Automate the security work
that used to take weeks.
VulnPilot turns raw scanner output into prioritized findings, SLA-tracked evidence, and CI gates — without requiring a dedicated vuln management platform.
Everything a vulnerability program needs.
Composite risk scoring
KEV + EPSS + CVSS + Severity weighted into a single score. Known exploited vulnerabilities always score ≥ 75. Deterministic and auditable.
CI/CD gate integration
vulnpilot analyze --fail-on-breach exits non-zero when unexcused SLA breaches exist. Works in GitHub Actions, GitLab CI, Jenkins, and any CI system.
SLA compliance tracking
Configurable deadlines per severity level. Every finding is classified: within SLA, approaching, or breached — with full exception handling.
Audit evidence generation
One command generates an evidence pack mapped to SOC 2 CC7.1 or ISO 27001 A.8.8. Your scan history becomes your audit trail automatically.
Remediation verification
vulnpilot verify diffs a new scan against history — classifying each finding as fixed, still open, or newly introduced. Scan-scope guard prevents false positives.
Local scan history
Every analysis recorded to ~/.vulnpilot/history.db. Never transmitted. SOC 2 Type II requires 6–12 months of evidence — VulnPilot builds it from day one.