+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. If you already run an agent covering part of this scope, that part is not charged again: only the real extension is priced. Request a quote
● B2B offer — Vulnerability & patch management

Vulnerabilities and patches: which advisory hits which machine, in what order, and on what evidence

A security advisory is published about a product; it says nothing about you until your inventory speaks. Your agent works on the inventories, software bills of materials and scanner reports you open to it: it looks for where that product runs, in which version, exposed how and under whose ownership, explains the order of work factor by factor, then prepares the ticket, the tests, the change window and the rollback. Hosted in France: the map of your versions and weak points does not leave the company. Deploying a patch stays a human decision, taken by the asset owner and recorded.

Hosted in France Version map protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
Vulnerability & patch management · hosted in France
Four advisories landed this week. Which ones actually concern us?
Across the inventories you deposited, each advisory is matched to the assets carrying the product in question, with the observed version, its source and its date.
Every match carries a confidence level and the evidence behind it; the order of work recomposes factor by factor, together with the policy rule that may have raised it.
An asset whose version is unknown is marked under investigation, never fixed.
🔗 Sourced · inventories, bills of materials and reports deposited, with their date and age
Can it apply the patches directly?
The change case is drafted, complete and replayable: asset, version, patch, prerequisites, tests, window, rollback, expected evidence.
A patch applied without a rollback turns a production capability into a bet: the decision belongs to the asset owner, execution to your operations team, and the effect is declared achieved only after the next inventory is read back.
✎ Framework · change prepared, decision and deployment human
Local inference · no data outside the EU
Version map hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
The owner decidesThe agent prepares, your operations team deploys
✦ In brief

A Blue Lemon Agent for vulnerability and patch management, working on the inventories, software bills of materials and reports you deposit: it matches each published advisory to the assets carrying the product, displays its confidence and its evidence, explains the order of work factor by factor, prepares the ticket, tests, window and rollback, then assembles the evidence file. Deployment orchestration runs in simulation by default: any real write requires a confirmed asset and version, a patch from an approved source, the required tests passed, an available rollback and a recorded human approval. It runs on local inference or is hosted in France: the map of your versions stays with you, an architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.

100 %
hosted in France in the target architecture
0
transfers outside the EU in the target architecture
12
vulnerability-management modules included in the core
0
patches deployed without a human decision

Reference points describing our offer, not results measured at a customer site. How far the gain reaches, across your assets, advisories and owners, is confirmed by a pilot.

The context

What does an AI agent bring to your patch management?

An advisory whose affected asset, observed version and owner are all visible is settled in a minute; a vendor bulletin cross-checked by hand takes a week.

! What is at stake

NIST describes patch management as preventive maintenance to be planned, not as a reaction to an event (NIST, SP 800-40 Rev. 4, “Guide to Enterprise Patch Management Planning”, published April 2022). The work that jams is not the decision: it is knowing whether the affected product runs anywhere in your estate, in which version, exposed how, and who answers for the machine. That work is systematic, and it can be prepared.

Our answer

Your asset owners receive cases that are already worked up: the advisory, the asset, the observed version with its source, the confidence level, the order of work recomposed factor by factor, and the change drafted with its tests and its rollback. They decide, and their reasoned decision is kept with its date and its author. An unknown version stays unknown: it blocks a closure rather than manufacturing a certainty. Local inference or an isolated resource hosted in France: the map describing your versions, and therefore your weak points, does not leave the company.

The decisive point

Your version map: sovereignty & confidentiality

The list of your unpatched assets says where your weak points are. Keeping it confidential is itself a security matter; here is how that is held.

Local inference

The agent can run on a machine inside your organisation: no inventory, no bill of materials and no scanner report leaves the network.

Hosting in France

Otherwise, a dedicated, isolated resource hosted in France under French law — your inventories, cases and evidence: processing and access operated within the European Union as targeted by the architecture.

Reduced extraterritorial exposure

For your version map and your unpatched assets, the architecture aims to reduce exposure to the Cloud Act and FISA 702; location in France or in the European Union does not on its own guarantee immunity.

Entities kept apart

Each subsidiary, entity or site has its own space: a remediation case never shows another entity's assets, and roles follow that separation.

Decisions kept

Every decision keeps its author, date, reason and the policy version applied; encryption, role-based access (RBAC) and logging usable in an audit. Read, write and approval rights are separated.

