Skip to content

What is Basirah?

It's the vulnerability remediation platform we built when we got tired of watching 'remediated' tickets that hadn't actually fixed anything. Ingestion through to auditable evidence, nothing dropped. When Basirah marks a fix verified, it re-scanned the asset, probed the API, or validated the control. It didn't read a status field.

Execution intelligence
01/ 04

Bassistant proposes. You confirm.

Bassistant is the execution intelligence layer. It stays page-aware across the whole workflow, grounded in your findings, SLA clocks, verification outcomes, and evidence history. Ask 'what should we fix this week?' and it ranks by financial exposure, then cites the finding, risk score, or control behind every call. It drafts the remediation brief and proposes the next move. Nothing fires until an operator confirms.

  • Structured trigger context: it reads the finding, asset, and SLA state wherever you are.
  • Governed actions carry a full source trail. Preview the blast radius, route sensitive moves through approval.
  • Every proposal, confirmation, and action lands in the evidence package.
Prioritization
02/ 04

One queue that explains itself.

Basirah ranks work by exploit signals, business criticality, internet exposure, FAIR loss, SLA pressure, and exception status. Click any row and the trace tells you why it landed there.

  • Decision traces show KEV, EPSS, asset context, FAIR P95, SLA status, and exception state.
  • Remediation briefs require owner, change window, rollback note, validation method, and evidence checklist.
  • Risk acceptance stays time-bound, approved, and tied to compensating-control proof.
Fix Now Queue 5 active
#FindingFAIR lossSLA
9132CVE-2025-9132 — Postgres priv-esc on prod-db-east-2P95 $1.4M2d
9118Tomcat 10.1.x — RCE via crafted multipart payloadP95 $820k4d
9094OpenSSH stale-session re-use on bastion-prodP95 $310k6d
9081S3 bucket "exports-archive" — public ACL driftP95 $290k6d
9072Stripe webhook secret rotated, 3 services still pinnedP95 $86k9d
Risk quantification
03/ 04

Risk in dollars, not severity labels.

FAIR Monte Carlo gives you P50 and P95 annualised loss for every finding group. Drill into a single team or roll up to a board narrative. The financial clarity the audit committee expects.

  • What-if modelling forecasts the impact of remediation campaigns before you commit.
  • Side-by-side comparison: current exposure vs post-remediation projection.
  • Board-ready PDF export with executive summary and trend charts.
P95 · FAIR ¹ Annualised loss
$2.4 M ↗ now priced
P50 · expected Expected loss
$680 k ↗ board-ready
Forecast · top-10 campaign Post-remediation
−42 % ↘ post-remediation
Audit evidence
04/ 04

Auditors don't want screenshots. They want proof.

Your auditor receives a tamper-evident package — SHA-256 integrity hashes, checksum manifests, optional signed manifests for later verification. The timeline shows scan to sign-off in one read.

  • Managed deployments can use customer-controlled signing keys when enabled.
  • Control mappings for ISO 27001, SOC 2, NIST CSF, PCI DSS, NCA ECC, DORA, NIS2.
  • Attachment-safe ZIP and PDF exports with package, integrity, and delivery metadata.
Evidence package BAS-9132
  1. 08:14 Scan ingested qualys · run_2026_05_18
  2. 08:21 Owner assigned platform-data · sla 48h
  3. 09:02 Dispatched jira PROD-OPS-9132
  4. 11:47 Re-scanned independent · clean
  5. 11:48 Verified multi-scanner consensus
  6. 11:49 Signed sha-256 · 9a7f…be3d
Plus four more

The work between the work.

01

Independent verification

Source re-scan, independent scanner evidence, API probe, manual attestation, control validation. Failed verification returns to remediation with the method, actor, and evidence gap recorded.

02

SLA enforcement

Severity-based deadlines from the active policy contract. Breach logging with root-cause fields, exception context recorded in the SLA history.

03

Idempotent dispatch

Native connectors for Jira, ServiceNow, and Azure DevOps. Deduplication on (CVE × asset × scanner) so retries never spawn duplicate tickets.

04

Compliance mapping

Posture scoring per framework with drill-down by control. Gap analysis highlights unaddressed controls with remediation guidance.

Notes

  1. 1 Modelled (FAIR), sample finding set. Under 20% of programs quantify loss in dollars at all (Gartner). Basirah enforces your policy's SLA windows and verifies each fix.