Zero to a scored queue in under ten minutes.
CVEasy AI runs on your hardware, start to finish. No cloud account. No API key required to get started.
- Platform
- macOS on Apple Silicon (M1 to M4)
- Cloud required
- None. Everything runs on your machine.
- To get started
- No API key, no cloud account.
- First results
- A TRIS™-scored triage queue.
Setup is an API key.
CVEasy AI · Connect in minutes · 0:30
Three prerequisites, and only Bun needs installing
CVEasy AI is a native Apple Silicon application with the AI engine built in. The only thing to install ahead of time is the Bun runtime. No agents, no cloud tenancy, no GPU cluster.
Apple Silicon Mac
M1, M2, M3, or M4 chip required.
The path, one clock, six steps.
Each step pairs the instruction with the screen you will actually see. The T+ marks pace the ten-minute clock; your pace may vary, the destination does not: a TRIS™-scored queue.
Download and install CVEasy AI
CVEasy AI includes a built-in AI engine for local inference, no external tools required. Install it, then pull the recommended model for your tier:
# No installation needed
# No installation needed. AI engine is built in
# Start the AI engine
# AI engine starts automatically
CVEasy AI auto-detects available models on startup. Pro users can configure model routing in Settings to assign specific models to remediation, chat, reports, code generation, and analysis tasks.
AI Engine. Lite runs one optimized model (~5 GB); Pro routes a primary (~10 GB) and code engine (~5 GB) per task. Both are bundled with the application.
Download and run CVEasy AI
CVEasy AI is distributed as a single binary. Download the latest release for your platform:
# Extract your installation package
tar -xzf cveasy-ai-*.tar.gz
cd cveasy-ai
# Install dependencies
bun install
# Start the server
bun run start
CVEasy AI starts on http://localhost:3001. Open it in your browser and the setup wizard verifies your local components.
Setup Wizard. Core components verify locally before the app launches. Nothing here reaches for the cloud.
Configure your company profile
Open Settings and set your industry vertical and compliance frameworks. This calibrates the TRIS score to your environment. A healthcare org and a retail org have different patch priorities for the same CVE.
Select your industry (Healthcare, Finance, Retail, Critical Infrastructure, etc.)
Select applicable compliance frameworks (HIPAA, PCI-DSS, SOC 2, NIST)
Confirm AI provider is set to CVEasy AI Engine (default)
Organization profile. Industry and compliance context flow into TRIS scoring, so prioritization reflects your business rather than a generic average.
Bring in your vulnerability data
Three ways to populate CVEasy AI, from most automated to most manual:
Scan Imports. Drop a file and the format is auto-detected. Native connectors and the webhook API land findings the same way, deduplicated on asset identity.
Review your triage queue
Open the Command Center. Every ingested CVE has been automatically scored and ranked. Findings are sorted by TRIS score, and KEV-listed CVEs are pinned at the top regardless of CVSS.
Click any CVE to open the detail view and generate an AI remediation guide. When you are ready to act, the Fix First board turns the ranked list into work orders you push through your patch consoles or cut as tickets. The AI runs locally via CVEasy AI Engine, and no data leaves your machine.
Command Center. KPI deck up top, TRIS priority queue below, top remediations and sector threat actors on the right. This is the screen you open every morning.
Connect Claude through the MCP server
The built-in CVEasy AI Engine handles everything on-device. If your team uses Claude, the native MCP server connects Claude Desktop or Claude Code directly to your live instance for posture queries, findings search, TRIS scoring, and report generation:
# In Claude Desktop → Settings → Developer → Edit Config
"cveasy": {
"command": "cveasy-mcp",
"args": ["--instance", "http://127.0.0.1:3001"]
}
The MCP server talks to your local instance, so your exposure data stays on your hardware. CVEasy is an Anthropic Claude Network Partner. Setup details at github.com/CVEasy/cveasy-mcp.
The wire. Claude talks to the MCP server, the MCP server talks to 127.0.0.1. There is no third hop.
Ten minutes in, you are looking at a ranked queue, not a raw export.
Every finding scored against your industry, your compliance frameworks, and the live threat picture. KEV pinned on top. Fix First ready to cut the work orders. All of it on your hardware.
What’s next
The tool is running; now build the practice around it. Two field guides and a direct line for anything the wizard didn’t answer.