Governed Agentic Remediation

VulnTrek supports governed agentic remediation with purpose-scoped AI agents, allow-listed non-mutating workflows, mandatory human approval, explicit refusal boundaries, and an append-only action ledger. The links below point at the related VulnTrek pages — capabilities, integrations, security and contact.

When patching must wait, plan the mitigation

VulnTrek’s remediation playbooks pair the recommended permanent fix with a pre-patch mitigation path for when immediate patching is not possible. Based on the finding and the available asset context, a playbook may suggest a compensating control, such as restricting access to an affected service, alongside the patch or upgrade, the risk of leaving it unfixed, and steps for your team to verify the outcome. These are recommendations for review and implementation by your authorised operators, not automatically enforced changes. Path 1: the durable fix: The vendor patch or upgrade that resolves the finding, including the smallest concrete change where that is known. Path 2: pre-patch mitigation: A compensating-control recommendation for the time before the fix can be applied. Depending on the finding, it may cover access restriction, temporary blocking, isolation or segmentation. Illustrative example: for an exposed cPanel & WHM login, a playbook recommends upgrading to the vendor’s fixed version and, if that upgrade must wait, restricting access to the affected login page to trusted addresses. Your team decides whether to apply the restriction, makes the change in its own systems, and confirms it works.