PDF + JSON + ledger proof
  • Recommendations engine highlights the controls closest to compliant
Compliance management
CVMS compliance dashboard with PCI DSS, SWIFT, SOX, NIS2 and DORA framework cards
Data segmentation

One platform, many tenants — without crossing the streams

CVMS isolates data the way regulators expect: by business unit, by environment, by support group, and by classification — with row-level enforcement at the database, the API, and the UI. A user only ever sees what their role and scope permit.

Tenant & scope isolation

Each business unit, subsidiary, or environment can be its own logical tenant. Row-level security ensures a Treasury analyst never sees a Retail asset, even via a crafted API call.

Data classification & PII guard

Findings carry classification labels (Public, Internal, Restricted, Regulated). PII fields are pseudonymised by default; un-mask requires a justified, signed action recorded in the audit log.

Cross-region data residency

Deploy a single platform with regional shards (EU, UK, US, APAC). Data never crosses a boundary unless an explicit, logged replication policy permits it — helpful for GDPR, Schrems II, and DORA Article 28.

Security

A vulnerability-management platform should be the safest service you run

CVMS treats its own attack surface as a first-class concern. Authentication, authorisation, transport, secrets, and supply chain are hardened against the same threat models the platform helps you defend against.

Identity & access

  • SSO via OIDC / SAML, with optional SCIM user lifecycle
  • Role-based access control: analyst, approver, auditor, admin, read-only
  • Just-in-time elevation with mandatory justification & expiry
  • WebAuthn / FIDO2 for high-privilege actions

Cryptography & integrity

  • TLS 1.3 enforced; HSTS preloaded; modern cipher suites only
  • Per-record encryption at rest with envelope keys (KMS / HSM-backed)
  • HMAC-SHA256 hash-chained decision log; tamper-evident audit trail
  • Signed scanner-ingest contracts; rejected on signature mismatch

Supply chain & runtime

  • SBOM published per release; signed container images (Cosign)
  • SLSA-aligned build pipeline; reproducible builds
  • Distroless runtime, non-root containers, read-only filesystems
  • Continuous self-scan: CVMS scans its own images and dependencies

Network & secrets

  • Air-gap mode: zero outbound traffic except opt-in advisory fetch
  • mTLS between internal services; egress allowlist by hostname
  • Secrets sourced from Vault / KMS — never in environment files
  • Rate-limited API; CSRF + CORS hardened; OWASP ASVS L2 baseline
Scalability

From a single rack to a global enterprise — same platform, same code path

CVMS scales horizontally on commodity infrastructure. The same binary that runs on a developer laptop runs at multi-million-asset scale — we just add workers, shards, and replicas. No "enterprise edition" rewrite, no licence-tier feature gates.

10M+
Findings ingested per day on a 3-node cluster, sustained.
500k+
Assets governed in a single deployment, with sub-second CMDB lookups.
<200ms
Median p95 API latency on the operational dashboard, fully populated.
99.95%
Achievable availability with a standard active/passive Postgres + Redis topology.

Designed for horizontal growth

  • Stateless API tier. Scale FastAPI workers behind any L7 load balancer.
  • Pluggable queue. Celery on Redis or RabbitMQ; partition by tenant, scanner, or priority lane.
  • Postgres-native. Read replicas for analytics; logical sharding by tenant for the largest deployments.
  • Vector store. ChromaDB for RAG embeddings, swappable for pgvector or a managed equivalent.
  • Bring your own LLM. On-prem (Ollama, vLLM), Azure OpenAI, or zero-LLM mode — the platform is fully usable without AI.

Operational efficiency

  • Backpressure-aware ingest. A misbehaving scanner cannot starve the platform.
  • Tenant-aware quotas. Noisy business units do not impact others.
  • Cold-storage archive. Multi-year history without inflating the hot dataset.
  • Predictable resource model. Capacity-planning tables published per release.
  • Zero downtime upgrades. Rolling deploy + DB migration with online schema changes.
Business value

What CVMS changes for your organisation

Vulnerability management is a budget line, a regulator’s checklist, and an operational drag — all at once. CVMS shrinks all three by collapsing the toolchain, automating the busywork, and producing the artefacts you used to assemble by hand.

−60%

Mean time to remediate

CMDB-aware routing puts the right finding in front of the right support group in seconds, with a ready-to-run remediation plan attached. No more triage backlog.

−70%

Audit preparation effort

Deterministic reports, signed evidence packs, and a queryable ledger replace weeks of spreadsheet wrangling before each PCI / NIS2 / SOX audit.

3→1

Tools consolidated

One platform replaces the typical stack of scanner UI + ticketing exports + BI dashboard + manual evidence binder — with a lower licence cost than any single piece.

100%

Evidence coverage

Every state change is signed and time-stamped. Auditors stop asking "can you prove" and start asking "can you export".

0

SaaS data egress

Your scanner output, asset inventory, and remediation history never leave your environment. Reduces third-party risk filings, supports DORA Article 28 ICT-provider scrutiny, and removes a class of breach exposure entirely.

Vendor optionality

Code-owned workflows, open data model, on-prem deployment. If we ever stop being the right partner, your data, history, and processes stay with you — nothing is hostage.

Architecture

Designed for the regulated enterprise

A pragmatic, code-first stack chosen for auditability, longevity, and air-gap deployment — not for vendor stickiness.

Stack

API
FastAPI 0.115 / Python 3.12, Pydantic v2
Data
PostgreSQL 15, Redis 7, ChromaDB (RAG)
Workers
Celery, scheduled via Beat
Frontend
React 18, MUI v6, Vite, react-i18next (EN / PL)
Runtime
Docker Compose, Kubernetes-compatible
AI
Pluggable agent runtime, on-prem LLM optional

Operational guarantees

  • Hash-chained decision log (HMAC-SHA256) per agent run
  • Mutating tools require explicit human approval
  • Air-gap-safe: no outbound calls except opt-in vendor advisory fetch
  • Deterministic reports: same inputs → identical PDF / Excel
  • Role-based access — analyst, approver, auditor, admin
  • Full RBAC + audit log of every state-changing action

Data flow

Scanners Qualys · Tenable · Trivy · OpenVAS
Normaliser + CMDB join
CVMS ledger signed, hash-chained
Workflows + AI agents
Analyst UI · Reports · Tickets
NIST SP 800-40 r4

Mapped to the standard, not just inspired by it

CVMS implements the five preparatory phases of NIST’s enterprise patch-management guidance as first-class platform capabilities.

1
Metrics & CPE inventoryPer-asset CPE record, KEV / EPSS enrichment, and exposure metrics — the prerequisite for measurable remediation.
2
Emergency protocolOut-of-band patch path with explicit approval, ledger entry, and post-incident reconciliation.
3
Asset inventory governanceCMDB join is mandatory — no orphan findings, no untracked owners, no silent assets.
4
Patch testing & verificationScan-compare proves the change actually closed the finding — not just the ticket.
5
Maturity & deploymentProgramme-level KPIs, SLA banding, and trend reporting feed continuous improvement.
Talk to us

Bring CVMS into your environment

We work with security, risk, and platform teams in regulated industries — financial services, healthcare, public sector, and critical infrastructure. Tell us about your scanner stack, CMDB, and compliance scope; we’ll respond with a tailored briefing.

  • 30-minute architecture walkthrough
  • Sandbox access on your infrastructure
  • Compliance-mapping workshop scoped to your frameworks
Registered office
CVMS sp. z o.o.
ul. Puławska 405 lok. 2
02-801 Warszawa, Poland
VAT EU
PL9512647459

No tracking, no analytics. Your message is delivered straight to contact@cvms.uk.