AI Act: governed deployment

The agent is strictly in support; no patch deployed, no risk accepted and no case closed automatically; traceability and human oversight end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For entities under a sector-specific regime — financial services, essential or important entities —, SecNumCloud and hardened hosting options are available depending on your level of requirement. Whether a given text applies is checked entity by entity, and this page is neither a finding nor a guarantee on that point.
Demonstration

See the agent at work

5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Vergaray Participations — active holding company, six subsidiaries

Sector
Active holding company, NAF 64.2 — six subsidiaries: one manufacturer, two service companies, three distributors
Headcount
31 people at head office, two of them in IT. No CISO, no security analyst. 1,240 employees across the six subsidiaries
Who it serves
The six subsidiary boards, a supervisory board, two statutory auditors
Order of magnitude
About 900 endpoints and 140 servers spread across the six subsidiaries; quarterly financial consolidation; treasury centralised at head office
Tools already in place
Three configuration databases out of six kept current, a weekly scanner at two subsidiaries, the head-office ticketing tool, the internal-control document store — the agent reads what the group opens to it, nothing is replaced
The manufacturing subsidiary
Fournils de Vaubourg — one site, two production lines running three shifts, 3 people in IT and 2 automation engineers; owner of the legacy regulatory-reporting server
The plant's constraint
One single planned line stop night a month — that constraint, not a vendor rating, governs the order of work on the manufacturing scope
Who decides
The chief financial officer arbitrates priorities and any risk acceptance; the head-office IT manager prepares the cases; each subsidiary director remains the owner of their assets and alone authorises changes to them
The improvement points
No single version table across the six subsidiaries; nobody at head office knows the version of the shared identity gateway; the regulatory-reporting server is out of vendor support

Vergaray Participations steers six subsidiaries that share neither an inventory tool, nor a patching rhythm, nor an owner. Head office receives vendor advisories like everyone else and has no way of saying, within a week, which subsidiary is concerned. The agent reads the three configuration databases that are kept current, the weekly scanner reports of two subsidiaries, the head-office ticketing tool and the group provider register. It matches, quantifies, explains and prepares — the chief financial officer arbitrates, and each subsidiary director authorises whatever touches their machines. The exchanges below cover one week, from advisory intake to evidence file. The fifth tab opens the MANUFACTURING scope of the subsidiary that already owns the regulatory-reporting server: four plant assets, one stop night a month, and safety impact as a priority factor.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

Vulnerability & patch management · hosted in France
I have assembled what your six subsidiaries declare, and I open with what is missing — that is half the work in a holding company.
This demonstration uses entirely fictional data. No system is scanned or changed.
The sovereign AI foundation chosen at quotation — local inference or an isolated resource hosted in France — carries this agent: your exports and your advisories stay inside that space.
The scope loaded:
· 4 group assets: the consolidation portal, the centralised treasury hub, the shared identity gateway serving all six subsidiaries, the legacy regulatory-reporting server.
· 4 fictional advisories, prefixed DEMO-CVE so that none can be mistaken for a real vulnerability.
· 5 simulated sources: the subsidiaries' configuration databases, the weekly scanner reports of two of them, the head-office ticketing tool, the group provider register, the internal-control document store.
· Advisory collection and normalisation, already done: the 4 advisories arrive in four different shapes and leave in one — a product, an affected version range, a source, a publication date. That normalisation is what makes line-by-line matching possible.
· Demonstration policy demo-policy-1.0, with its four thresholds and six priority rules — yours would apply, not mine.
And the two gaps, named:
· The version of the shared identity gateway is unknown — it is operated by a provider under a group framework contract, and none of your databases carries it.
· The regulatory-reporting server has no owner at head office: it belongs to the manufacturing subsidiary, which alone authorises changes to it.
An unknown value stays unknown throughout. It is neither healthy nor fixed, and you will see that it blocks a closure rather than manufacturing one. deposit-of-sources_vergaray-group.pdfINPUT DOCUMENT · 5 exports deposited, 4 advisories, 0 writes
⛓ Sourced · 5 exports deposited on 07/09, ages shown, group threshold 72 h
Three of our six subsidiaries keep their inventory. What are you working from for the other three?
From nothing, and I display it — it is the first indicator on the dashboard, ahead of any score.
Here is the reconciled cyber inventory of the group first: your five exports come back as a single table — asset, component, version, owner, source and age of the data. Everything that follows rests on that reconciled table.
Inventory coverage is the measure that governs all the others: an asset missing from an inventory is invisible to me, and it is precisely the forgotten asset that causes trouble. The attachment gives you coverage subsidiary by subsidiary, with what each one lacks.
What I propose, and the arithmetic: the four group assets head office operates itself are 100 % covered, because you keep that inventory. The three subsidiaries without a current database represent, in this fictional scenario, about 380 endpoints and 46 servers on which I can affirm nothing. Rather than opening six inventory projects at once, I propose starting with the manufacturing subsidiary: it hosts the out-of-support regulatory-reporting server, so it is where the ignorance costs the most today.
The decision is yours, and it is taken on a figure: three inventory projects, or one, on the asset you already know is out of support. inventory-coverage_six-subsidiaries.pdf3 entities out of 6, 2 named gaps
⛓ Sourced · inventory coverage given ahead of any score
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

Twelve modules included in the core, from the reconciled inventory to the evidence file. All of them work in support, under your approval.

