Available Now

Quick Start

Get CVEasy AI running on your hardware in under 10 minutes. No cloud account. No API key required to get started.

Prerequisites
Apple Silicon Mac
M1, M2, M3, or M4 chip required
CVEasy AI Engine (Built-in)
Local AI inference. cveasyai.com
Bun Runtime
JavaScript runtime. bun.sh
Entry Configuration
Mac Mini M2+ · 16 GB unified memory
Single AI model (~5 GB VRAM). Perfect for core VM.
Full Platform
Mac Studio M2 Max+ · 64 GB unified memory
Multi-model routing (~15 GB VRAM). Full suite + BASzy.
1

Download and Install CVEasy AI

CVEasy AI includes a built-in AI engine for local inference, no external tools required. Install it, then pull the recommended model for your tier:

# No installation needed # No installation needed. AI engine is built in # Start the AI engine # AI engine starts automatically
Lite (16 GB Mac)
# Single optimized model (~5 GB) # Model is bundled with the application
Pro (64 GB Mac)
# Primary engine (~10 GB) # Model is bundled with the application # Code engine (~5 GB) # Model is bundled with the application

CVEasy AI auto-detects available models on startup. Pro users can configure model routing in Settings to assign specific models to remediation, chat, reports, code generation, and analysis tasks.

2

Download and run CVEasy AI

CVEasy AI is distributed as a single binary. Download the latest release for your platform:

# Extract your installation package tar -xzf cveasy-ai-*.tar.gz cd cveasy-ai # Install dependencies bun install # Start the server bun run start

CVEasy AI starts on http://localhost:3001. Open it in your browser and the setup wizard verifies your local components.

CVEasy AI · Setup Wizard
CVEasy AI Setup Wizard showing the AI Engine, AI Model, and Database core components all marked Ready

Setup Wizard. Core components verify locally before the app launches. Nothing here reaches for the cloud.

3

Configure your company profile

Open Settings and set your industry vertical and compliance frameworks. This calibrates the TRIS score to your environment. A healthcare org and a retail org have different patch priorities for the same CVE.

Select your industry (Healthcare, Finance, Retail, Critical Infrastructure, etc.)
Select applicable compliance frameworks (HIPAA, PCI-DSS, SOC 2, NIST)
Confirm AI provider is set to CVEasy AI Engine (default)
CVEasy AI · Settings
CVEasy AI Enterprise Settings page with company profile, industry, and compliance framework options

Organization profile. Industry and compliance context flow into TRIS scoring, so prioritization reflects your business rather than a generic average.

4

Bring in your vulnerability data

Three ways to populate CVEasy AI, from most automated to most manual:

Option A: Connect a scanner or EDR
Open Connectors under Integrate and authorize a native API client. Twenty-seven pull live across 16 categories; Rapid7 InsightVM, Tenable.io, Qualys VMDR, CrowdStrike, SentinelOne, and Defender TVM lead the set. Click Test, then Pull. Schedule auto-sync to stay current. Findings from every tool dedupe on asset identity.
Option B: Import or push a scan file
Drop an export onto Scan Imports, or POST it to the webhook API. Fifty-seven file formats are auto-detected: Nessus, Qualys, Nuclei, Burp, ZAP, Trivy, OpenVAS, SARIF, Wiz, Prowler, Nmap, CSV, and more.
Option C: Search NVD directly
Use the search bar to look up CVEs by ID (CVE-2024-1234) or keyword. CVEasy AI pulls live data from NIST NVD and enriches it automatically.
CVEasy AI · Scan Imports
CVEasy AI Scanner Import page with a drag-and-drop area and tiles for Nessus, Qualys, Rapid7, OpenVAS, Nuclei, Burp Suite, Trivy and more

Scan Imports. Drop a file and the format is auto-detected. Native connectors and the webhook API land findings the same way, deduplicated on asset identity.

5

Review your triage queue

Open the Command Center. Every ingested CVE has been automatically scored and ranked. Findings are sorted by TRIS score, and KEV-listed CVEs are pinned at the top regardless of CVSS.

CVEasy AI · Command Center
CVEasy AI Command Center showing risk posture KPI cards, platform intelligence, a priority queue of findings, and top remediations

Command Center. KPI deck up top, TRIS priority queue below, top remediations and sector threat actors on the right. This is the screen you open every morning.

Click any CVE to open the detail view and generate an AI remediation guide. When you are ready to act, the Fix First board turns the ranked list into work orders you push through your patch consoles or cut as tickets. The AI runs locally via CVEasy AI Engine, and no data leaves your machine.

6

(Optional) Connect Claude through the MCP server

The built-in CVEasy AI Engine handles everything on-device. If your team uses Claude, the native MCP server connects Claude Desktop or Claude Code directly to your live instance for posture queries, findings search, TRIS scoring, and report generation:

# In Claude Desktop → Settings → Developer → Edit Config "cveasy": { "command": "cveasy-mcp", "args": ["--instance", "http://127.0.0.1:3001"] }

The MCP server talks to your local instance, so your exposure data stays on your hardware. CVEasy is an Anthropic Claude Network Partner. Setup details at github.com/CVEasy/cveasy-mcp.

What's next