Platform

One Platform. Continuous Security Intelligence.

Detection · Intelligence · Response · Vulnerability · Automation — and the controls that make agentic security safe to run in your environment.

Agentic AI

Security That Doesn't Stop at Detection.

Traditional tools identify problems. DIRVA's specialized agents pick up where detection stops — investigating, enriching, recommending, and, with approval, acting.

01Finding
Scanner outputCritical

CVE-2024-3094

Asset
build-runner-07
Package
xz-utils 5.6.1
CVSS
10.0

No context. No owner. No plan.

02Understanding
Enriched by DIRVAImmediate
  • Reachable on TCP/22 from partner VLAN
  • Exploited in the wild
  • Holds CI signing secrets
  • Owner: Platform Eng · window Tue

Exploitable, reachable, high-value.

03Human approval
Requires a personAwaitingApproved
Proposed actionPin xz-utils 5.4.6 · rotate runner tokens · restart sshd
ApproveReject

Nothing executes without this step. Every decision is logged.

04Acting
Executed & validatedResolved
  1. Change CHG-48213 opened
  2. Package pinned · tokens rotated
  3. Re-scan clean · exposure closed
  4. Evidence attached to finding

Closed loop. Full audit trail.

  • Vulnerability analysisExploitability, reachability, and business impact evaluated for every finding.
  • Security investigation & collaborationAgents query SIEM, EDR, cloud, and identity sources to build the full picture — and hand findings to each other.
  • Remediation recommendationsEnvironment-specific fixes with rollback steps and a validation check.
  • Repetitive security operationsHigh-volume, low-variance work handled by agents — triage, enrichment, ticketing, validation.

Vulnerability management

From Vulnerability Discovery to Remediation.

Every finding moves through a complete lifecycle — from discovery to validated closure, with a full evidence trail.

STEP 01

Discover

Asset discovered and enrolled. Software inventory, exposure, and ownership captured.

STEP 02

Analyze

DIRVA analyzes the vulnerability and its context: exploitability, reachability, and impact.

STEP 03

Prioritize

Risk and potential impact evaluated against the environment — not just a CVSS number.

STEP 04

Remediate

Recommended or automated remediation, with approvals and rollback built in.

STEP 05

Validate

Confirm remediation was successful and close the finding with evidence.

  • Endpoints & serversOperating systems, packages, and configuration weaknesses.
  • Applications & repositoriesApplication dependencies and software composition across development environments.
  • Cloud resourcesCloud misconfigurations and exposed services across providers.
  • Network infrastructureNetwork devices, exposed services, and segmentation gaps.
Finding · DIRVA-2411
CriticalCVE-2024-3094Exploitable

Backdoored compression library on internet-facing build host

Affected asset
build-runner-07 · 10.40.12.7
Risk level
Critical · CVSS 10.0
Potential impact
Remote code execution via SSH pre-auth; lateral movement into CI secrets.
Recommended action
Downgrade xz-utils to 5.4.6, rotate runner credentials, validate SSH integrity.
  • AnalyzeReachability confirmed. Asset exposed on TCP/22 from partner VLAN; vulnerable package version 5.6.1 present.
  • RemediateRemediation plan generated. Change ticket drafted with rollback steps; awaiting approval.
  • ValidateRe-scan scheduled post-change to confirm package version and service integrity.

Guardrails & safety

Autonomy With Guardrails. Always a Human in the Loop.

Agents propose; people approve; the platform enforces. Access controls, approval gates, and audit are internal to DIRVA — not bolted on, and not dependent on any external service.

  • Human in the loop, alwaysAny action with operational impact requires a person's approval before it executes. New deployments start recommend-only.
  • Agent identity & least-privilege accessEvery agent has its own identity, so every action is attributable. Agents run with scoped, per-action credentials, tool allow-lists, and environment boundaries — never a shared service account.
  • Role-based control for peopleWho can approve actions, change policy, or widen an agent's scope is governed by RBAC and logged.
  • No PII is ever shared with the LLMBefore any prompt reaches a model, DIRVA minimizes and redacts the finding inside the platform — no names, credentials, personal identifiers, or customer records. This applies to local and hosted models alike, and is enforced by the platform, not left to the model.
  • Enforced at the platform layerControls are evaluated by DIRVA's policy engine, not by the model. A prompt cannot grant an agent permissions it does not have.
  • Stop, rollback, auditOperators can halt any run. Plans carry rollback steps. Every proposal, decision, approval, and tool call is recorded with evidence.
Enforced inside the DIRVA platform
  • PII redactionFindings are minimized and redacted by the platform. No personal data ever reaches the LLM.
  • Agent proposesAn agent drafts an action — never executes directly.
  • Policy engineAgent identity verified; scope, tool allow-list, and least-privilege checks enforced by the platform.
  • Human approvalA person reviews and approves. Always present for actions with impact.
  • Scoped executionRuns with per-action credentials limited to the approved target.
  • Audit & validateEvery step logged with evidence; outcome validated and reversible.