Included in your agent The 13 capabilities essential to this promise are included, at no extra cost.

Reconciled cyber inventory

Brings your inventory sources together — endpoint estate, configuration database, cloud accounts, image registries, dependency manifests — into one table of assets, components, versions and owners, each with its source and its age.

Advisory collection and normalisation

Takes in the advisories, bulletins and reports you open to it, normalises them into a single format and keeps, for every value, its source and its publication date.

Vulnerability-to-asset matching

Matches each advisory to the assets carrying the affected product, with the observed version, the affected range, a mandatory confidence level and the evidence retained.

Explainable contextual prioritisation

Builds the order of work with a versioned deterministic engine: every score recomposes on screen factor by factor, and every policy rule displays its identifier.

Remediation plan

Writes, for each case, the action, the owner, the due date taken from your policy, the required tests and the rollback — and flags the case that is missing one of the four.

Tickets, changes and escalations

Prepares the ticket and the change request in the form you already produce, with no duplicate when a case is replayed, and drafts the escalation as a due date approaches.

Patch checks before it goes on

Checks the patch's approved provenance, its prerequisites, the tests it must pass and the pilot group it proves itself on before it is proposed to the whole estate.

Guarded orchestration

Shows in simulation what would be triggered, case by case. A real write requires a confirmed asset and version, an approved patch, passing tests, a compliant window, an available rollback and a recorded approval.

Verification after remediation

Reads the next inventory to confirm the effect obtained, separates a complete fix from a partial one and names the assets left open with their reason.

Dated exceptions and compensating controls

Drafts the exception with its scope, compensating controls, owner, approver, expiry date and revocation conditions — and reopens the case at the due date.

Bills of materials and exploitability statements

Uses the software bills of materials (SBOM) and exploitability statements (VEX) you or your suppliers produce, ties each component to the delivered version and prepares the product-security case.

Evidence and steering

Logs source, decision, case, exception, action, acknowledgement and delay, and puts its own inventory coverage at the top — the file an internal auditor or a statutory auditor asks for.

Sovereign AI

The hosting and confidentiality foundation the agent rests on.

Controls and safeguards These 10 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Recorded human approval before any write and before any deployment Strict separation of read, write and approval rights; least-privilege permissions No execution of code coming from an advisory, a ticket, an attachment or a repository; external content is DATA, never instructions Provenance, timestamp and freshness carried by every fact; no value without its source; conflicting sources are kept and flagged, never settled silently A mandatory confidence level on every match; a fuzzy match is never presented as confirmed Blocked where the version, the asset or the patch is not sufficiently identified, or where the required tests, rollback or approval are missing Simulation by default on all deployment orchestration; idempotent writes and no duplicate tickets A verifiable log of every decision and every change, with the policy version applied; the previous priority and its reasoning are kept after any recalculation No automatic closure where the evidence is missing, out of date or contradictory; an expired exception reopens the case and never renews itself Separation of clients and entities; masking of secrets, addresses and personal data in every output; an explicit, dated degraded mode when a source is unavailable

Need to go further?

These agents handle a different business process, with their own owner and their own price. They are added to this one.

Cybersecurity & logs

Correlating the events of an incident and qualifying an alert starts from a fact observed in your logs; the vulnerability cycle starts from an advisory published outside.

Cybersecurity & logs from 601 € excl. VAT / month Discover the agent

Advanced technical support

Resolving a request raised by a user belongs to support; here, cases exist whether or not anyone raises them, with due dates that run while nobody calls.

Advanced technical support from 566 € excl. VAT / month Discover the agent

Code generation & review

Writing the fix for a dependency happens in the repository; knowing on how many assets that dependency is deployed, and how exposed they are, happens here.

Code generation & review from 624 € excl. VAT / month Discover the agent

Regulatory control

Showing that an obligation is met, and keeping the file that proves it, belongs to compliance control; here the material is technical — an asset, a version, a patch — and the verification record produced feeds that file rather than replacing it.

Regulatory control from 721 € excl. VAT / month Discover the agent

Technical support & documentation

Writing and maintaining operational documentation belongs to that agent; here documentation is an input — maker data sheets, release notes — and the output is a dated change file, ready to sign.

