Autonomous Cyber Remediation

FERRALON

Prove what’s exploitable. Prove it’s fixed.

Autonomous remediation for developers, security teams, and MSSPs.

FERRALON
SCROLL
39.7°N · 104.9°W

Frontier AI has made vulnerability discovery abundant.

Finding vulnerabilities is no longer the bottleneck. Determining what is exploitable — and proving the fix — is.

Findings now outnumber available remediation hours. Most do not apply. The ones that do must be found, fixed, and verified.

WHAT WE DO

Prove it. Fix it.
Prove it holds.

ProofVerify whether a vulnerability is actually exploitable.Cut the exposure list to the findings that matter.
RemediationGenerate and validate the fix.Prove the fix is correct before it reaches production.
EvidenceShow that the fix holds.Demonstrate the exposure is closed — and prove that status remains true.
FREE · OPEN SOURCE

A free scanner that tells you which findings you can ignore.

Ferralon Assay analyzes your code and the execution paths through it to determine whether it can actually reach known vulnerable code. It gives developers and security teams a clear answer: fix this finding, investigate it, or ignore it.

It ships as a GitHub Action and runs on your own runners, so your source never leaves your network.

  • DisqualifiedThis one doesn't apply to your setup at all.
  • Not reachableThe vulnerable code isn't in your build, or nothing in your code can reach it.
  • Reachable candidateYour code does reach the vulnerable function. Worth a look.

The free scanner will never tell you something is exploitable.

It can’t — nothing was run, so nothing was proven. Finding out whether an attack actually works means executing it in a sandbox, and that’s our paid product. Plenty of scanners blur that line. We built ours so it can’t.

Explore Ferralon Assay →

OPEN DATA · CC BY 4.0

Vulnerability intelligence that does not invent certainty.

Ferralon Vulnerability Corpus turns public advisory data into structured records for scanners and enrichment systems. Missing facts stay missing—not guessed, defaulted, or implied.

  • INTEGRITY-PINNEDEvery record is listed in a manifest with its SHA-256 digest.
  • SELECTION, NOT VERDICTSPolicies narrow what you scan. They do not call anything outside the set safe.
  • OPENLY LICENSEDCC BY 4.0 data with provenance and terms published in the repository.

Explore the Vulnerability Corpus →

Built for developers, security teams, and MSSPs operating at enterprise scale.

01

One pane across your whole estate.

Exposure and proof across every system you run — or customer you protect.
02

Proof you can show, not just claim.

Evidence of what was exploitable and closed — for boards, auditors, and customers.
03

Not another scanner.

You get verdicts, not another queue of noise to triage.
Operators

Founded by operators who have built and run internet-scale security analytics platforms.

Gene Stevens
Co-Founder

Gene Stevens

Co-Founder & CTO
ProtectWise
Head of Global Product Innovation
Verizon Business Group
Built & operated internet-scale
security analytics platforms
OPERATOR & FOUNDERLinkedIn ↗
Eric Stevens
Co-Founder

Eric Stevens

Technical Fellow
Pax8 Labs
Director, Security Engineering
Verizon
VP Engineering & Principal Architect
ProtectWise
OPERATOR & FOUNDERLinkedIn ↗

Two operators. One conviction: remediation must run at machine speed, with operator control and accountable results.