Offer · Operate Early access

Your scanners find it. Someone says it is fixed.
Only a scanner should say it is closed.

Fix Squad reads every scanner you run, puts the exposures attackers already use first, fixes them through the tool that owns each asset under a change your process authorised, and closes an exposure only when your next scan no longer sees it.

Six steps, every time

1

Collect

Every scanner you run is read, and a scanner that could not be read is reported — never counted as clean.

2

Rank

The same exposure found twice is one line. Exploited in the wild, internet-facing and business-critical go first, by published rules.

3

Plan

Fixes grouped into change-sized batches: one owning tool, one maintenance window, one ring at a time.

4

Fix

Through the automation that owns the asset, against an authorised change record checked right before launch.

5

Verify

A scan completed after the fix, covering the asset, no longer sees it. Nothing else closes it.

6

Prove

Each closure keeps its change, its job, its scans and its timing — ready for your auditors.

Closed means rescanned

A job that ends green says the job ran. It does not say the vulnerability is gone, and the agent that applied the fix is the last one who should vouch for it. So the verdict comes from scan evidence only, and a scanner that still sees the exposure outweighs one that does not.

Verified closed

Every scanner that reported it scanned the asset after the fix and no longer sees it.

Still open

A scan after the fix still sees it. Back to planning, with the evidence.

Regressed

It came back after being closed. Reopened, with an incident on the original change.

Unverified

No covering scan yet. It stays open, and a missing scan is chased.

What the agents may not do when they start

Never, at entry

  • Approve a change, or launch without one
  • Touch a business-critical server without a person approving that change
  • Run outside your maintenance windows or during a freeze
  • Widen a batch to finish a job
  • Accept a risk or grant an exception
  • Close an exposure because a job succeeded

Always

  • Only one agent can launch, and it checks the change record right before every launch
  • A failed batch stops the change; a failed fix is backed out only through its declared backout
  • A scanner that could not be read, or an asset nobody scans, is reported
  • Every ranking, verdict and launch leaves a record

Autonomy earned per class of fix

A class is one kind of fix, on one kind of asset, through one tool. Each climbs on its own verified record, and drops back on its first failure.

Test & workstations

Standard patches your change board pre-approved start with a person confirming each batch, and can run on their own once their verified record holds.

Production servers

The same path, one ring at a time, opened only when the ring before it is already trusted.

Business-critical

One server per change, each approved by a person, until that class earns a pre-approved path of its own.

Settings & cloud

Recommended first; applied by a person or by the team that owns the infrastructure code.

Nothing is autonomous by default, and nothing is capped forever: the verified record decides, and your change board signs off each promotion.

What is live, what early access adds

Live on the platform today

  • Read connectors to vulnerability scanners, asset inventories and your service-management tool
  • Execution through your automation, with approval gates and a person's decision recorded
  • Tamper-evident audit trail of every action
  • Autonomy earned on measured results
  • Installation on your premises

Built with early-access customers

  • Cross-scanner merging and ranking, and scan-verified closure
  • Fixes through endpoint management platforms
  • Rescans launched on demand (today verification waits for your next scheduled scan)
  • Pre-approved fix classes and their promotion rules

Priced per managed endpoint or server, plus per exposure verified closed — never per fix attempted. Your own security and operations teams run Fix Squad. It works on your running estate; for what your pipelines and infrastructure code do before a release, see DevSecOps assurance. Fixes can take the same governed path as every other production change through Change Guard.

See every offer · Agent Fleet Guardian