Automate the routine.
Let expertise lead.
Valdren turns vulnerability data into analysis grounded in the real context of your assets. The machine prepares. Your experts decide.
- NIS2 vulnerability management
- DORA operational resilience
- LPM vital infrastructure
- CRA digital products
Where does your analysts' time go?
Every import restarts the same work: reassessing vulnerabilities you've already reviewed, hunting advisories one by one, rescoring out of context, assembling a report by hand. None of these tasks requires an expert. Every one of them consumes one.
Triage starts over with every import
Each new import reopens vulnerabilities that were already qualified. Without a memory of past decisions, the same triage happens again, campaign after campaign.
Scores without context
A base CVSS score ignores the asset's real exposure. When everything looks critical, nothing is truly prioritized.
Fragmented vulnerability intelligence
Advisories are scattered across vendors and distributions. They have to be tracked down, cross-referenced and consolidated manually, vulnerability by vulnerability.
Let the machine handle the repetitive work.
Your experts make the decisions.
The principle is simple: Valdren prepares, your experts decide. Here's how the work is divided; the next section walks through a campaign from import to report.
Import and version
Every import is kept, dated and comparable to the previous one.
Deduplicate and map
Findings are merged across assets and matched to your component inventory.
Enrich from advisories
Vendor advisories, references and fixed versions attached to each vulnerability, from feeds or imported files.
Pre-analyze with Valdren AI
Our model, trained for vulnerability analysis, proposes a reasoned verdict per vulnerability in the context of the asset. Prefer your own? Any OpenAI-compatible API plugs in.
Flag what changed
New, fixed and rescored vulnerabilities are surfaced so analysts start where it matters.
Impact verdicts
Affected, limited impact, not affected or to review: each verdict is documented and justified, per vulnerability. Treatment status (to treat, scheduled, in progress or fixed) is tracked through to closure.
Context-aware scoring
Adjust CVSS vectors to your real exposure. Base score stays visible, your context wins.
Prioritization and recommendations
Team discussion threads, decisions on record, remediation guidance that reflects your environment.
From import to report, without friction
A Valdren campaign follows four simple steps. Each one replaces hours of manual handling. None of them takes the decision away from the expert.
Import, without overwriting history
An OVAL scan or a plain CVE list. Valdren computes the differential: what's new, what's been fixed, and what remains unchanged. Each import becomes a version, and past versions remain available read-only.
Enrichment happens automatically
Vendor advisories and public catalogs are synchronized locally and attached to each CVE: fixed versions, patches, published severity. The Valdren model, purpose-built for vulnerability analysis, provides an initial assessment based on the asset's context.
A score that reflects your context
Describe an asset's role once: exposure, criticality, security requirements. Valdren reapplies the environmental metrics to every affected vulnerability, following the inheritance rule: library, machine, base vector.
Decide, record, export
Impact verdict, treatment status, comments: every decision is recorded with its author and date. The PDF, CSV, XLSX or JSON export reflects the exact state of the analysis, enrichments included.
Around the analysis, a real working tool
The method covers the core of the work; the platform surrounds it with what a team expects day to day: projects, overviews, accounts and settings.
Multi-project
One workspace per scope: client, system, campaign. Each project has its own imports, verdicts and history.
Campaign statistics
Track severity, analysis progress, and changes from one import to the next throughout the campaign.
Asset inventory
Your experts document machines and software components, bringing their context to every analysis.
Built-in vulnerability database
Vendor advisories, public catalogs and known-exploited listings, synchronized locally and available at any time.
Accounts and roles
Every member works under their own identity: verdicts and comments are attributed, access is managed per project.
Per-project settings
LLM module, prompt anonymization policy, read-only lock: each scope follows its own constraints.
Integrates with your existing tools and processes
Valdren does not replace your scanners; it consumes their output. It can ingest data continuously from vulnerability scanners, SBOM tools and CI/CD pipelines, or from manually transferred files when systems cannot communicate directly.
- Native import of common scanner and SBOM formats
- API and CLI to automate imports from your CI/CD pipelines
- File-based exchange for isolated or air-gapped segments
- Exports in the formats your reporting workflows already use
Runs where your data is allowed to live
Designed in France for regulated and sensitive environments, Valdren deploys on your infrastructure. When constraints require it, it can rely on locally hosted AI models and receive vulnerability intelligence as files, with no outbound network access needed.
On-premise, built for regulated environments
Runs on your servers, in your racks, under your operating procedures, with no mandatory cloud dependency. Built for restricted, low-connectivity and sensitive contexts where every flow must be justified.
Local AI, or an external API if you choose
The Valdren model deploys on your infrastructure by default. If you opt for an external API, only anonymized prompts leave: asset names, IPs and identifiers are stripped first.
Local AI, isolated
The Valdren model runs entirely on your infrastructure. Prompts, assets and findings never leave the perimeter: no external API, in any direction.
Public feeds, inbound only
Valdren pulls public CVE feeds, advisories and references. The flow is one-way inbound: nothing about your assets or findings ever goes the other way.
File-based intelligence
CVE descriptions, advisories and references import from signed files and are processed locally: no callbacks to online services, no outbound network.
Built by the people who run the assessments
Valdren comes from years spent analyzing vulnerabilities, and one simple belief: without context, it is hard to tell what really matters.
That experience shaped every workflow in the product: imports are versioned because scans arrive in waves; each asset carries a description of how it is used, as context changes the answer; and file-based exchange stays possible where some networks never see the internet.
Nothing silent
Automation never overwrites a human decision. Suggestions are clearly identified and require an explicit analyst decision.
Nothing lost
Imports, scores and verdicts are versioned. You can always answer "what did we know, and when".
Nothing leaked
The product assumes your data is sensitive by default. Offline operation is a first-class mode, not a degraded one.
See Valdren on your own data
A working session with our team: bring an export from your scanner, leave with a first prioritized analysis.
- ✓Deployment review included
on-premise, isolated or air-gapped - ✓Valdren AI model
trained for vulnerability analysis - ✓French-based team
engineering and support