Vulnerability assessment platform, designed in France

Automate the routine.
Let expertise lead.

Valdren turns vulnerability data into analysis grounded in the real context of your assets. The machine prepares. Your experts decide.

On-premise
from connected to air‑gapped
Valdren AI model
trained for vulnerability analysis
Your data
stays within your infrastructure
Helps meet regulatory requirements
  • NIS2 vulnerability management
  • DORA operational resilience
  • LPM vital infrastructure
  • CRA digital products
The problem

Where does your analysts' time go?

Every import restarts the same work: reassessing vulnerabilities you've already reviewed, hunting advisories one by one, rescoring out of context, assembling a report by hand. None of these tasks requires an expert. Every one of them consumes one.

Day to day, without tooling

Triage starts over with every import

Each new import reopens vulnerabilities that were already qualified. Without a memory of past decisions, the same triage happens again, campaign after campaign.

Scores without context

A base CVSS score ignores the asset's real exposure. When everything looks critical, nothing is truly prioritized.

Fragmented vulnerability intelligence

Advisories are scattered across vendors and distributions. They have to be tracked down, cross-referenced and consolidated manually, vulnerability by vulnerability.

WITHOUT VALDREN Most of the time is absorbed by mechanical tasks
  • Import triage · 30%
  • Advisory hunting · 22%
  • Manual rescoring · 18%
  • Report formatting · 15%
  • High-value analysis · 15%
WITH VALDREN Analysis and decision-making move back to the center
  • Analysis and prioritization · 62%
  • Verdicts and decisions · 23%
  • Fix verification · 15%
Illustrative split: it varies with scope and team maturity.
Who does what

Let the machine handle the repetitive work.
Your experts make the decisions.

The principle is simple: Valdren prepares, your experts decide. Here's how the work is divided; the next section walks through a campaign from import to report.

Valdren automates
machine time

Import and version

Every import is kept, dated and comparable to the previous one.

Deduplicate and map

Findings are merged across assets and matched to your component inventory.

Enrich from advisories

Vendor advisories, references and fixed versions attached to each vulnerability, from feeds or imported files.

Pre-analyze with Valdren AI

Our model, trained for vulnerability analysis, proposes a reasoned verdict per vulnerability in the context of the asset. Prefer your own? Any OpenAI-compatible API plugs in.

Flag what changed

New, fixed and rescored vulnerabilities are surfaced so analysts start where it matters.

processing complete · 214 CVEs ready for review
Your experts decide
expert time

Impact verdicts

Affected, limited impact, not affected or to review: each verdict is documented and justified, per vulnerability. Treatment status (to treat, scheduled, in progress or fixed) is tracked through to closure.

Context-aware scoring

Adjust CVSS vectors to your real exposure. Base score stays visible, your context wins.

Prioritization and recommendations

Team discussion threads, decisions on record, remediation guidance that reflects your environment.

The principle
Every automated suggestion stays visible, attributable and reversible: the final decision always remains with your team.
The method

From import to report, without friction

A Valdren campaign follows four simple steps. Each one replaces hours of manual handling. None of them takes the decision away from the expert.

01

Import, without overwriting history

An OVAL scan or a plain CVE list. Valdren computes the differential: what's new, what's been fixed, and what remains unchanged. Each import becomes a version, and past versions remain available read-only.

02

Enrichment happens automatically

Vendor advisories and public catalogs are synchronized locally and attached to each CVE: fixed versions, patches, published severity. The Valdren model, purpose-built for vulnerability analysis, provides an initial assessment based on the asset's context.

03

A score that reflects your context

Describe an asset's role once: exposure, criticality, security requirements. Valdren reapplies the environmental metrics to every affected vulnerability, following the inheritance rule: library, machine, base vector.

04

Decide, record, export

Impact verdict, treatment status, comments: every decision is recorded with its author and date. The PDF, CSV, XLSX or JSON export reflects the exact state of the analysis, enrichments included.

Platform

Around the analysis, a real working tool

The method covers the core of the work; the platform surrounds it with what a team expects day to day: projects, overviews, accounts and settings.

Multi-project

One workspace per scope: client, system, campaign. Each project has its own imports, verdicts and history.

Campaign statistics

Track severity, analysis progress, and changes from one import to the next throughout the campaign.

Asset inventory

Your experts document machines and software components, bringing their context to every analysis.

Built-in vulnerability database

Vendor advisories, public catalogs and known-exploited listings, synchronized locally and available at any time.

Accounts and roles

Every member works under their own identity: verdicts and comments are attributed, access is managed per project.

Per-project settings

LLM module, prompt anonymization policy, read-only lock: each scope follows its own constraints.

Integrations

Integrates with your existing tools and processes

Valdren does not replace your scanners; it consumes their output. It can ingest data continuously from vulnerability scanners, SBOM tools and CI/CD pipelines, or from manually transferred files when systems cannot communicate directly.

  • Native import of common scanner and SBOM formats
  • API and CLI to automate imports from your CI/CD pipelines
  • File-based exchange for isolated or air-gapped segments
  • Exports in the formats your reporting workflows already use
Sovereignty by design

Runs where your data is allowed to live

Designed in France for regulated and sensitive environments, Valdren deploys on your infrastructure. When constraints require it, it can rely on locally hosted AI models and receive vulnerability intelligence as files, with no outbound network access needed.

Deployment mode
Outbound access to public feeds, everything else stays local. No outbound network access. Intelligence arrives as files.

On-premise, built for regulated environments

Runs on your servers, in your racks, under your operating procedures, with no mandatory cloud dependency. Built for restricted, low-connectivity and sensitive contexts where every flow must be justified.

Local AI, or an external API if you choose

The Valdren model deploys on your infrastructure by default. If you opt for an external API, only anonymized prompts leave: asset names, IPs and identifiers are stripped first.

Local AI, isolated

The Valdren model runs entirely on your infrastructure. Prompts, assets and findings never leave the perimeter: no external API, in any direction.

Public feeds, inbound only

Valdren pulls public CVE feeds, advisories and references. The flow is one-way inbound: nothing about your assets or findings ever goes the other way.

File-based intelligence

CVE descriptions, advisories and references import from signed files and are processed locally: no callbacks to online services, no outbound network.

Why Valdren

Built by the people who run the assessments

Valdren comes from years spent analyzing vulnerabilities, and one simple belief: without context, it is hard to tell what really matters.

That experience shaped every workflow in the product: imports are versioned because scans arrive in waves; each asset carries a description of how it is used, as context changes the answer; and file-based exchange stays possible where some networks never see the internet.

01

Nothing silent

Automation never overwrites a human decision. Suggestions are clearly identified and require an explicit analyst decision.

02

Nothing lost

Imports, scores and verdicts are versioned. You can always answer "what did we know, and when".

03

Nothing leaked

The product assumes your data is sensitive by default. Offline operation is a first-class mode, not a degraded one.

See Valdren on your own data

A working session with our team: bring an export from your scanner, leave with a first prioritized analysis.

contact@valdren.app
  • Deployment review included
    on-premise, isolated or air-gapped
  • Valdren AI model
    trained for vulnerability analysis
  • French-based team
    engineering and support