Technology inventory
Register the products, packages, versions, environments, and criticality that define your monitoring scope.
- Canonical product catalog
- CPE and package URL identifiers
- Version and environment context
Connect what you run to what is vulnerable, keep the evidence visible, and give every team a focused path from disclosure to decision.
Each stage creates structured evidence for the next, reducing manual handoffs and making decisions easier to explain.
Register the products, packages, versions, environments, and criticality that define your monitoring scope.
Collect vulnerability data on a schedule while retaining raw source records for replay and provenance.
Evaluate product identity and version applicability as separate checks, preserving human-readable evidence.
Move findings from open to investigated, remediated, accepted, or resolved with ownership and context.
Apply organization and contact thresholds before generating in-app and email delivery records.
Create point-in-time reports and retain an audit trail of meaningful changes across the workspace.
VulnTrust keeps vulnerability identity, applicability, severity, finding status, and alert delivery deterministic and source-evidenced. Future AI-assisted explanations operate only on tenant-scoped, existing findings.
Every customer-owned query resolves through an active organization membership. Selecting an organization in the interface never replaces server-side authorization.
Source leases, immutable alert events, idempotency keys, task retry controls, and retained raw records support safe recovery from partial failures.
Findings preserve the inventory item, vulnerability, affected rule, confidence, evidence, timestamps, and analyst-controlled resolution.
Bring a sample of your technology inventory. We’ll show how VulnTrust identifies, prioritizes, and explains the findings that deserve attention.