Platform
One Platform. Continuous Security Intelligence.
Detection · Intelligence · Response · Vulnerability · Automation — and the controls that make agentic security safe to run in your environment.
Agentic AI
Security That Doesn't Stop at Detection.
Traditional tools identify problems. DIRVA's specialized agents pick up where detection stops — investigating, enriching, recommending, and, with approval, acting.
CVE-2024-3094
- Asset
- build-runner-07
- Package
- xz-utils 5.6.1
- CVSS
- 10.0
No context. No owner. No plan.
- Reachable on TCP/22 from partner VLAN
- Exploited in the wild
- Holds CI signing secrets
- Owner: Platform Eng · window Tue
Exploitable, reachable, high-value.
Nothing executes without this step. Every decision is logged.
- Change CHG-48213 opened
- Package pinned · tokens rotated
- Re-scan clean · exposure closed
- Evidence attached to finding
Closed loop. Full audit trail.
- Vulnerability analysisExploitability, reachability, and business impact evaluated for every finding.
- Security investigation & collaborationAgents query SIEM, EDR, cloud, and identity sources to build the full picture — and hand findings to each other.
- Remediation recommendationsEnvironment-specific fixes with rollback steps and a validation check.
- Repetitive security operationsHigh-volume, low-variance work handled by agents — triage, enrichment, ticketing, validation.
Vulnerability management
From Vulnerability Discovery to Remediation.
Every finding moves through a complete lifecycle — from discovery to validated closure, with a full evidence trail.
Discover
Asset discovered and enrolled. Software inventory, exposure, and ownership captured.
Analyze
DIRVA analyzes the vulnerability and its context: exploitability, reachability, and impact.
Prioritize
Risk and potential impact evaluated against the environment — not just a CVSS number.
Remediate
Recommended or automated remediation, with approvals and rollback built in.
Validate
Confirm remediation was successful and close the finding with evidence.
- Endpoints & serversOperating systems, packages, and configuration weaknesses.
- Applications & repositoriesApplication dependencies and software composition across development environments.
- Cloud resourcesCloud misconfigurations and exposed services across providers.
- Network infrastructureNetwork devices, exposed services, and segmentation gaps.
Backdoored compression library on internet-facing build host
- AnalyzeReachability confirmed. Asset exposed on TCP/22 from partner VLAN; vulnerable package version 5.6.1 present.
- RemediateRemediation plan generated. Change ticket drafted with rollback steps; awaiting approval.
- ValidateRe-scan scheduled post-change to confirm package version and service integrity.
Guardrails & safety
Autonomy With Guardrails. Always a Human in the Loop.
Agents propose; people approve; the platform enforces. Access controls, approval gates, and audit are internal to DIRVA — not bolted on, and not dependent on any external service.
- Human in the loop, alwaysAny action with operational impact requires a person's approval before it executes. New deployments start recommend-only.
- Agent identity & least-privilege accessEvery agent has its own identity, so every action is attributable. Agents run with scoped, per-action credentials, tool allow-lists, and environment boundaries — never a shared service account.
- Role-based control for peopleWho can approve actions, change policy, or widen an agent's scope is governed by RBAC and logged.
- No PII is ever shared with the LLMBefore any prompt reaches a model, DIRVA minimizes and redacts the finding inside the platform — no names, credentials, personal identifiers, or customer records. This applies to local and hosted models alike, and is enforced by the platform, not left to the model.
- Enforced at the platform layerControls are evaluated by DIRVA's policy engine, not by the model. A prompt cannot grant an agent permissions it does not have.
- Stop, rollback, auditOperators can halt any run. Plans carry rollback steps. Every proposal, decision, approval, and tool call is recorded with evidence.
- PII redactionFindings are minimized and redacted by the platform. No personal data ever reaches the LLM.
- Agent proposesAn agent drafts an action — never executes directly.
- Policy engineAgent identity verified; scope, tool allow-list, and least-privilege checks enforced by the platform.
- Human approvalA person reviews and approves. Always present for actions with impact.
- Scoped executionRuns with per-action credentials limited to the approved target.
- Audit & validateEvery step logged with evidence; outcome validated and reversible.
Guardrails are native to DIRVA — PII redaction, the policy engine, approval workflow, credential scoping, and audit log run inside the appliance and cannot be bypassed by an agent, a prompt, or an integration.
Integrations & MCP
Connect the Security Stack.
DIRVA is an orchestration and intelligence layer — not another isolated product. It works with the tools you already run, through API, MCP, RAG, syslog, and webhooks.
- Endpoints, servers, cloud, containers, repos, network
- Security applications · intelligence into DIRVA
- DIRVA agents · each with its own identity & scoped credentials
- Agent-to-agent handoffs · Discover → Analyze → Remediate → Validate
- Actions, tickets & response out of DIRVA
MCP & API
Built for the agentic security ecosystem
DIRVA acts as a Model Context Protocol client, so any compatible MCP server — commercial, open-source, or built in-house — can become part of a DIRVA workflow without a custom connector.
For tools that don't expose an MCP server, DIRVA integrates directly through their APIs. Either way, tool access passes through the same policy engine and approval gates.
- Security tools, cloud platforms, and ticketing systems through MCP servers.
- REST and vendor APIs for tools without MCP support.
- Internal knowledge and runbooks available to agents in context via RAG.
- Bring your own MCP server for custom or in-house systems.
Enterprise deployment
AI Security. Under Your Control.
DIRVA Enterprise operates as an on-premises virtual appliance inside your environment — built for government, defense, intelligence, regulated industries, and security-conscious enterprises.
- Customer-controlled environmentPrivate deployment on your infrastructure. Your data stays inside your boundary.
- Controlled AI / model architectureLocal or private model support where configured. You decide which models run and where.
- Reduced dependence on external SaaSCore operation does not route security data through third-party SaaS infrastructure.
- DIRVA DesktopSecurity analysis for individual users and developers — availability to be announced.
- Servers
- Endpoints
- Applications
- Cloud Resources
- Security Tools
- AI Models
Architecture
How DIRVA fits in.
- Endpoints
- Servers
- Applications
- Cloud
- Repositories
- Network Infrastructure
- Discovery
- Vulnerability Intelligence
- Agentic AI
- RAG
- MCP
- Automation Engine
- Remediation
- SIEM
- EDR
- ITSM
- Threat Intelligence
- DevSecOps
- Cloud Security
FAQ
Common questions.
DIRVA Enterprise is delivered as a virtual appliance for common hypervisors and private cloud environments. Contact us for current platform support.
Core operation is designed for controlled environments. Optional outbound connectivity (for example, threat intelligence feeds or updates) can be configured according to your policy.
DIRVA supports a controlled model architecture, including local or private model options where configured. Model selection is a deployment decision made with your team.
Only inside a narrow scope a person has explicitly pre-approved for low-risk, well-understood actions — and that scope can be revoked instantly. Actions with operational impact are approval-gated by default. Every run is logged.
In DIRVA's policy engine, inside the appliance. They are not implemented as instructions to the model, so they cannot be overridden by prompt content or by data an agent reads.
No. DIRVA never shares PII with the LLM. Findings are minimized and redacted by the platform before a prompt is constructed — personal identifiers, credentials, and customer records are stripped. This holds whether the model is local or hosted.
Get started
Move Beyond Reactive Security.
DIRVA AI helps security teams detect vulnerabilities, understand risk, respond faster, and automate repetitive security operations.