Every finding tracked to closure — or to a decision.
Scanners produce findings. Governance is what happens next — and in most organizations what happens next is a weekly export, a prioritization debate, and a growing backlog nobody is accountable for closing.
NIS2 treats vulnerability handling as part of secure acquisition, development and maintenance — a standing obligation, not a project. TruSecure reads scanner and patch-management state through connectors and governs the lifecycle: an SLA per severity, exceptions that expire, closure evidence captured as it happens.
How it works
- Read
Connectors ingest findings and patch posture from your scanners and endpoint tooling, reconciled against the asset picture so the same finding is not counted three times.
- Govern
Each severity class carries a remediation SLA. Overdue items surface as gaps against the control — visible in the same model the frameworks read — not as rows in a report.
- Except — with an expiry
Deferring a fix is a formal risk acceptance: a named approver, a written rationale, a defined expiry date. No expiry, no exception.
- Prove
Closure and exception history accumulate as evidence. The vulnerability-management record an auditor asks for is built as a by-product of operating, not assembled under pressure.
What vulnerability posture looks like
- Critical open
- 3 · all inside 14-day SLA
- High open
- 27 · 2 nearing SLA
- Active exceptions
- 4 · none expired
- Citations
- NIS2 21(2)(e) · ISO A.8.8
- Source
- scanner connector · 1 h ago
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Vulnerability handling and disclosure in acquisition, development and maintenance | Art. 21(2)(e) |
| ISO 27001 | Technical vulnerabilities identified, evaluated and remediated | A.8.8 |
| CIS v8 | Continuous vulnerability management process, operating | Control 7 |
The vulnerability-management connectors read findings directly from your scanner, and the endpoint and MDM connectors confirm patch state — TruSecure governs the tools you already run instead of adding another scanner.
The number that matters is not how many findings you have — it is how many are outside their window without a signed reason. That number is now always current, always attributable, and always one click from the evidence behind it. AI chases the routine closures; your team makes the judgment calls on what to fix first.
The monitoring loop
continuous · every 6 hours- 01
01
Connect
Read-only connectors into AWS, Azure, GCP, on-premise.
AWSAzureGCPon-prem - 02
02
Collect
AI pulls compliance evidence every 6 hours — not at audit time.
every 6 h - 03
03
Detect
Gaps and control drift flagged the moment they appear.
24/7 - 04
04
Remediate
Routine fixes closed automatically; the rest routed to you.
auto - 05
05
Approve
A named person decides. The approval is the record.
logged
The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.