VulnTrek operationalises the CTEM lifecycle across the security tools you already run—connecting scope, findings, asset identity, threat context, ownership, policy, remediation and evidence in one governed decision loop.
Last reviewed:
Define the business services, assets, boundaries and outcomes that matter before measuring exposure. Business context, asset criticality and accountable ownership establish the decision boundary.
Unify findings from connected scanners, cloud, code, infrastructure, VDP and OT sources. Source provenance stays attached while records normalise into one tenant-scoped finding model.
Combine severity with exploit intelligence, exposure, reachability, asset context and policy. Every priority remains decomposable into its evidence and recorded model version.
Test whether the exposure is reachable, relevant and affected by compensating controls. Validation refines the decision; a missed re-probe never silently closes the finding.
Route approved treatment to the right owner, workflow and SLA, then verify closure. Material actions stay under human authority and leave an append-only evidence trail.
Vendor-neutral intake and reversible deduplication turn overlapping source findings into an accountable working record without discarding provenance.
Ownership, threat context, policy, compensating controls and score factors remain visible instead of collapsing into an unexplained severity number.
Security, IT, engineering, cloud and OT teams coordinate through governed workflows, defined authority and recorded approvals.
Pramana retains the append-only history of decisions, exceptions, remediation and verification for exposures managed in VulnTrek.
VulnTrek is not a vulnerability scanner and does not replace the tools that discover findings. It governs their output, coordinates human-approved treatment and records the evidence. It does not autonomously patch systems, self-approve actions, mutate firewall or IAM configuration, commit code, or operate as an inline LLM gateway.
Continuous Threat Exposure Management, or CTEM, is an operating model for repeatedly scoping, discovering, prioritizing, validating and mobilizing treatment of exposures. It is a program, not a single scanner or one-time assessment.
No. VulnTrek consumes and governs findings from the security tools an organisation already runs. Those tools discover the findings; VulnTrek normalises, correlates, prioritizes, routes and records their treatment.
VulnTrek connects business scope and asset identity to vendor-neutral finding intake, evidence-led prioritization, reachability and control validation, then human-approved remediation workflows and closure evidence.
No. VulnTrek can prepare recommendations and perform bounded actions through approved workflows, but material remediation and other high-impact actions remain subject to human authority, policy controls and recorded evidence.
The platform keeps source provenance, score rationale, ownership, approvals, exceptions, treatment activity and closure evidence in an append-only history. Compliance mappings present that evidence without changing severity, SLA, status, totals or audit history.