Unified Exposure Management and Security Assurance
VulnTrek gives security teams a unified control plane for understanding, prioritizing, governing, and reducing enterprise exposure.
Instead of treating vulnerabilities, cloud findings, application-security issues, control gaps, audit evidence, risk exceptions, and remediation tickets as separate operational silos, VulnTrek connects them into one accountable security operating model.
VulnTrek combines vulnerability intelligence, exposure prioritisation, security orchestration, audit-ready evidence, and a governed agentic AI workforce for human-approved remediation operations.
VulnTrek is a Unified Exposure Management & Security Assurance Platform that connects findings, risks, controls, compliance obligations, and remediation work across your security-tool ecosystem. The unified control plane for exposure, remediation, and audit-ready security assurance.
Vulnerability management is one input to VulnTrek—not the limit of what VulnTrek manages.
Last reviewed:
What VulnTrek is — and what it is not
VulnTrek is not another vulnerability scanner or a passive security dashboard. It is a vendor-neutral Unified Exposure Management and Security Assurance Platform.
VulnTrek connects fragmented security signals across vulnerability management, cloud and application security, external attack-surface intelligence, penetration testing, red-team activity, bug bounty programs, SIEM, EDR, identity, GRC, and service-management workflows.
It helps teams understand which exposures matter, connect them to business and control context, assign accountable owners, orchestrate action, validate outcomes, manage exceptions, and maintain audit-ready evidence.
The result is a continuous, measurable path from security finding to defensible risk reduction.
We publish the delta candidly: VulnTrek decides, orchestrates, enforces and evidences — it is not itself a scanner, so SAST, DAST, SCA and infrastructure testing stay with your existing tools.
The four platform pillars
Unified exposure intelligence, risk and control context, governed action orchestration, and continuous assurance and evidence — the operating model the capability inventory below implements.
Unified Exposure Intelligence
Bring together findings, assets, attack-surface context, threat intelligence, business criticality, control coverage, and ownership from across the security-tool ecosystem.
Vulnerability scanners
Cloud security and cloud posture tools
Application security tools
External attack-surface management
SIEM and EDR
Identity and access signals
Penetration tests and red-team exercises
Bug bounty findings
OT and industrial-security sources
Threat and vulnerability intelligence feeds
Risk and Control Context
Connect technical exposure to the business services, system owners, risk registers, policies, controls, exceptions, compliance obligations, and materiality that determine what must happen next.
Business criticality
Asset and service ownership
Exploitability and exposure context
Risk acceptance
Compensating controls
Control requirements
Compliance obligations
Remediation SLAs
Evidence requirements
Audit trails
Governed Action Orchestration
Turn prioritized exposure into accountable work through routing, playbooks, ticket orchestration, deadlines, escalations, approvals, exception workflows, and remediation tracking.
One actionable remediation queue
Clear ownership
SLA accountability
Workflow automation
Ticket and service-management integration
Risk-acceptance workflows
Escalation paths
Human-led decision support
Closed-loop collaboration between security and technology teams
Continuous Assurance and Evidence
Validate outcomes, preserve proof, measure control effectiveness, maintain audit trails, and demonstrate measurable exposure reduction to security leaders, risk owners, and auditors.
Remediation validation
Evidence collection
Control-assurance reporting
Audit readiness
Exception history
Risk reduction trends
Leadership reporting
Governance metrics
Defensible security decisions
Comprehensive capability inventory
Every item below denotes shipped, verifiable platform behaviour — no roadmap language, no aspirational claims. Each domain is an anchored, citable section of the platform's end-to-end exposure management and vulnerability orchestration capability.
Exceptionally deep integration across large, complex IT & OT infrastructure — every source is normalised onto one canonical finding schema before a single triage or orchestration decision is taken.
Breadth absent adjudication is ingestion theatre: hundreds of pass-through connectors merely multiply an unqualified queue instead of distilling it into defensible, owner-assigned, orchestrated work.
Attack Surface Management (ASM)
Comprehensive, continuous and authoritative enumeration of the attack surface across large, heterogeneous IT, cloud, code, OT and third-party estates.
Vendor-neutral ingestion & orchestration
Fifty-five deeply engineered native connectors converging on one canonical finding schema — the foundation of vendor-neutral vulnerability orchestration across heterogeneous toolchains.
Correlation & deduplication
Vendor-neutral semantic correlation collapses redundant findings, with defensible evidence retained for every merge and eligibility-controlled admin reversal.
Exploitability-informed prioritisation
Prioritisation informed by public exploit intelligence (CISA KEV, EPSS) and recorded reachability. These signals show exploitation in general; exploitability in your environment needs separate validation evidence.
