Security tools discover findings. VulnTrek decides what matters.

Unify security signals across your tool universe, prioritize what matters, mobilize the right owners, validate outcomes, and maintain evidence for continuous security assurance.

Last reviewed:

VulnTrek is a Unified Exposure Management & Security Assurance Platform that connects findings, risks, controls, compliance obligations, and remediation work across your security-tool ecosystem. The unified control plane for exposure, remediation, and audit-ready security assurance.

Unified Exposure Management & Security Assurance Platform

Category coverage: VulnTrek is vulnerability management and exposure management software for evidence-led, human-approved security remediation. Core categories: vulnerability management (RBVM), continuous threat exposure management (CTEM), attack surface management (ASM/EASM/CAASM). Defined partial coverage, with boundaries stated in full: application security posture management (ASPM). Complete ASPM decision coverage, without running the scanners — the scanning stays with the tools you already own. Partial coverage means selected use cases only. VulnTrek is not a scanner and does not replace application security, attack surface or configuration-management products; every boundary and out-of-scope area is documented on the category coverage page.

Read VulnTrek's full category coverage, boundaries and exclusions

What Unified Exposure Management Means

Turn fragmented security signals into governed, measurable security action. VulnTrek brings findings, assets, exposure context, ownership, control coverage, and remediation work from across the security-tool ecosystem into one accountable operating model. Vulnerability management is one input to VulnTrek—not the limit of what VulnTrek manages.

What Security Assurance Adds

Vendor-neutral orchestration, accountable action, and audit-ready evidence. Outcomes are validated, exceptions are recorded, control effectiveness is measured, and audit-ready evidence is preserved so exposure reduction can be demonstrated to security leaders, risk owners, and auditors.

Turn Security Findings Into Explainable Decisions

Netra is VulnTrek’s AI-assisted decision layer. It analyzes available vulnerability, exploit, exposure, asset, ownership, and workflow context; explains why a risk matters; proposes disposition options; and prepares context-aware remediation playbooks. Netra provides recommendations within governed workflows. It does not make production changes, close findings, or mutate risk state without the required policy controls and human authorisation.

Unify Vulnerability Findings Into One Accountable Workflow

Bring connected scanner, endpoint, cloud, advisory, and manual findings into one decision path with risk context, ownership, remediation workflow, and retained source evidence.

Operationalize Continuous Threat Exposure Management

Built to operationalize Continuous Threat Exposure Management across the enterprise security-tool ecosystem. VulnTrek supports the CTEM lifecycle as an operating model: scope what matters, discover exposure, prioritise risk, validate action, and mobilise accountable remediation.

Prioritise the Exposure That Matters Most

The VulnTrek Risk Index is an explainable prioritisation view that brings together available technical severity, exploit signals, exposure, asset context, ownership, SLA, and business context. It helps teams understand the factors behind a priority decision.

Govern Remediation With Human Authorisation

AEDE is VulnTrek’s governed exposure-to-remediation loop. It helps teams move from prioritised risk to scoped remediation campaigns, read-only planning, approval routing, controlled execution, and recorded outcomes. Consequential actions remain policy-bound and approval-aware. Teams retain control over scope, target systems, execution, exceptions, and closure. AI recommends. Policy governs. Humans approve. Evidence remains.

Validated deduplication benchmark

VulnTrek deduplicates findings across Nessus, Qualys, and Burp with 94% accuracy on a labeled set of 2,000 findings.

Coordinate Remediation With a Governed Agentic AI Workforce

VulnTrek coordinates remediation through purpose-scoped AI agents aligned to the AEDE loop. Agents assess evidence, develop recommendations, prepare allow-listed non-mutating workflows, and document outcomes. Every action that would create a change outside VulnTrek requires mandatory human approval, is recorded in an append-only action ledger, and remains governed by policy controls, execution tiers, kill-switch controls, and explicit refusal boundaries.

Designed not to autonomously patch systems, self-approve actions, mutate firewall or IAM policies, or operate as an inline LLM gateway.

Recognised guidance and intelligence sources

VulnTrek helps teams work with the guidance, standards and intelligence sources that already inform enterprise security programmes:

Frequently Asked Questions

How does the platform integrate with our existing security tools?

55+ native integrations out of the box — Jira, ServiceNow, Slack, Microsoft Teams, HackerOne, Bugcrowd, Tenable, Qualys, Rapid7, Wiz, CrowdStrike and every major scanner. Integration depth is bi-directional: findings, status, comments, owners, SLA timers and remediation evidence sync both ways, with field-level mapping, custom JQL/queues, and conflict resolution rules per project. A versioned REST API (250 req/min, OpenAPI 3.1), HMAC-signed webhooks and a Terraform provider cover everything else. Median time-to-first-integration is under 48 hours; SSO (SAML/OIDC) and SCIM provisioning ship on day one.