Technical support & documentation from 664 € excl. VAT / month Discover the agent

Testing & software quality

Designing and running an application test campaign belongs to that agent; here regression tests are a CONDITION of the deployment window, required on file and checked before the change goes out.

Testing & software quality from 522 € excl. VAT / month Discover the agent
Does your need fall outside this?

In 15 minutes we identify the most relevant agent — without oversizing the project.

Book the free audit Build your agent
The gain

How many advisories can a team work through?

By taking on the matching, the search for the owner and the reconstruction of versions, the effort moves towards the decision. How far the gain reaches depends on your estate and is confirmed by a pilot.

Matching an advisory to the assets concerned
Today · done by hand
Assets matched, confidence shown
Finding the owner and the version
Today · done by hand
Version sourced, owner proposed
Assembling the evidence file
Today · done by hand
File assembled as decisions are taken
Illustrative, non-contractual reference points, to be confirmed by a pilot on your number of assets, sources and owners. No qualification or remediation delay is announced: the due dates the agent displays come from your policy, they are not a performance of the agent. Deploying a patch can interrupt production: that decision belongs to the asset owner, and its execution to your operations team.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One scope, one agent

One vulnerability and patch management agent (inventory, matching, prioritisation, plan, evidence), installed and operated for you. The scope is quoted individually: it depends on your inventory sources, your environments and your change windows.

This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. Request a quote
Our commitment

Four commitments that matter for your estate

Your version map stays with youLocal inference or an isolated resource hosted in France; no inventory entrusted to a third party, no data used to train a model.
Data in France, under French lawYour inventories, cases and evidence: minimisation and location in France, an architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.
The owner keeps the decisionThe agent prepares worked-up cases and replayable changes, verifiable and editable; orchestration stays in simulation by default, and a real write requires a recorded human approval.
Human oversight & traceabilityEvery decision carries its author, date, reason and the policy version applied; the previous priority is kept after any recalculation, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Does the agent replace our vulnerability scanner or our asset management?
No. The scanner remains the source that observes, asset management remains the register of machines, and your operations team remains what deploys. The agent consumes their results when you give it access: it matches, explains, ranks and prepares the change. It owns no asset.
Can it deploy a patch automatically?
Orchestration runs in simulation by default: it shows what would be triggered, case by case. A real write requires, cumulatively, a confirmed asset and version, a patch from an approved source, a valid ticket and change, the required tests passed, a compliant window, an available rollback and a recorded human approval. The effect is declared achieved only after the next inventory is read back — not on the strength of the order sent.
How does it connect to our tools?
Through the exports you deposit, in the format you already produce, with their date. No direct connection to a scanner, a configuration database, a ticketing tool or a deployment tool is sold on this page: such a link is handled case by case, after a feasibility study, and is announced only once it is established and documented.
Which advisory sources are covered?
The ones you open to it, and they are named during scoping. No coverage of a public database or a vendor feed is announced here: each carries its own terms of use, quotas and redistribution policy, and a source is announced only with the licence held, the component that ingests it and a freshness measured over a named period. The set of sources retained appears in the quote.
What does it do when an asset's version is unknown?
It writes it down and draws the consequence. The case moves to “under investigation”, it gets no score — the absence of a score is information, a zero would send it to the bottom of the list — and closure is blocked, with the date on which the data is missing. In parallel, the agent drafts the evidence request to the operator or provider concerned: version in service, date of last deployment, and a dated exploitability statement.
And when no patch exists?
The case stays open and keeps working. The agent prepares a dated exception — exact scope, reason, described risk, compensating controls, owner, approver, expiry date, review and revocation conditions — and the asset's replacement plan alongside it. The exception expires and the case reopens; it never renews itself.
Does it run active scans, or penetration tests?
No. The agent works on the inventories and reports you open to it. No active scan outside a mandate, no exploitation of a vulnerability to confirm it, no proof of concept executed. That is in particular what makes an industrial scope workable: a scan on a running controller can disturb the process.
Does this page prove our compliance with any text?
No. Delegated Regulation (EU) 2024/1774 of 13 March 2024 carries, at its Article 10, “vulnerability and patch management” for the financial entities in scope of DORA; Regulation (EU) 2024/2847 on cyber resilience entered into force on 10 December 2024, its reporting obligations applying from 11 September 2026 and its main obligations from 11 December 2027 (European Commission official page, read on 07/09/2026). Directive (EU) 2022/2555 (NIS 2) requires a transposition that the French legislative file does not show as completed. Whether any of these texts applies to you, and on what basis, is checked entity by entity: the agent produces evidence usable in an audit, it issues no compliance finding.
Let's talk

Let us size the potential on your next batch of advisories

15 minutes to scope your inventory sources, your environments and your owners — hosted in France, supervised, no commitment.