VulnTrek Risk Index (VRI)
A single 0–100 index fusing rigorous technical risk-graph modelling with quantified financial exposure in EUR.
Backlog reduction (valid-backlog funnel)
An unqualified backlog is an unmanaged liability, not a workload — threat-informed prioritization distils vast raw volume into the demonstrably real and actionable.
End-to-end remediation
Actionable, automated and auditable remediation orchestration from adjudicated finding to evidence-backed closure, with re-checks where re-scan or validation results are available.
Purpose-scoped agentic AI that accelerates remediation inside an enforced governance envelope — autonomous where it is safe, provably accountable everywhere else.
Developer & AI access layer (MCP + deployment gate)
The platform is embedded in the developer's own workflow: connect a supported MCP-compatible AI client via OAuth and query exposure decisions in natural language, and let CI enforce the same policy at deployment time.
Netra — AI decision engine
Explainable, deterministic triage executed under unambiguous human authority.
OT / ICS coverage
Safety-first, process-aware risk adjudication engineered for critical national and industrial infrastructure.
Analytics & executive reporting
Board-grade, defensible metrics derived from the identical evidence base that drives operational triage.
VDP & researcher intake
Operate a credible, policy-governed coordinated disclosure programme without a discrete second platform.
Kavach — platform security & tenancy
Rigorous multi-tenant isolation enforced at the data layer by design, never merely at the presentation layer.
Executive Crisis Game (NATO-style exercises)
A NATO-style executive crisis game that turns the tenant's own live exposure into cross-functional decision drills — collaboration rehearsal, not generic tabletop content.
Pramana Ledger — evidence & compliance output
Immutable, audit-defensible assurance evidence — the terminal stage of the decision loop, never the substitute for it.
Depth, not connector count
Breadth of ingestion without adjudication merely inflates an unqualified backlog. Every source is normalised onto one canonical schema and arbitrated by one decision engine — the discriminating factor is depth of integration across large, complex IT and OT estates, not a superficial connector count.
16 shipped domains, each with its own section in the capability inventory.
Built on Recognized Guidance and Intelligence
VulnTrek helps teams operationalize risk-informed work using the guidance, standards, and intelligence sources that already inform enterprise cybersecurity programs.
Prioritize with context, not severity alone
VulnTrek helps teams combine technical findings with asset criticality, ownership, internet exposure, control context, remediation status, and threat-informed signals. Where organizations use sources such as the CISA Known Exploited Vulnerabilities Catalog and FIRST Exploit Prediction Scoring System (EPSS), those inputs can support a more defensible prioritization process.
NIST Cybersecurity Framework 2.0 — Common vocabulary for identifying, protecting, detecting, responding, and recovering, which many security programs already use to structure exposure work.
CISA Known Exploited Vulnerabilities Catalog — Published record of vulnerabilities with confirmed exploitation, widely used as an escalation signal in prioritization decisions.
Security tools discover findings. VulnTrek decides which exposure actually matters, why it matters, who owns it, what should happen next, and proves that the decision was carried through to closure. It does this by continuously discovering the digital, cloud, code and OT attack surface; ingesting vendor-specific findings and generic signed-webhook/API input into one canonical schema; applying vendor-neutral semantic deduplication with eligibility-checked admin undo; validating exploitability through CISA KEV, EPSS, NVD and graded reachability evidence; scoring business risk via the VulnTrek Risk Index (VRI); routing the valid backlog to accountable owners with SLA bands; driving remediation to verified closure through supported workflow connections; and recording append-only, audit-defensible evidence in the Risk Ledger.
Is VulnTrek a compliance or risk-ledger product?
No. The immutable Risk Ledger, auditor evidence room and compliance mapping are the terminal stage of a six-stage exposure-management loop — the output, not the offering. The platform's primary function is continuous, dynamic attack surface management and vendor-neutral vulnerability orchestration: deciding which vulnerabilities are genuinely exploitable and tracking their remediation to evidence-backed closure, with re-checks where re-scan or validation results are available.
How many integrations does VulnTrek have?
The connector registry contains 56 connectors in three separate groups, each counted once: 44 vendor-specific finding connectors (vulnerability scanners, cloud security, application and code security, EDR, SIEM, API security and bug bounty/VDP), 5 generic intake adapters (signed webhook, SIEM, EDR, EASM and cloud-posture formats) and 7 ticketing/workflow connections (Jira Cloud, Jira Data Center, Jira work management, Jira Service Management, ServiceNow, GitHub Issues and Azure DevOps). A versioned REST API covers other sources. Every connector is normalised onto the same canonical schema, then handled by the same semantic deduplication, exploitability-informed prioritisation, ownership inference and remediation deadline routing — depth of integration across large, complex IT and OT estates, not a larger count of forwarding-only integrations.
