Vulnerability assessment platform, designed in France

Automate the routine.
Let expertise lead.

Valdren is the software backbone of your Vulnerability Operations Center (VOC): it takes over the mechanical work of vulnerability assessment: imports, deduplication, enrichment, scoring context, reporting. Your experts keep what matters: judgment.

Deployed on-premise
up to fully offline operation
Valdren AI built in
our dedicated model, or yours if needed
Your data
stays within your infrastructure
Built on field experience in
  • Industry OT environments
  • Finance regulated sector
  • Insurance sensitive data
  • Defense sensitive networks
The problem

Where does your analysts' time go?

Every import restarts the same work: requalifying CVEs already seen, hunting advisories one by one, rescoring out of context, assembling a report by hand. None of these tasks requires an expert. Every one of them consumes one.

Day to day, without tooling

Triage restarted at every import

Each new import reopens CVEs that were already qualified. Without a memory of past decisions, the same triage happens again, campaign after campaign.

Scores without context

A base CVSS score ignores the asset's real exposure. When everything looks critical, nothing is truly prioritized.

Decentralized intelligence

USN, RHSA, NVD: advisories get hunted down by hand, advisory by advisory, CVE by CVE. Copy-paste becomes a workload of its own.

WITHOUT VALDREN Most of the time is absorbed by mechanical tasks
  • Import triage · 30%
  • Advisory hunting · 22%
  • Manual rescoring · 18%
  • Report formatting · 15%
  • High-value analysis · 15%
WITH VALDREN analysis and decisions take back the central place
  • Analysis and prioritization · 62%
  • Verdicts and decisions · 23%
  • Fix verification · 15%
Illustrative split: it varies with scope and team maturity.
Who does what

The mechanics go to the machine.
The judgment stays with you.

One rule shapes the product: Valdren prepares, your experts decide. Here is the split; the method below then walks through a campaign, move by move.

Valdren automates
machine time

Import and version

Scanner output lands as import v12. Every wave is kept, diffed and comparable.

Deduplicate and map

Findings are merged across assets and matched to your component inventory.

Enrich from advisories

Vendor advisories, references and fixed versions attached to each CVE, from feeds or imported files.

Pre-analyze with Valdren AI

Our model, purpose-built for vulnerability analysis, drafts an impact analysis per CVE. Need a different model? Any OpenAI-compatible API plugs in.

Flag what changed

New, fixed and score-shifted CVEs are surfaced so analysts start where it matters.

pipeline idle · 214 CVE prepared for review
Your experts decide
expert time

Impact verdicts

Affected, limited impact, not affected or to confirm: each verdict is documented and justified, per asset. Treatment status (to treat, scheduled, in progress or fixed) is tracked through to closure.

Score recontextualization

Adjust CVSS vectors to your real exposure. Base score stays visible, your context wins.

Prioritization and recommendations

Team discussion threads, decisions on record, remediation guidance that reflects your environment.

The principle
Every automated suggestion stays visible, attributable and reversible: the final decision is never made in your place.
The method

From import to report, without friction

A Valdren campaign comes down to four moves. Each one replaces hours of manual handling. None of them takes the decision away from the expert.

01

Import, without overwriting history

An OVAL scan or a plain CVE list. Valdren computes the differential: what appears, what is fixed, what stays put. Each import becomes a version, and past versions remain available read-only.

02

Enrichment arrives on its own

DSA, USN, RHSA and NVD advisories are synchronized locally and attached to each CVE: fixed versions, patches, vendor priorities. The Valdren model, purpose-built for vulnerability analysis, drafts a first reading in the asset's context.

03

A score that reflects your context

Describe an asset's role once: exposure, criticality, security requirements. Valdren reapplies the environmental metrics to every affected CVE, following the inheritance rule: library, machine, base vector.

04

Decide, record, export

Impact verdict, treatment status, comments: every decision is recorded with its author and date. The PDF, CSV, XLSX or JSON export reflects the exact state of the analysis, enrichments included.

Platform

Around the analysis, a real working tool

The method covers the core of the work; the platform surrounds it with what a team expects day to day: projects, overviews, accounts and settings.

Multi-project

One workspace per scope: client, system, campaign. Each project has its own imports, verdicts and history.

Campaign statistics

Severity breakdown, triage progress, evolution from one import to the next: the state of a scope reads at a glance.

Asset inventory

Machines and software components described once (role, exposure, criticality), then reused throughout the analysis.

Search and filters

Find a CVE by identifier, severity, status or asset. Filtered views double as the basis for scoped exports.

Accounts and roles

Every member works under their own identity: verdicts and comments are attributed, access is managed per project.

Per-project settings

Enrichment sources, AI model, scoring rules: each scope follows its own constraints.

Integrations

Integrates with your existing tools and processes

Valdren does not replace your scanners: it consumes their output. Fed continuously by vulnerability scanners, SBOM tools and CI/CD pipelines, or by files dropped in by hand when systems cannot talk to each other.

  • Native import of common scanner and SBOM formats
  • API and CLI for pipeline-driven imports on every build
  • File-based exchange for isolated or air-gapped segments
  • Exports to the formats your reporting chain expects
Sovereignty by design

Runs where your data is allowed to live

Designed in France for regulated and sensitive environments, Valdren deploys on your infrastructure. When constraints require it, it can rely on locally hosted AI models and receive vulnerability intelligence as files, with no outbound network access needed.

Deployment mode
Outbound access to public feeds, everything else stays local. No outbound network. Intelligence arrives as files.

On-premise, ready for your accreditation

Runs on your servers, in your racks, under your operating procedures, with no mandatory cloud dependency. Built for restricted, low-connectivity and sensitive contexts where every flow must be justified.

Local AI, or an external API if you choose

The Valdren model deploys on your infrastructure by default. If you opt for an external API, only anonymized prompts leave: asset names, IPs and identifiers are stripped first.

Locally hosted AI, isolated

The Valdren model runs entirely on your infrastructure. Prompts, assets and findings never leave the perimeter: no external API, in any direction.

Live public feeds, inbound only

Valdren pulls public CVE feeds, advisories and references. The flow is one-way inbound: nothing about your assets or findings ever goes the other way.

File-based intelligence

CVE descriptions, advisories and references import from signed files and are processed locally: no callbacks to online services, no outbound network.

Why Valdren

Built from the operator's side of the table

Valdren comes from years of running vulnerability assessments in industry, finance, insurance and defense: environments where a wrong call is expensive.

That experience shaped every workflow in the product: imports are versioned since scans arrive in waves; verdicts are set per asset, as context changes the answer; and file-based exchange stays possible where some networks never see the internet.

01

Nothing silent

Automation never overwrites a human decision. Suggestions are labeled as such and require an explicit call.

02

Nothing lost

Imports, scores and verdicts are versioned. You can always answer "what did we know, and when".

03

Nothing leaked

The product assumes your data is sensitive by default. Offline operation is a first-class mode, not a degraded one.

See it on your own scan data

A 45-minute working session with our team: bring an export from your scanner, leave with a first prioritized analysis.

contact@valdren.app
  • Deployment review included
    on-premise, isolated or air-gapped
  • Valdren AI included
    another model can be plugged in if your constraints require it
  • French-based team
    engineering and support