VulnTrek Platform Architecture

VulnTrek is a vendor-neutral exposure-management platform that helps teams turn connected vulnerability and security signals into explainable priorities, governed remediation, and traceable evidence.

Last reviewed:

What VulnTrek is

VulnTrek brings findings from connected security sources into a common operational workflow. It helps teams normalize available source data, enrich findings with risk context, prioritize exposure, govern remediation decisions, and preserve evidence from finding through closure.

VulnTrek is designed to complement—not replace—existing scanners, endpoint tools, cloud-security platforms, service-management workflows, and security operations processes. Those systems continue to perform their established discovery and operational roles while VulnTrek connects the available findings, decisions, ownership, and evidence.

Canonical data model

Where connected source data supports it, VulnTrek normalizes findings into a canonical data model while retaining source evidence. This enables cross-source correlation, more consistent prioritisation, ownership workflows, and traceable remediation decisions.

The canonical record provides a shared operational shape for the context available from different sources. Source lineage remains available so analysts and reviewers can inspect the basis of a correlation or decision rather than treating normalization as a loss of evidence.

Eight-step governed exposure-to-remediation workflow

AEDE is VulnTrek’s governed exposure-to-remediation loop. It helps teams move from prioritised risk to scoped remediation campaigns, read-only planning, approval routing, controlled execution, and recorded outcomes.

Consequential actions remain policy-bound and approval-aware. Teams retain control over scope, target systems, execution, exceptions, and closure.

AI recommends. Policy governs. Humans approve. Evidence remains.

  1. Connect security signals

  2. Normalize and correlate available findings

  3. Enrich findings with threat, exposure, asset, ownership, and workflow context

  4. Explain and prioritise risk

  5. Prepare a scoped remediation plan

  6. Apply policy checks and required human approval

  7. Coordinate a permitted action through a configured system

  8. Record outcome, refusal, exception, undo, or closure evidence

Threat intelligence and risk prioritisation

VulnTrek can incorporate available severity, exploit, exposure, asset, ownership, SLA, and business context into explainable priority decisions. These inputs help teams distinguish technical severity from the operational and organisational context that affects what should be addressed first.

External sources provide specific inputs, not endorsements of VulnTrek. Known exploitation, exploitation probability, and severity context can be reviewed together with exposure and business context; no single signal is presented as a complete measure of business risk.

Netra AI decision layer

Netra is VulnTrek’s AI-assisted decision layer. It analyzes available vulnerability, exploit, exposure, asset, ownership, and workflow context; explains why a risk matters; proposes disposition options; and prepares context-aware remediation playbooks.

Netra provides recommendations within governed workflows. It does not make production changes, close findings, or mutate risk state without the required policy controls and human authorisation.

Pramana evidence and governance

Pramana preserves append-only, traceable evidence and audit records for relevant vulnerability, remediation, and governance events. It helps teams review why a decision was made, what was approved, what occurred, and what evidence supports closure.

Pramana supports review and evidence preparation; it does not provide legal advice, certification, attestation, or determine audit or regulatory acceptance.

Compliance mapping as evidence support

VulnTrek helps teams view relevant findings and remediation evidence through configured regional, framework, and sector mapping views. It explains why a mapping is shown and preserves the underlying risk facts consistently across views.

Configured examples may include NIS2, DORA, ISO 27001, CERT-In Directions, the DPDP Act, and an optional RBI CSCRF sector overlay for eligible Indian financial-sector organisations. CERT-In timing is treated as incident-reporting context where applicable, not as a generic vulnerability-remediation deadline.

Framework mappings are presentation-only evidence support. They do not change finding severity, SLA, status, totals, or audit history.

Compliance mappings are provided as an informational aid and are not legal advice, an attestation, or a certification determination.

IT and OT/ICS exposure context

VulnTrek supports IT and OT/ICS exposure workflows that can incorporate advisory, asset, maintenance-window, and operational-context considerations. This helps teams review exposure with an awareness that remediation in operational environments may require additional planning and human review.

The workflow does not imply automated OT remediation or complete coverage of industrial protocols, vendors, asset types, or environments. It provides a governed place to consider the available operational context alongside vulnerability and advisory information.

MCP-enabled tool access

Where enabled, VulnTrek supports governed, tenant-scoped MCP access for approved AI-assisted analysis and tool workflows.

MCP access remains bounded by the user’s permissions and the approved tool surface. It is not presented as a general CI/CD integration layer or as universal compatibility with all AI tools, agents, developer environments, or external MCP servers.

Designed to complement the security stack you already use

VulnTrek is designed to unify available findings and context from connected sources, help teams explain why remediation work matters, govern the path from decision to action, and retain evidence of what happened. It complements existing scanners and operational systems by connecting exposure prioritisation with accountable workflows and traceable closure.

This approach keeps discovery, endpoint, cloud-security, service-management, security-operations, governance, legal, and audit responsibilities with the systems and people responsible for them. VulnTrek provides a connected decision and evidence layer rather than claiming to replace the complete security stack.

Review the architecture with your operating model in mind

Walk through how connected findings, prioritisation inputs, approval boundaries, and evidence paths can fit your existing security operations.

Request a guided architecture walkthrough