Secure AI Agent · Vulnerability Management
AI applied to
prioritizing what to fix
A specialist configured to turn scanner exports into a prioritized remediation queue, track the SLA, and maintain the risk register within your company's rules.
Companies that trust UPX
Capabilities
What the Vulnerability Management Agent
can do
Main areas of work for the Vulnerability Management AI Agent in your operation.
Export parsing
Interprets the reports from the scanners your company already runs.
Risk-based prioritization
Orders findings considering EPSS, CISA KEV, and asset criticality.
Deduplication
Groups repeated findings across scanners to cut noise from the queue.
SLA tracking
Monitors remediation deadlines and flags what is close to expiring.
Accepted risk register
Keeps a record of what was accepted, by whom, and until when.
Remediation tickets
Turns prioritized findings into tickets with context for the responsible team.
Skills
Capabilities that compose the specialist
Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.
- Finding prioritization
- Orders vulnerabilities by real risk, not just nominal severity.
- SLA tracking
- Monitors remediation deadlines and flags what needs attention.
- Risk register
- Documents acceptances, owners, and reassessment dates.
From export to prioritized queue,
with review at every step
Connect your scanners, define what the agent can do, and let prioritization and tracking happen within your company's limits.
- Connect scanners and inventory
- The agent works with what you already run.Connect your scanning tools, the asset inventory, and the ticket tracker so the Secure AI Agent has access only to what it needs to prioritize.
- Ask for the work
- Talk to the agent in natural language.Request the cycle prioritization, the SLA status, or a review of accepted risks through the available channels. The agent understands the context, applies the configured skills, and follows the criteria your company defines.
- The agent prepares. The team fixes.
- From finding to remediation, with control.The agent queries, prioritizes, and opens tickets within the defined permissions. Remediation, change windows, and risk acceptance stay with the responsible teams.
01
02
03
Integrations
Connected to the scanners your company already uses
The Vulnerability Management AI Agent can query your scan reports and run tasks in the systems your team already uses.
Snyk Wiz Semgrep Checkmarx Veracode
Flow
What goes in,
what the agent does, and what comes out
From the raw export to a prioritized queue, following your company's rules and permissions.
Inputs
- Scanner exportCSV
- Asset inventoryList
- SLA policyDOC
Processing
Secure AI Agent
Processing the task
- Read
- Group
- Prioritizerunning
- Prepare
Output
Completed
Queue prepared
- Findings prioritized by risk
- Duplicates grouped
- Tickets ready for review
Control
You define how far the Agent can act
Different actions can operate with different autonomy levels, always within your company's rules.
- 1
Query
Reads exports and inventory and answers with the reference.
- 2
Prepare
Prioritizes findings and organizes the remediation queue.
- 3
Request review
Waits for validation from the system owner.
- 4
Execute
Performs the action within the defined limits.
Levels are configured per type of action, according to each company's policy. Applying fixes and accepting risk always stay under human approval.
Get started
Put a Secure AI Agent to work.
Start on the platform or choose the plan that fits the pace of your operation.
Security that can be verified.
Certifications and attestations
UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.
Privacy and regulation
- LGPD
- Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
- Zero Data Retention
- A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
- Retention and deletion
- The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.
Frequently asked questions
Common questions about the Vulnerability Management Agent
What teams usually ask before putting an agent to support the remediation cycle.
Does the agent run the scan?
No. It works on the exports from the scanning tools your company already uses. Running the scanner stays with the tools and teams that already maintain it.Does it apply the fix on its own?
Not by default. The agent prioritizes, opens the ticket, and tracks the deadline. Applying a patch, changing configuration, or opening a change window stays under approval from the system owner.How does it decide what is most urgent?
Prioritization considers exploitation probability (EPSS), presence in the CISA KEV catalog, and asset criticality in your inventory. The weights can be adjusted to your company's policy.Can it accept a risk on our behalf?
No. The agent maintains the accepted risk register, with owner and reassessment date, but the acceptance itself is always a recorded decision by an authorized person.Are our reports used to train models?
No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.Can we audit what the agent did?
Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.How long does it take to go live?
It depends on the scanners involved and your company's SLA policy. The starting point is connecting one scanner and the inventory, then expanding the scope as results come in.
Secure AI Agent
Bring a Secure AI Agent to your vulnerability management
Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.















