The VulnTrust platform

One operating view from technology inventory to remediation.

Connect what you run to what is vulnerable, keep the evidence visible, and give every team a focused path from disclosure to decision.

A connected operating model

Keep context intact across the full vulnerability workflow.

Each stage creates structured evidence for the next, reducing manual handoffs and making decisions easier to explain.

01InventoryWhat you operate
02IntelligenceWhat has changed
03CorrelationWhat applies
04PrioritizationWhat matters
05ResponseWhat happens next
Core capabilities

Built for defensible decisions, not a larger alert queue.

Technology inventory

Register the products, packages, versions, environments, and criticality that define your monitoring scope.

  • Canonical product catalog
  • CPE and package URL identifiers
  • Version and environment context

Continuous intelligence

Collect vulnerability data on a schedule while retaining raw source records for replay and provenance.

  • NVD and OSV advisories
  • CISA Known Exploited Vulnerabilities
  • EPSS exploitation probability

Explainable correlation

Evaluate product identity and version applicability as separate checks, preserving human-readable evidence.

  • Affected version ranges
  • Confirmed and potential findings
  • Confidence and source evidence

Risk-focused workflow

Move findings from open to investigated, remediated, accepted, or resolved with ownership and context.

  • KEV and severity visibility
  • Assignment, due dates, and notes
  • False-positive and accepted-risk states

Controlled alerting

Apply organization and contact thresholds before generating in-app and email delivery records.

  • Severity thresholds
  • Potential-match controls
  • Idempotent alert delivery

Evidence and reporting

Create point-in-time reports and retain an audit trail of meaningful changes across the workspace.

  • PDF finding reports
  • Organization audit events
  • Source and workflow timestamps
Responsible assistance

AI can clarify. It does not get to invent exposure.

VulnTrust keeps vulnerability identity, applicability, severity, finding status, and alert delivery deterministic and source-evidenced. Future AI-assisted explanations operate only on tenant-scoped, existing findings.

  • No provider key exposed to the browser
  • No AI authority over match or severity
  • Generated content identified as assistance
AI provider boundary
Source recordsAuthoritative
Version applicabilityDeterministic
Analyst explanationAssistive
Workflow decisionHuman-controlled

Tenant-scoped by design

Every customer-owned query resolves through an active organization membership. Selecting an organization in the interface never replaces server-side authorization.

Recoverable by design

Source leases, immutable alert events, idempotency keys, task retry controls, and retained raw records support safe recovery from partial failures.

Explainable by design

Findings preserve the inventory item, vulnerability, affected rule, confidence, evidence, timestamps, and analyst-controlled resolution.

See VulnTrust on your stack

Turn your inventory into an actionable vulnerability program.

Bring a sample of your technology inventory. We’ll show how VulnTrust identifies, prioritizes, and explains the findings that deserve attention.