Kervo AI
[ The loop · Resolve ]
Kervo AI · Resolve

Fix what matters. Shut down what's live.

AI Analyst does the work of a security analyst on every finding: it investigates, works out the impact, finds the fix and pushes it once a human approves. Guided remediation covers everything Evaluate ranked.

platform.kervo.ai / resolve / remediation
Resolve / Remediationliveacme-prodAI ANALYSTresolvedHIGHCVE-2025-31255 · prod-db-01Reachable · from internetExploit · public PoCAttack path · AP-118Confirmed. Fix ready to approve.Awaiting approval · #482141sRISK SCORE30 days7241-31 after fixREMEDIATION13 openTo do6CVE-2025-31255criticaldue Jun 2CVE-2012-2750highdue Jun 4In progress3CVE-2025-9074highpatchingIAM · prod-deploycriticalrotatingVerified4CVE-2026-4688criticalrescanneds3-backup-prodhighrescannedGuided fixes attached to every card
First-pass triage handled automatically
full investigation, not sorting
Escalations arrive with the work done
evidence, correlation, reasoning
Fixes ranked by paths closed
remediation that moves the risk score
[ Products in Resolve ]1 pages
[ The problem ]

Why this stage exists

Two things eat a security team's week. Triage: findings arrive faster than anyone can check them, so they get skimmed. And remediation gruntwork: someone still has to work out the actual fix, who owns the system and what it might break.

Most tooling just sorts findings by severity. A person still does the investigation.

[ What Kervo AI does here ]

What Kervo AI does here

Every finding goes to AI Analyst before a human. It pulls asset context from the inventory, checks whether the issue is real and reachable, correlates signals across every other layer and checks for a known attack path. Then it works out the impact, finds the fix and reaches a verdict: a false positive closed with reasoning, or a confirmed risk with the fix ready for a human to approve.

Every finding Evaluate ranked comes with the specific change, the systems affected, the controls satisfied and the attack paths collapsed. "Close four paths to your customer database" beats "severity high".

[ Capabilities ]4 in this stage
01

AI Analyst: investigation to approved fix

The work of a security analyst on every finding: is it real, can an attacker reach it, what does it put at risk, and what is the fix. Where an integration allows, AI Analyst pushes the fix once a human approves. Your analysts start at the decision.

02

Guided remediation

The specific fix for every ranked finding, with affected systems, compliance controls touched, attack paths collapsed and a sense of what it might break. Findings route straight into your ticketing system with that context attached.

03

Orchestrated response

Fixes that need a person to approve, not to carry out: rotate a key when a credential surfaces, apply a configuration change, open a ticket with the owner. Nothing runs without approval unless you choose to automate a category. The default is conservative.

04

Before-and-after risk scoring

Every path and finding carries a score that updates as fixes land, so you can see which remediation moved the number. A trend line from real data instead of a count of closed tickets.

[ How it works ]

How it works

AI Analyst runs on the same data model as everything else in Kervo AI, which gives it something to investigate with. When a finding lands on a host, it already knows what that host is, who can reach it, what changed, whether it is on a live attack path, and how similar findings were resolved before.

Verdicts are explainable by design: what was checked, what was found, what was ruled out and why. Disagree, and that feedback tunes the model for your environment.

[ Where it sits in the loop ]

Where it sits in the loop

Resolve closes the issue. It does not prove it stayed closed, or that your controls are working. Validate does that: controls checked continuously, evidence collected automatically, drift caught before an auditor finds it.

[ FAQ ]Resolve
What does AI Analyst do that a scanner doesn't?

A scanner reports that an issue exists. AI Analyst checks whether it is real in your environment, whether an attacker can reach and exploit it and what it would expose, then works out the fix and, once you approve, pushes it.

Will it close something it shouldn't?

Every verdict is explainable and auditable, and you configure which categories always require human review. Most teams start conservative and widen automation as the reasoning holds up.

Does Kervo AI make changes in our environment automatically?

Only after a human approves, fix by fix, unless you choose to automate a category. Discovery and analysis are read-only throughout.

How does remediation handle systems we don't own?

Findings on vendor infrastructure route to your vendor risk workflow with the evidence needed to raise them, rather than into your patch queue.

[ The whole loop ]
Get started

Watch AI Analyst work a real finding.

Bring a vulnerability or exposure from your environment and we'll run it end to end: investigation, impact, the fix and the approval step.