Fix Squad reads every scanner you run, puts the exposures attackers already use first, fixes them through the tool that owns each asset under a change your process authorised, and closes an exposure only when your next scan no longer sees it.
Every scanner you run is read, and a scanner that could not be read is reported — never counted as clean.
The same exposure found twice is one line. Exploited in the wild, internet-facing and business-critical go first, by published rules.
Fixes grouped into change-sized batches: one owning tool, one maintenance window, one ring at a time.
Through the automation that owns the asset, against an authorised change record checked right before launch.
A scan completed after the fix, covering the asset, no longer sees it. Nothing else closes it.
Each closure keeps its change, its job, its scans and its timing — ready for your auditors.
A job that ends green says the job ran. It does not say the vulnerability is gone, and the agent that applied the fix is the last one who should vouch for it. So the verdict comes from scan evidence only, and a scanner that still sees the exposure outweighs one that does not.
Every scanner that reported it scanned the asset after the fix and no longer sees it.
A scan after the fix still sees it. Back to planning, with the evidence.
It came back after being closed. Reopened, with an incident on the original change.
No covering scan yet. It stays open, and a missing scan is chased.
A class is one kind of fix, on one kind of asset, through one tool. Each climbs on its own verified record, and drops back on its first failure.
Standard patches your change board pre-approved start with a person confirming each batch, and can run on their own once their verified record holds.
The same path, one ring at a time, opened only when the ring before it is already trusted.
One server per change, each approved by a person, until that class earns a pre-approved path of its own.
Recommended first; applied by a person or by the team that owns the infrastructure code.
Nothing is autonomous by default, and nothing is capped forever: the verified record decides, and your change board signs off each promotion.
Priced per managed endpoint or server, plus per exposure verified closed — never per fix attempted. Your own security and operations teams run Fix Squad. It works on your running estate; for what your pipelines and infrastructure code do before a release, see DevSecOps assurance. Fixes can take the same governed path as every other production change through Change Guard.