Deterministic-first · AI-advisory · isolated by construction

A security verdict is only worth acting on if you can trust how it was reached.

Our Vulnerability Advisor tells you which CVEs actually affect your software. Every one of those matches is computed by deterministic code — vendor-aware version logic, not a language model's guess. The AI writes the advisory and prioritises the noise; it can never add a vulnerability that isn't there, or hide one that is. That boundary is the whole product.

✔ Matches computed, never guessed by an LLM ✔ The AI advises · it can't invent or hide a CVE ✔ Your tenant data isolated by construction

A scanner that guesses wastes your week on false alarms. We compute the answer, then let the AI explain it. — Proven, not guessed.

The questions that decide whether you trust the output

Four fair questions to ask any AI-powered security tool.

We answer ours up front — because a verdict you can't trust is worse than no verdict at all.

CAN I TRUST THE MATCHES?They're computed, not guessed.

Whether a CVE affects your version is decided by deterministic, vendor-aware version logic — the same result every time, reproducible and explainable. No probability, no hallucination in the answer that matters.

CAN THE AI MAKE THINGS UP?Not in the verdict.

The language model advises — it summarises impact and prioritises what to fix first. It cannot add, remove, or override a single match. Every claim it makes is checked back against a real, computed CVE before you ever see it.

IS MY DATA SEEN BY OTHER TENANTS?No — by construction.

Every query is scoped to your organisation on the server, not in the browser. We actively tried to reach across that boundary during our own security audit and could not. Isolation is enforced in code, not promised in a policy.

HOW DO YOU STOP QUALITY REGRESSING?Nothing ships past the gates.

Every change runs a regression suite and a benchmark against the authoritative CVE oracle, and every merge is blocked unless secret-scanning, dependency-auditing, and a real runtime build all pass. Green isn't a vibe — it's a gate.

Under the hood · for your security team

The AI never decides whether you're vulnerable.

The same principle that runs through everything we build — AI proposes, deterministic code decides, a human acts — is what makes a vulnerability verdict something you can put in front of an auditor.

MATCH

Deterministic matcher

Vendor-aware version parsing and CPE logic decide reachability against the full CVE corpus — not naïve string matching, and never a model's opinion.

BOUNDARY

AI on a leash

The advisory model can explain and rank, but is fenced from the decision. Its output is sanitised: any risk it cites without a valid, computed CVE behind it is dropped before display.

ISOLATION

Tenant separation

Server-side org scoping on every path, verified sound in an adversarial audit. Your inventory, your findings, your data — never visible to another customer.

FRESHNESS

Nightly corpus sync

The CVE corpus is refreshed on a schedule with gap-recovery, so a vulnerability disclosed today is matched against your software tomorrow — not next quarter.

How we ship

Gated, audited, and re-checked on every change.

A security company that ships carelessly is a contradiction. Here's the discipline behind every release.

Secret-scanning blocks the merge — a credential that reaches the codebase fails the build, not a review
Dependency auditing blocks the merge — a newly-disclosed vulnerability in what we depend on stops the release
The real runtime is built and imported — we don't trust a green test suite alone; "it resolves" and "it runs" are different claims, and we check both
Regression + benchmark against the CVE oracle — accuracy is measured every time, so a fix can't quietly break a match
365k+
CVEs indexed — the full public corpus, refreshed nightly
0
LLM calls in the match decision
100%
of matches computed deterministically
every
merge gated on secrets, deps & a real build
We are explicit about what's computed versus advised. The list of CVEs that affect you is deterministic and reproducible. The narrative around them — severity in your context, what to fix first — is AI-generated guidance, and we label it as such. We never dress advice up as a guarantee, and we never let the guidance overrule the math. In a security business, that line is the trust.
Who builds it

Eduard Dulharu

Founder & CTO

Twenty years in network and security architecture, six of them in NATO environments. The Vulnerability Advisor is built on one conviction: in security, an answer you can't trust is worse than no answer. So the part that decides whether you're exposed is deterministic and auditable, and the AI stays where it belongs — explaining, never deciding.

20+ years networking & security6 years NATO environments deterministic by design
See it on your own software

Point it at your stack. Judge the answers yourself.

The scanner is free to try. Bring a product and version you already know the answer for, and check ours against it — that's the fastest way to trust a security tool.