Does VulnTrek model technical risk or only financial impact?
Both, deterministically. Asset and dependency graph correlation, exploit intelligence, graded network reachability and internet exposure form the technical risk model; modelled annualised loss expectancy in EUR is derived from that same graded evidence, so the technical and financial layers can never diverge. This is the VulnTrek Risk Index (VRI).
Does the AI act on findings automatically?
No. Netra, the AI decision engine, proposes dispositions, scores and owners with a written, explainable rationale. Promotion of any finding to actioned or closed is gated on an explicit human decision, which keeps AI-assisted decisions auditable and defensible under ISO 27001, SOC 2 and similar assurance regimes.
Can developers use VulnTrek from their own AI tools?
Yes. VulnTrek operates a hosted Model Context Protocol (MCP) server: a developer or security analyst connects their AI client to VulnTrek once by OAuth, then asks in natural language — what is blocking my release, which KEV-listed CVEs affect this service, who owns this finding, what does the deployment gate say. Every tool call executes as that user under row-level security and is limited by that person's permissions, never another tenant's data. Most tools only read. The security gatekeeper records a CI verdict without changing findings. submit_findings adds scanner findings to the user's own organisation's intake, with a batch cap and rate limit. request_action only creates a pending proposal that a person with remediation approval rights decides inside VulnTrek; no MCP tool approves or executes an action.
Does VulnTrek enforce anything in CI/CD?
Yes. The security gate evaluates your policy — priority band, KEV listing, SLA breach, asset criticality — and returns pass, warn or fail with the deciding rule and triggering findings. Pipelines call it over REST or through the supplied CI client, which fails the job on a blocking verdict. Every evaluation is written to an append-only verdict ledger and mirrored into the hash-chained evidence chain, so blocked builds become ISO 27001 change-management and DORA Article 6 change-control proof automatically.
What are Netra Skills?
Netra Skills (previously labelled Platform Skills) are named, repeatable analyses run by the Netra AI decision engine over your own register and return a written recommendation: /triage for batched finding triage, /risk-brief for the weekly executive summary, /release-gate for a GO, REVIEW or BLOCKED verdict before a release, /sla-check for overdue and unowned work, /incident-report for a regulator-shaped narrative built from the lifecycle trail, and /audit-pack for an evidence index against ISO/IEC 27001 A.8.7 and A.8.8. Skills are advisory only — they recommend, a person decides, and the existing approval path records the decision. Runs can be scheduled or triggered by a completed scan, and every run is logged. An evidence index is not an attestation or a certification determination.
What does VulnTrek not do?
VulnTrek is not a scanner and not a code-security testing tool: it does not perform SAST, DAST, SCA or infrastructure scanning itself. It consumes that output from vendor and generic sources, decides what deserves engineering time, orchestrates the fix to verified closure, enforces the decision at deployment time through the security gate, and records the evidence.
Related platform capabilities
The technical detail behind these claims lives on the platform pillar pages.
What is VulnTrek? — The canonical definition — the category, the six AEDE stages, the named capabilities and the explicit non-goals.
Category coverage — ASM, CTEM, RBVM, ASPM, AI-SPM, SBOM/VEX, VDP, OT — what VulnTrek is core to, partial on, and stays out of.
Continuous Threat Exposure Management — How VulnTrek operationalises Scope, Discover, Prioritize, Validate and Mobilize across existing security tools.
Attack Surface Management — Continuous inventory across external, cloud, code, host, OT and researcher-reported surface.
Netra — the AI decision engine — The AI layer that deduplicates, grades with live exploit evidence and writes down its reasoning.
MCP server — AI access layer — Connect an AI tool once by OAuth, then query findings, CVE impact, campaigns and CI gate verdicts in natural language — read-only and tenant-scoped.
Governed agentic remediation — Purpose-scoped AI agents, playbooks and read-only code review under human approval and an immutable audit ledger.
Agentic AI workforce — The published roster — Netra plus eight named agents, each with its AEDE stage, default authority and whether it may call a model.
AI-native architecture — Why a platform built with AI ships and patches faster than one that bolted AI on — and the governance that makes it adoptable.
VulnTrek Risk Index (VRI) — Asset graph, threat intel, reachability, business context and financial quantification in one score.
CI/CD release gates — Deduplicated intake and KEV/EPSS prioritisation at the pipeline gate, without replacing existing scanners.