Connect your Vulnerability Management
Vulnerability scanners already produce the data your risk register quotes by hand. TruSecure's vulnerability-management connector pulls findings, severities and remediation state directly, so risk entries carry scanner provenance instead of pasted screenshots.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Scan findings | Open findings, CVE identifiers, CVSS scores | Risk and Exception Management · live risk entries |
| Remediation state | Ticket linkage, fix dates, exceptions with expiry | Audit Trail · SLA evidence |
| Asset coverage | Scanned vs unscanned assets, scan freshness | Evidence Automation · scan-completeness controls |
| SBOM data | Component inventories, affected versions | CRA tracking · vulnerable-component obligations |
Evidence produced from Vulnerability Management data
One control test pulled from live Vulnerability Management state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- Remediation SLA · critical findings within 14 days
- Scanner source
- Tenable.io · scan completed 2026-08-21
- Test
- re-perform · open findings vs SLA window
- Sample
- 23 critical findings · 19 in-window, 4 breached
- Result
- fail · 4 breaches, each with owner and exception status
- Evidence
- Scanner API query · timestamped 2026-08-22T07:55:03Z
- Export
- sealed · sha256:9d2e...6a1c
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to findings, asset coverage, and remediation state. No write permissions, no ability to close or reopen findings.
- Data filtered by entity
Findings scoped to your asset groups — a shared scanner serving several organizations keeps each organization's governance record separate.
- Continuous sync
Risk entries refresh as scans complete. An SLA breach is dated from the scan that proved it, not from whenever someone updated the register.
Commercial packaging
Vulnerability Management connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual Vulnerability Management environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.