Coming soon
PatchGuard
Autonomous vulnerability patching that closes the gap between disclosure and remediation.
Security commitments are easy to make and hard to keep. Every framework you certify against — and every enterprise contract you sign — puts a clock on remediating known vulnerabilities. Engineering teams miss those clocks not because they don't care, but because patching competes with the roadmap: someone has to stop shipping features to chase down a dependency bump, verify it doesn't break anything, and push it through CI. PatchGuard will be an autonomous agent that closes that gap, so remediation deadlines stop depending on whoever has a free afternoon. If you're already working toward SOC 2 Readiness or a Cyber360 Assessment, PatchGuard is built to keep the remediation evidence those engagements depend on flowing automatically.
How It Will Work
Here's what PatchGuard will do:
- Learns Your Repositories, building an understanding of your codebase, dependencies, frameworks and conventions, so patches match how your team already writes code.
- Patches Safely, generating the minimal fix scoped to the affected code path, rather than a wholesale dependency bump that breaks three other things.
- Runs Your Tests First, executing your existing test suite before a patch is ever proposed; a change that breaks tests never reaches a reviewer.
- Clears Your CI/CD Pipeline, pushing through your existing pipeline, watching the checks, and fixing what it broke instead of handing you a red build.
- Resolves Issues Autonomously, iterating through regressions, lint failures and type errors until the pipeline is green.
- Keeps a Human in the Loop, arriving as a reviewable pull request with the vulnerability, the fix and the evidence. Nothing merges without approval.
- Produces Audit Evidence, recording CVE, severity, remediation date and test results, mapped to the control an auditor will ask about.
Every Framework Puts a Clock on Remediation
Whichever frameworks and contracts govern your business, patching known vulnerabilities is rarely optional, and it's almost always timed:
- SOC 2 (CC7.1) prescribes no fixed timeframe for remediation. Instead, you're held to the SLA stated in your own policy — which is precisely what auditors sample against. It's the most misunderstood point in the list: SOC 2 doesn't hand you a number, your own documented commitment becomes the number.
- PCI DSS 4.0 (Req 6.3.3) requires patches for critical and high-severity vulnerabilities to be installed within one month of release.
- ISO/IEC 27001:2022 (Annex A 8.8), technical vulnerability management, requires timely, evidenced remediation without specifying a fixed number.
- HIPAA Security Rule requires risk management and patching for systems handling PHI, again without a fixed number specified.
- FedRAMP sets critical and high-severity vulnerabilities at 30 days, moderate at 90 days, and low at 180 days.
- NIST SP 800-53 addresses this through SI-2 (flaw remediation) and RA-5 (vulnerability monitoring and scanning).
- CIS Controls v8 covers it under Control 7, Continuous Vulnerability Management.
- Cyber Essentials (UK) requires high and critical patches within 14 days.
On top of every framework, most enterprise customer agreements carry their own contractual SLAs — and those are often stricter than any framework above. PatchGuard is built to help your team meet those remediation SLAs and produce the evidence to prove it, not to promise compliance on its own; no framework is satisfied by a tool alone, only by the controls and evidence around it. For the wider control set those frameworks expect, pair PatchGuard with Product Security.
Join the Waitlist
PatchGuard isn't available yet. Tell us a little about your team and we'll let you know as soon as early access opens.


