An autonomous AI-driven agent that consolidates fragmented vulnerability data from multiple enterprise scanners into a unified, trustworthy service with full traceability and confidence scoring.
Same inputs always produce the same outputs. Every decision is traced, every merge is scored, every anomaly is flagged.
Read CSV feeds from Qualys, Tenable, and CMDB asset sources
Map source fields to unified schema with derived criticality scores
Group duplicates by FQDN + CVE match keys across all scanners
Apply deterministic rules with confidence scoring and conflict resolution
Top 10 vulns per business unit, risk-ranked with alert thresholds
Production-grade vulnerability consolidation with explainability at its core.
Unifies Qualys and Tenable vulnerability data with CMDB asset enrichment into a single source of truth.
Every merged record gets a 0-1 confidence score based on source agreement, FQDN match, IP match, and data completeness.
Every merge decision is logged: chosen values, alternatives, reasoning, and confidence breakdown. Full traceability.
Tracks missing fields, empty rows, low-confidence merges, and asset-vuln mismatches. Reports DQ metrics via API.
Configurable critical and high vulnerability thresholds per business unit. API endpoint identifies BUs needing escalation.
All business logic externalized in manifest.yaml: field mappings, merge policies, derivation rules, and confidence weights.
Six endpoints exposing consolidated vulnerability data, summaries, alerts, and quality metrics.