Guardrails are native to DIRVA — PII redaction, the policy engine, approval workflow, credential scoping, and audit log run inside the appliance and cannot be bypassed by an agent, a prompt, or an integration.

Integrations & MCP

Connect the Security Stack.

DIRVA is an orchestration and intelligence layer — not another isolated product. It works with the tools you already run, through API, MCP, RAG, syslog, and webhooks.

Cloud SecurityDevSecOpsSIEMThreat IntelITSMEDR / XDRIdentityVulnerability MgmtData SecurityDiscovery AgentAGT-DSC · SCOPED IDENTITYAnalysis AgentAGT-ANL · SCOPED IDENTITYRemediation AgentAGT-REM · SCOPED IDENTITYValidation AgentAGT-VAL · SCOPED IDENTITYDIRVA AIORCHESTRATION
  • Endpoints, servers, cloud, containers, repos, network
  • Security applications · intelligence into DIRVA
  • DIRVA agents · each with its own identity & scoped credentials
  • Agent-to-agent handoffs · Discover → Analyze → Remediate → Validate
  • Actions, tickets & response out of DIRVA
APIMCPRAGSyslogWebhooks

MCP & API

Built for the agentic security ecosystem

DIRVA acts as a Model Context Protocol client, so any compatible MCP server — commercial, open-source, or built in-house — can become part of a DIRVA workflow without a custom connector.

For tools that don't expose an MCP server, DIRVA integrates directly through their APIs. Either way, tool access passes through the same policy engine and approval gates.

  • Security tools, cloud platforms, and ticketing systems through MCP servers.
  • REST and vendor APIs for tools without MCP support.
  • Internal knowledge and runbooks available to agents in context via RAG.
  • Bring your own MCP server for custom or in-house systems.
Security Tool · MCPCloud Platform · APIThreat Intelligence · MCPTicketing System · APIInternal Knowledge · RAGCustom MCP ServerDIRVA AIMCP · API CLIENTMODEL CONTEXT PROTOCOL · REST APIS

Enterprise deployment

AI Security. Under Your Control.

DIRVA Enterprise operates as an on-premises virtual appliance inside your environment — built for government, defense, intelligence, regulated industries, and security-conscious enterprises.

  • Customer-controlled environmentPrivate deployment on your infrastructure. Your data stays inside your boundary.
  • Controlled AI / model architectureLocal or private model support where configured. You decide which models run and where.
  • Reduced dependence on external SaaSCore operation does not route security data through third-party SaaS infrastructure.
  • DIRVA DesktopSecurity analysis for individual users and developers — availability to be announced.
Customer network boundary
DIRVA ApplianceOn-premises virtual appliance · customer-controlled
  • Servers
  • Endpoints
  • Applications
  • Cloud Resources
  • Security Tools
  • AI Models

Architecture

How DIRVA fits in.

Enterprise environment
  • Endpoints
  • Servers
  • Applications
  • Cloud
  • Repositories
  • Network Infrastructure
DIRVA AI Platform
  • Discovery
  • Vulnerability Intelligence
  • Agentic AI
  • RAG
  • MCP
  • Automation Engine
  • Remediation
Security ecosystem
  • SIEM
  • EDR
  • ITSM
  • Threat Intelligence
  • DevSecOps
  • Cloud Security

FAQ

Common questions.

DIRVA Enterprise is delivered as a virtual appliance for common hypervisors and private cloud environments. Contact us for current platform support.

Core operation is designed for controlled environments. Optional outbound connectivity (for example, threat intelligence feeds or updates) can be configured according to your policy.

DIRVA supports a controlled model architecture, including local or private model options where configured. Model selection is a deployment decision made with your team.

Only inside a narrow scope a person has explicitly pre-approved for low-risk, well-understood actions — and that scope can be revoked instantly. Actions with operational impact are approval-gated by default. Every run is logged.

In DIRVA's policy engine, inside the appliance. They are not implemented as instructions to the model, so they cannot be overridden by prompt content or by data an agent reads.

No. DIRVA never shares PII with the LLM. Findings are minimized and redacted by the platform before a prompt is constructed — personal identifiers, credentials, and customer records are stripped. This holds whether the model is local or hosted.

Get started

Move Beyond Reactive Security.

DIRVA AI helps security teams detect vulnerabilities, understand risk, respond faster, and automate repetitive security operations.