About · BlueTeamAutomation

Vulnerability management,
simpler and more private

CVEasy AI is the first local-first exposure management platform: the scanning, the scoring, and the remediation run on a machine you own, and your security data never leaves it. Built by BlueTeamAutomation in Milwaukee, Wisconsin. A proud Anthropic Claude Network Partner.

Company ledger2026
Company
BlueTeamAutomationMilwaukee, Wisconsin, USA
Founder
Chris BokerMS Cybersecurity & Information Assurance
Ships
CVEasy AI, a desktop CTEM platformmacOS · Apple Silicon · Tauri + Rust, React
AI model
cveasy-ai-v1runs on the device
Scoring
TRIS™, 12 layers · patent pending
Validation
BASzy™158,271 attack payloads
Integrations
152 across 16 categories
Partner
Anthropic Claude Network Partner
Cloud required
None. Air-gap capable.
Questions about any row: contact us
361K+
CVEs indexed
12
TRIS scoring layers
152
Integrations, 16 categories
100%
Local-first
01 · Why it exists

Built to make vulnerability management simpler and more private.

CVEasy AI began as internal tooling for one security team. The goal never changed: less triage, and no security data leaving the building.

Every vulnerability management tool on the market follows the same playbook: charge per asset, lock your data in someone else's cloud, and hand back a CVSS score that says everything is critical. A dashboard that says everything is on fire is one more thing to triage. The useful output is a short list, ranked against your environment, with the fix attached, and it should never require shipping your most sensitive inventory to a third party.

CVEasy AI is the answer to both problems at once. It is the first local-first exposure management platform: the scanning, the scoring, and the remediation all run on your own machine rather than sending your security data to an outside SaaS. The product grew out of years of hands on vulnerability management practice, custom tooling built to run cybersecurity for a family owned business, and graduate research in risk based vulnerability management.

BlueTeamAutomation is the company that ships it: based in Milwaukee, Wisconsin, designed and built in the United States. The name is literal. Automate the blue team's work until fixing is cheaper than triaging.

03 · Why local-first

Your vulnerability data is the most sensitive inventory you own.

A complete map of what is unpatched and reachable in your environment is a target list. CVEasy's answer is architectural: keep the application, the database, and the model on your machine, so there is no third party to trust and nothing in transit to intercept.

The app is local

A desktop application, on a machine you own.

Built with Tauri and Rust with a React front end, running on a Mac with Apple Silicon. The database sits on the same disk as the app.

  • No SaaS tenant, no shared infrastructure
  • Scan results and reports have no upload path
The model is local

cveasy-ai-v1 runs on the device itself.

The AI model behind scoring and remediation guidance does its inference on your hardware. Prompts, findings, and fixes never transit a cloud API.

  • On-device inference on Apple Silicon
  • Analysis happens where the data lives
Offline is a mode

Designed to run with no connection at all.

Teams on isolated or regulated networks run the entire exposure management loop fully offline. Air-gapped builds ship for government and defense.

  • Isolated and regulated networks supported
  • Your data never leaves your network
04 · The goals

Enterprise exposure management on a single Mac.

Vulnerability intelligence has been priced and architected for the Fortune 500. The goal is to put the same capability in front of every security team without asking for their data in exchange.

Enterprise vulnerability management shouldn't scale your bill with your infrastructure. It shouldn't require sending your most sensitive data to someone else's cloud. And it shouldn't take a team of ten to operate.

CVEasy AI puts AI-powered vulnerability intelligence, breach & attack simulation, and compliance automation on a single Mac. Your hardware. Your data. Forged in Milwaukee, Wisconsin: founded, designed, and built in the United States.

We work with managed security providers, healthcare organizations, and enterprise security teams who need to keep their exposure data in house. CVEasy is the same for a startup and the Fortune 500: the CTEM platform we wished existed, now in reach of every security team.

05 · Founder

Chris Boker

Founder of BlueTeamAutomation. He leads the engineering and product architecture and created the TRIS scoring method.

Chris designed CVEasy to work the way a practitioner needs it to: offline capable, private by default, and focused on closing findings rather than reporting them. Alongside the product he maintains a research portfolio anchored by the TRIS scoring method, built on years of vulnerability management practice, custom tooling for a family owned business, and a Master's degree focused on risk based vulnerability management, backed by more than 20 industry certifications.

Get in touch →
The research behind the product
06 · Interoperability

Works with the tools you already run.

73 native API connectors pull from your scanners, EDR, AppSec, identity, and cloud tooling. 43 file imports and 14 push endpoints catch the rest of what comes in, 15 outbound destinations carry work back to your ticketing, patch and chat tools, and 7 engines and feeds ship built in. 152 integrations across 16 categories in total.

CVEasy AI is an Anthropic Claude Network Partner and ships an open-source MCP server so Claude can query your posture locally.

Tenable
TenableNative API connector
Rapid7
Rapid7Native API connector
Qualys
QualysNative API connector
CrowdStrike
CrowdStrikeEDR connector
SentinelOne
SentinelOneEDR connector
Microsoft Defender TVM
Microsoft Defender TVMEDR connector
NVD / NIST
NVD / NISTCVE database
OSV / GHSA
OSV / GHSAAdvisory feeds
CISA KEV
CISA KEVExploit catalog
MITRE ATT&CK
MITRE ATT&CKThreat framework
CVEasy AI
CVEasy AI™Built-in AI engine
Anthropic Claude
Anthropic ClaudeNetwork Partner · MCP

All trademarks are the property of their respective owners. Logos denote integration context, not endorsement.

Validate the company by running the product.

A demo on your hardware beats a slide about ours.

Request a Demo → See public pricing