Kervo AI
Platform/Resolve/AI Analyst
Kervo AI · Resolve

The work of a security analyst, on every finding.

AI Analyst investigates every vulnerability, exposure and misconfiguration, works out what it puts at risk, finds the fix and, once a human approves, pushes it. False positives close themselves. Real risks get fixed.

platform.kervo.ai / resolve / ai-analyst
Resolve / AI Analystliveacme-prodFINDING QUEUE142 todayHIGHCVE-2025-31255 · prod-db-01confirmed · escalatedHIGHLeaked credential · svc-deployconfirmed · key rotatedMEDPublic S3 bucket · logsconfirmed · fixedMEDOpen port 3389 · bastion-02false positive · closedLOWCVE-2023-4863 · cdn-edgenot reachable · acceptedHIGHAdmin role · ci-roleconfirmed · escalatedLOWTLS 1.0 · api.payco.iovendor · sent to TPRMTriaged automatically: 131 / 14211 escalatedINVESTIGATION · #482141sHIGHCVE-2025-31255 · prod-db-01 · PostgreSQL 14.2EVIDENCEAsset contextprod-db-01 · crown jewelReachabilityinternet → vpn-legacy → dbExploitpublic PoC · KEV listedCorrelatedsvc-deploy key leakedCompensating controlnone foundConfirmed · confidence 0.94Reachable from the internet through vpn-legacy, with a publicexploit and 2.1M customer rows behind it. Patch to 14.11.ACTIONSFix found · patch PostgreSQL to 14.11autoSEC-4821 opened · owner: platform teamautoPush patch to prod-db-01awaiting approval
Investigates like an analyst
reachability, exploitability, impact
Finds the fix
the specific change, its owner and what it might break
Pushes it after approval
nothing changes without a human yes
[ The problem ]

The problem with finding triage

Scanners, cloud tools and code analysis produce findings faster than anyone can check them properly. Each one needs the same questions answered: is it real, can an attacker reach it, what does it expose, and who owns the fix. Nobody has time to ask them three thousand times, so findings get skimmed or left in the backlog.

Most tooling just sorts findings by severity. A person still has to investigate, work out the fix, find the owner and get the change made.

[ What Kervo AI does ]

What Kervo AI does

Every finding goes to AI Analyst before it reaches a human. It pulls the asset's context from the inventory, checks whether the issue is actually present and reachable, looks for a public exploit or active exploitation, correlates with every other layer (a leaked credential, an overpermissioned role, an exposed port) and checks whether the asset sits on a known attack path.

Then it does what an analyst would do next. It works out the impact, meaning what the asset holds and what an attacker could reach from it, and finds the remediation: the patch version, configuration change or key rotation, with the owner and what the change might break.

Read more

False positives close with the reasoning attached. For confirmed risks, AI Analyst prepares the fix and, where an integration allows it, pushes it once a human approves. Otherwise it hands your team a ticket with the change spelled out. Your team makes the decision instead of doing the legwork.

[ Capabilities ]6 capabilities
01

End-to-end investigation

Vulnerabilities, exposures, misconfigurations and leaked credentials, each checked for whether it is real, reachable and exploitable, with asset context, cross-layer correlation and attack-path relevance. A finished investigation rather than another line in the backlog.

02

Impact analysis

What the asset holds, who depends on it, which attack paths run through it and which compliance controls it touches, so every verdict comes with the stakes spelled out.

03

Remediation, worked out

The specific fix for each confirmed finding: the patch version, configuration change or access revocation, with the owner and a note on what it might break.

04

Fixes pushed after approval

Where an integration allows it, AI Analyst applies the fix itself once a human approves: a configuration change, a key rotation, a patch. Where it can't, the fix goes to the owner as a ticket with everything needed to make the change.

05

Explainable verdicts and audit trail

Every conclusion shows what was checked, found and ruled out, and every approval and change is logged. Disagree and that feedback tunes the model for your environment.

06

Configurable guardrails

Which categories always need human review, who can approve which fixes, severity thresholds and escalation channels. Most teams start conservative and widen automation as the reasoning holds up.

[ How it works ]

How it works

AI Analyst operates over the same data model as everything else in Kervo AI, which gives it something to investigate with. When a finding lands on a host, it already knows what that host is, who can reach it, what changed, whether it is on a live attack path, and how similar findings were resolved before.

Nothing in your environment changes until someone approves it. Check the reasoning closely for the first few weeks, then less as it earns trust.

[ One data model ]

Why investigation needs the whole picture

A standalone triage tool sees only the finding and the scanner output. It can classify but not investigate, because investigating means asking about the environment: is this asset reachable, is this credential valid, does it lead somewhere that matters. In Kervo AI those answers live on the same graph as the finding.

See how this fits into Resolve
[ FAQ ]AI Analyst
What does AI Analyst do that a scanner doesn't?

A scanner reports that an issue exists. AI Analyst checks whether it is real in your environment, whether an attacker can reach and exploit it and what it would expose, then works out the fix and, once you approve, pushes it.

Will it close something it shouldn't?

Every verdict is explainable and auditable, and you configure which categories always require human review.

Does AI Analyst make changes in our environment?

Only after a human approves. Investigation is read-only. Where an integration supports it, AI Analyst applies the approved fix itself. Otherwise it hands the change to your team as a ticket with everything needed to make it.

How many investigations are included?

Essentials includes up to 500 a month. Professional and Enterprise are unlimited.

[ More in Resolve ]
Get started

Watch AI Analyst work a real finding.

Bring a vulnerability or exposure from your environment and we'll run it end to end: investigation, impact, the fix and the approval step.