Documentation menu

Guides

AI triage

Let an AI propose triage decisions from your deployment profile — you review and decide.

Triaging hundreds of findings by hand is slow, and most of the work is reading advisories to answer the same few questions: Does this only affect Windows? Is it only reachable in a browser? Does an attacker need network access? AI triage answers those questions for you and proposes a decision. A person always decides: a suggestion never becomes a triage decision until someone accepts it.

Turning it on

AI triage is off by default for every project, because it sends data to an AI provider. Owners and admins of the organization can change it on the project’s AI triage tab.

Mode What happens
Off No data is sent to the AI provider.
On request Reviewers request a suggestion per finding, or for all open findings at once.
Automatic New, untriaged findings get a suggestion after every analysis. Each one still needs a review.

Minimum severity limits which findings are evaluated in bulk and in automatic mode: critical only, high and above, medium and above (default), or all scored findings. Actively exploited findings are always evaluated, whatever their score, and they go first.

The deployment profile

The AI can only rule a finding out if it knows how your software runs. Describe it on the AI triage tab:

Field Options
Exposure Reachable from the internet · Internal network only · Offline / no network input
Runs as Server / service · CLI / local tool · Library used by others · Browser / frontend bundle · Build tooling
Operating system Linux · Windows · macOS · Any / several
Notes Free text, used for the written explanation only

Set project-wide defaults and override them per artifact — your API image and your browser bundle run very differently. Without a profile, suggestions are capped at low confidence, because almost nothing can be ruled out.

How a suggestion is made

  1. Facts first, no AI involved. A withdrawn advisory, or a component your SBOM marks as development-only, is proposed as not affected right away.
  2. Four questions about the advisory. The AI answers each from a fixed set of options: Is it limited to an operating system? In which kind of use is the vulnerable code reached? Does exploitation need attacker-controlled input? Must a non-default option be enabled? Each answer comes with a confidence.
  3. Rules decide, not the AI. Fixed rules combine the answers with your profile. A Windows-only flaw on a Linux server, a browser-only flaw in a CLI tool, or a network attack on an offline system becomes not affected with the matching OpenVEX justification. If a relevant answer is unclear, the suggestion is under investigation and lists the questions you need to check. Otherwise it is affected.
  4. Written statements. The AI writes the reasoning, impact and action statements in English, ready for your VEX document.

Reviewing

Suggestions appear in the finding’s side sheet and can be filtered on the Findings tab (suggested).

  • Accept & save turns the suggestion into your decision. Edit the statements first if you like.
  • Reject it with an optional reason (wrong status, right status but wrong reasoning, missing context about our use, other). Your feedback improves future versions.
  • Request again asks for a fresh evaluation.

A suggestion is marked stale when the advisory was updated or your deployment profile changed after it was made. Stale suggestions are not recomputed automatically — request them again when you’re ready.

Accepting in bulk

You can select several suggestions and accept them at once, but only those that are safe to wave through: not affected, high confidence, not stale, and based on hard facts — a withdrawn advisory, a development-only dependency, or an operating system, runtime or exposure mismatch with your profile. Anything that needs judgement has to be reviewed one by one, and so does every suggestion for an actively exploited vulnerability: a wrong not affected there would hide a reporting duty under the CRA. Such suggestions start their reasoning with the exploitation status; the model itself never sees it.

What is sent to the AI provider

Only public data about the vulnerability: the advisory text, the affected package name and version, and — for the written statements — the decision and your deployment profile, including its notes. Your SBOM, other components and your source code are never sent. Answers about an advisory depend only on public data and are reused, so evaluating the same advisory again doesn’t cost twice.

Budget

Each organization has a monthly AI budget that comes with its plan; the AI triage tab shows how much of it is used. When it runs out, new requests are refused until the next calendar month.