What's the typical ROI timeline?

Measurable ROI inside 30 days. Customers cut triage time from ~6 hours to under 8 minutes per finding (98% reduction), shrink mean-time-to-remediate on critical issues from 90+ days to 14, and avoid an average of €38K/quarter in duplicate bug-bounty payouts. Typical full payback is 60–90 days; year-one ROI averages 4–7x on the Growth tier.

How long does implementation take?

Onboarding follows a fixed three-week path with a named implementation engineer. Day 1: connect your first scanner and KEV/NVD feeds (under 45 minutes) — prioritized findings appear the same afternoon. Week 1: Jira/ServiceNow bi-directional sync, Slack/Teams alerts, SSO (SAML/OIDC), SCIM and asset-criticality mapping. Weeks 2–3: SLA policies, executive dashboards, custom risk formulas and your first scheduled board report. 95% of customers go from kickoff to production in 14 days and to full org-wide rollout in 30; onboarding is included at no extra cost on every tier.

How is VulnTrek priced?

Three tiers, billed annually in EUR, priced on deduped assets and write seats. Starter starts at €490 / month (5 seats, up to 500 assets, 5 connected sources). Growth starts at €1,900 / month (10 seats, 501–5,000 assets, 15 sources, custom ownership and CTEM preview). Enterprise uses asset-based pricing for 5,000+ assets with unlimited seats and sources, full CTEM and hackability scoring, and a named CSM. Viewer seats are always free. Seat add-ons €40/seat/month, source add-ons €25/source/month.

Where is my data stored and processed?

All customer data is stored and processed in the European Union — primary region Frankfurt (eu-central-1) with hot standby in Dublin (eu-west-1). Single-tenant logical isolation per organization, encryption keys held per customer in AWS KMS, and no data transfer outside the EU without an explicit, written, per-tenant opt-in. We are GDPR-aligned and mapped to BSI C5 and NIS2 controls; full residency and sub-processor list is published in the Trust Center.

What is the status of your SOC 2 and ISO 27001 certifications?

SOC 2 Type II — observation window opened Q1 2026, report expected Q3 2026 (audited by a Big-4 firm). ISO 27001 — gap assessment complete, Stage 1 audit scheduled Q4 2026, certification targeted H1 2027. First independent penetration test completed Q2 2026 (CREST-accredited tester); annual cadence going forward. Our current SOC 2 Type I letter, NIS2 / BSI C5 control mapping, and pen-test executive summary are available under NDA via the Trust Center.

How does AI-powered duplicate detection work?

Every incoming finding is converted into a multi-signal embedding — CVE/CWE identifiers, affected component and version, endpoint or file path, request/response fingerprints, screenshot hashes and reporter prose — then compared against the open and historical backlog. A Lovable AI Gateway model scores semantic similarity, and a deterministic rules layer breaks ties on CVE + asset + scanner. Suspected duplicates are auto-linked with a confidence score and a side-by-side diff; triage owners approve or reject in one click. Precision sits at ~95% on our design-partner corpus, and every decision is logged for audit.

Is my vulnerability data secure?

Absolutely. We're SOC 2 Type II certified with end-to-end encryption, role-based access controls, and complete audit logging. Your data never leaves your control—we offer both cloud and on-premise deployment options. All data is encrypted at rest and in transit.

How does CISA KEV compliance automation work?

The platform automatically monitors the CISA Known Exploited Vulnerabilities catalog daily. When a new KEV is added that matches your asset inventory, we immediately create prioritized tickets, notify relevant teams, and track remediation against federal deadlines—all automatically.

Can we customize risk scoring for our business context?

Yes. While we provide CVSS, EPSS, and industry-standard scoring out of the box, you can create custom risk formulas that factor in your crown jewel assets, business criticality, data sensitivity, and regulatory requirements. This ensures vulnerabilities are prioritized based on actual business impact.

What kind of support do you offer?

Tiered SLAs with response times measured 24×7 from the moment a ticket is opened in the in-app help center or via email. Starter: P1 4h / P2 1 business day / P3 2 business days, email + chat. Growth: P1 1h / P2 4h / P3 1 business day, plus a shared Slack/Teams channel and a named technical contact. Enterprise: P1 15 min / P2 1h / P3 4h, a dedicated Customer Success Manager, quarterly business reviews, and a 99.9% platform uptime SLA with service credits. All tiers get documentation, video tutorials and the community forum.

Does VulnTrek use agentic AI?

Yes. VulnTrek uses a governed, purpose-scoped AI agent workforce to support evidence-led remediation workflows. Agents operate within defined execution tiers and allow-listed actions. Human approval is required for every change leaving the platform, and VulnTrek does not autonomously patch systems, self-approve remediation, mutate firewall or IAM configurations, or function as an inline LLM gateway.