Evidence chain (VM) by SPNORTH

Planned, not yet available: From finding to retest: a logged vulnerability workflow with owner, SLA and traceable records.

Status: planned

This product is planned and is not currently available as software.

Starting point

Without an evidence chain nobody can prove a vulnerability was triaged, prioritized and fixed.

Who it is for

Security operations, engineering leads, audit responsibles.

Capabilities (planned)

  • Finding register with CVSS context
  • Owner and SLA assignment
  • Remediation workflow with status history
  • Retest log per finding
  • Audit export of the evidence chain

Limitations

  • Planned: currently not available, not for sale, no commitment on scope or date
  • No automated remediation without approval

Human boundary

Named people at the customer assess findings and approve remediation; the register logs but does not decide.