Partners & Integrations

Backed by an enterprise network,
wired into your stack

CVEasy AI is delivered through managed-service and technology alliances with the biggest names in security, and it plugs natively into the scanners, EDR, MDM, and ticketing tools your team already runs.

01 · The integration ledger

152 integrations across sixteen categories, and every row reconciles

It doesn't replace your stack; it reads it. One-click connectors pull findings in, TRIS™ reranks everything, and patch orchestration pushes fixes back out. Encrypted credentials, auto-sync scheduling, all local. Deduped on asset identity and grouped by the fix that closes them, teams see around a 75% reduction in ticket volume.

01

AppSec & Code

The largest category. Code, dependency, secrets, and SBOM findings land in the same graph as your infrastructure vulns.

GitHub Snyk GitLab SonarQube Semgrep Checkmarx Veracode Trivy SARIF
38
02

Cloud

The proprietary cloud scan engine runs 204 CIS rules across all three major providers, and posture findings ingest from your CNAPP.

AWS Azure Google Cloud Wiz
11
03

Network

Firewall and device exports feed reachability and segmentation context.

Cisco ASA
9
04

Automation

CI pipelines and webhooks push findings in as part of the build.

GitHub Actions n8n Webhooks
9
05

CMDB

Inventory pulls keep canonical assets and owners current.

ServiceNow CMDB NetBox Intune
8
06

Vuln Scanners

Scan imports are rescored with TRIS 12-layer intelligence, so your team patches what attackers actually use.

Rapid7InsightVM QualysVMDR TenableNessus Burp Suite
7
07

Controls

Mitigating controls earn, or lose, credit in TRIS scoring.

Palo Alto Networks Fortinet Cloudflare
7
08

Threat Intel

Enrichment feeds that mark what is being exploited in the wild.

CISAKEV NISTNVD EPSS MITREATT&CK
6
09

ITSM

Work orders flow into the queue your team already lives in, with webhook updates when status changes.

ServiceNow Jira
5
10

Patch

Fix First pushes tiered patches: staged rollouts, maintenance windows, and fail-closed approval gating.

Microsoft Intune Jamf Pro
5
11

Notifications

Alerts and status changes flow out to wherever your team watches.

Slack Teams PagerDuty
5
12

EDR & Endpoint

Agent inventory and detections keep canonical assets current, without another agent to deploy.

CrowdStrike SentinelOne MicrosoftDefender
3
13

Identity

Directory pulls put an owner on every exposure instead of a bare IP.

Okta Entra ID
3
14

EASM

External surface findings merge onto the same asset identity.

Rapid7Surface Command
2
15

Engines

Scan engines that ship inside the app. No connector, no credential.

Built-in
2
16

SIEM

Investigation context lands next to the vulnerable asset it fired on.

Rapid7InsightIDR
1
16 categories
27 native API57 file import14 push
152
CVEasy AI · Connectors
CVEasy AI Connectors catalog, showing connector cards grouped by category with connector cards for Tenable, Qualys, Rapid7, Nessus, and CrowdStrike showing API and FILE mode badges

The same ledger in the shipped app. Every card is honest about its mode: API pull, file import, push ingest, outbound, or built-in.

02 · AI partner

Claude in the loop, when you want it.

Frontier reasoning is a first-class option, not a dependency. One membership covers both halves: the in-product Claude integration, and the open-source MCP server that puts your live install inside Claude Desktop and Claude Code.

Claude Partner Network · member
Anthropic

An Anthropic partnership, built local-first

CVEasy AI is a member of the Anthropic Claude Partner Network. For teams that want frontier models in the loop, the Claude integration routes through a secure connection you control, and the official CVEasy MCP server connects Claude Desktop and Claude Code straight to your live install for posture queries, TRIS™ scoring, and report generation.

Optional by design. The on-device CVEasy AI Engine runs the product on its own, so air-gapped installs lose nothing.

cveasy-mcp · open source · thin client
Tools
Posture · CVE deep-dives · TRIS scoring · report generation
Client
Thin by design. The tools run against your install, not a copy of your data.
Data path
Your exposure data never leaves your machine.
CVEasy MCP on GitHub →
03 · Deployed alongside

The stacks we run in.

Beyond the connector catalog, these are the environments CVEasy deploys into: the storage, virtualization, backup, network, and awareness platforms sharing the rack on real engagements.

Zscaler
VMware
Veeam
Pure Storage
KnowBe4
Barracuda Networks
Dynatrace
Extreme Networks
Infinidat
Hitachi Vantara
Wasabi
Perimeter 81
RingCentral

All trademarks are the property of their respective owners. Logos denote integration or deployment context, not endorsement.

04 · Work with us

Become a partner.

Whether you deliver security for other people, build a tool we should read, or just need your stack supported, there is a track for it.

Track A

MSSP & managed service

Run CVEasy across your client base from one install. Built for teams who own posture for somebody else.

  • Per-tenant workspaces with isolated data and scoring
  • Client-branded TRIS™ reports and remediation plans
  • Scheduled auto-ingest from each client's scanners
  • Fix First work orders pushed through your patch consoles
Talk to us →
Track B

Technology Partners

Build a connector, or have us build one. If your tool produces findings, asset data, or detections, it belongs in the graph.

  • API pull, file import, or push ingest, whichever fits
  • Listed in the in-app connector catalog
  • SARIF, CSV, and webhook paths already supported
  • Joint validation against a real environment
Start a conversation →
Track C

Request an Integration

Running something we don't support yet? Tell us what it is and what it exports. Customer requests set the connector roadmap.

  • Most file-import connectors ship in days, not quarters
  • We'll take a sample export and confirm the mode
  • You get told when it lands, in the changelog
Request your tool →

Want to see it running against your stack?

Bring your scanner. We'll show you what TRIS reranks in the first ten minutes.

Request a Demo →