For DevSecOps

Automate the security work
that used to take weeks.

VulnPilot turns raw scanner output into prioritized findings, SLA-tracked evidence, and CI gates — without requiring a dedicated vuln management platform.

Capabilities

Everything a vulnerability program needs.

Composite risk scoring

KEV + EPSS + CVSS + Severity weighted into a single score. Known exploited vulnerabilities always score ≥ 75. Deterministic and auditable.

CI/CD gate integration

vulnpilot analyze --fail-on-breach exits non-zero when unexcused SLA breaches exist. Works in GitHub Actions, GitLab CI, Jenkins, and any CI system.

SLA compliance tracking

Configurable deadlines per severity level. Every finding is classified: within SLA, approaching, or breached — with full exception handling.

Audit evidence generation

One command generates an evidence pack mapped to SOC 2 CC7.1 or ISO 27001 A.8.8. Your scan history becomes your audit trail automatically.

Remediation verification

vulnpilot verify diffs a new scan against history — classifying each finding as fixed, still open, or newly introduced. Scan-scope guard prevents false positives.

Local scan history

Every analysis recorded to ~/.vulnpilot/history.db. Never transmitted. SOC 2 Type II requires 6–12 months of evidence — VulnPilot builds it from day one.