From CVE noise to a defensible decision.
BrunoSan connects vulnerabilities, products, vendors, exploit evidence, KEV, EPSS, CVSS and sources into one traceable Decision State for agents and security teams.
How BrunoSan Cyber thinks.
Raw threat signals move through a six-stage evidence chain. Every stage remains inspectable, every source stays attached, and uncertainty is never promoted into certainty.
Affected Products
Evidence Signals
Corroboration
Decision State
Recommended Action
Decision Graph & Evidence Matrix.
Not a decorative web of dots. A security operator sees the exact route from vendor and product to CVE, evidence, corroboration and action—plus a comparable matrix of the current decision objects.
Decision Graph
Evidence Matrix
Live contract · 2026-07-12| CVE | CVSS | EPSS | KEV | PoC | Patch | Sources | Decision | Action |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59856 | 8.4 | 0.2% | No | Yes | Yes | 2 | WATCH | Watch |
| CVE-2026-13777 | 8.8 | 0.3% | No | No | No | 2 | MONITOR | Monitor |
| CVE-2026-20213 | 7.5 | 0.5% | No | No | No | 2 | MONITOR | Monitor |
One vocabulary for action.
Advisory never becomes patch evidence. PoC never becomes active exploitation. Unknown stays unknown.
Confirmed exploitation with no qualifying patch or mitigation evidence.
Confirmed exploitation plus qualifying patch evidence.
Confirmed exploitation, no qualifying patch, but qualifying mitigation evidence.
Proof-of-concept evidence without confirmed active exploitation.
Advisory-only or low-signal evidence that does not justify escalation.
The evidence contract is insufficient for a defensible decision.
The current publishable object.
Publishing is fail-closed. A Decision Brief enters the queue only when the decision CVE, product context, confidence floor and independent-source gate are satisfied.
CVE-2026-59856
Independent sources: 2. Published Decision Briefs: 1.
Inspect Decision BriefWhat the system refuses to fake.
Useful cyber intelligence can show the object, evidence, source and rule behind every recommendation.
Is BrunoSan Cyber a vulnerability scanner?
No. It is an intelligence and decision layer. Inventory assessment can match supplied assets, but BrunoSan does not scan customer infrastructure.
Does KEV automatically mean patch now?
No. KEV proves known exploitation. The final state also separates patch evidence, mitigation evidence and inventory match.
Can the MCP explain its decision?
Yes. Decision tools return evidence, confidence, recommended action and explicit change conditions.