Skip to main content
INTEGRATION

Connect your Vulnerability Management

Vulnerability scanners already produce the data your risk register quotes by hand. TruSecure's vulnerability-management connector pulls findings, severities and remediation state directly, so risk entries carry scanner provenance instead of pasted screenshots.

What the connector pulls

Vulnerability Management data pulled into TruSecure
Source systemWhat TruSecure pullsFeeds governance
Scan findingsOpen findings, CVE identifiers, CVSS scoresRisk and Exception Management · live risk entries
Remediation stateTicket linkage, fix dates, exceptions with expiryAudit Trail · SLA evidence
Asset coverageScanned vs unscanned assets, scan freshnessEvidence Automation · scan-completeness controls
SBOM dataComponent inventories, affected versionsCRA tracking · vulnerable-component obligations

Evidence produced from Vulnerability Management data

One control test pulled from live Vulnerability Management state — not a manual export, not a screenshot, but a verified query result with provenance:

Control test · VM-2026-031 remediation SLASample data
Control tested
Remediation SLA · critical findings within 14 days
Scanner source
Tenable.io · scan completed 2026-08-21
Test
re-perform · open findings vs SLA window
Sample
23 critical findings · 19 in-window, 4 breached
Result
fail · 4 breaches, each with owner and exception status
Evidence
Scanner API query · timestamped 2026-08-22T07:55:03Z
Export
sealed · sha256:9d2e...6a1c

Setup and scope model

  1. Read-only, scoped permission

    Connector requires read-only access to findings, asset coverage, and remediation state. No write permissions, no ability to close or reopen findings.

  2. Data filtered by entity

    Findings scoped to your asset groups — a shared scanner serving several organizations keeps each organization's governance record separate.

  3. Continuous sync

    Risk entries refresh as scans complete. An SLA breach is dated from the scan that proved it, not from whenever someone updated the register.

Commercial packaging

Vulnerability Management connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.

How integration works

A demo with your actual Vulnerability Management environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.