Meridian
Open console

Focus on the exposures that matter most — with clarity on why.

Meridian brings together exposure data from across the technology estate, applies a transparent and explainable prioritisation model, and helps teams progress material exposures through governed validation and remediation.

8sources integrated across the estate
9transparent factors informing each score
1human decision for every consequential action
EXP-0417OpenSSH signal-handler race condition (regreSSHion) on dmz-sftp-01
Critical
Base scoreCVSS 3.1 · CVE-2024-6387 · NVD
8.1
Exploit availableFunctional public exploit · NVD
+0.5
Internet-facingReachable from the internet · Defender EASM
+0.5
Business-critical assetCustomer Order Exchange · Very High
+1.0
Compensating controlSSH restricted to the jump host · ServiceNow CMDB
1.0
Risk scoreL1 · due within 7 days of first found
9.1
Reported byQVQualys VMDRCFCrowdStrike FalconMicrosoft Defender EASM
Remediation owner · Platform Engineering

A continuous approach to exposure management.

Meridian supports a continuous, evidence-led programme across the five stages of CTEM, connecting each decision to the context produced before it.

  1. 01Scope

    Define business services, asset criticality and rules of engagement before activity begins.

  2. 02Discover

    Consolidate and deduplicate asset and finding data from ServiceNow, Qualys, Wiz, Entra, Defender EASM, CrowdStrike and Argus, while retaining provenance.

  3. 03Prioritise

    Assess each finding through a deterministic model and elevate material risk as an exposure.

  4. 04Validate

    Validate exposures in a controlled environment and retain evidence before remediation begins.

  5. 05Mobilise

    Assign accountability, initiate the SLA and verify closure through re-detection.

Integrate the technology landscape. Strengthen the risk view.

Meridian integrates information from the CMDB, security tools and public intelligence feeds to create a consolidated view of the estate while retaining record-level provenance. Connectors can be aligned to the organisation's existing technology landscape.

8connected sources
4public intelligence feeds
ServiceNow
ServiceNow CMDB
Configuration items, ownership, business services and support groupsEvery 15 min
Qualys VMDR
Host detections and KnowledgeBase definitionsEvery 4 h, delta
Wiz
Wiz
Cloud resources, vulnerability findings and toxic-combination issuesHourly
CrowdStrike
CrowdStrike Falcon
Sensor inventory, Spotlight vulnerabilities and internet exposureEvery 2 h
Brinqa
Brinqa
Gold records already consolidated from your scanners, with Brinqa risk scores, ownership clusters, SLA state and ticketsAfter each orchestration
Microsoft Entra ID
Users, service principals, privileged roles and risk signalsEvery 30 min
Microsoft Defender EASM
Internet-facing hosts, domains, certificates and exposed servicesDaily
Argus
ArgusEY
Repository and application findings, joined to the assets that run themOn commit
Intelligence that supports informed decisions.

Public feeds provide exploitation status, prediction scores and CVSS data. Each CVE retains the corresponding KEV date and EPSS percentile, enabling teams to verify the intelligence independently.

CISA KEVExploited in the wild · KEV due dateCISA · Every 2 h
FIRST EPSSEPSS probability · percentileFIRST.org · Daily
NVDCVSS base · vector · CWENIST · Hourly
MITRE ATT&CKTechnique identifiers on pathsMITRE · On release
Also in the connector library
TenableTenableRapid7Rapid7Microsoft SentinelSnykGitHubGitLabSplunkOktaCyberArkCyberArkSailPointSailPointPalo Alto NetworksFortinetZscalerZscalerCloudflareCloudflareOrca SecurityOrca SecurityAqua SecurityAqua SecurityCheckmarxCheckmarxVeracodeVeracodeSentinelOneSentinelOneJiraKubernetesKubernetesDatadogDatadogPagerDutyPagerDutyElastic

Transparent prioritisation. Defensible decisions.

Each score combines a CVSS base with named offsets and is capped at ten. Agents may propose relevant context, such as a route to a critical asset, but the deterministic model remains unchanged. The result is consistent, explainable and auditable.

score = clamp(base + Σ offsets, 0, 10)Base is the definition’s CVSS 3.1 score. Offsets are the rows on the right.
Critical9.0 – 10L1 · 7 days
High7.0 – 8.9L2 · 30 days
Medium4.0 – 6.9L3 · 90 days
Low0 – 3.9L4 · 365 days
FactorWhen it appliesOffset
Exploited in the wildOn CISA KEV or observed exploited in the wild.+1.0
Exploit availableA public, functional or weaponized exploit exists.+0.5
High EPSSEPSS probability of exploitation is ≥ 15%.+0.25
Internet-facingThe asset is publicly reachable from the internet.+0.5
Business-critical assetAsset criticality is Very High (crown jewel / Restricted data).+1.0
On a path to a crown jewelThis finding lies on an attack chain reaching a Very-High asset.+1.0
Low EPSSEPSS probability of exploitation is below 1%.1.5
Low-criticality assetAsset criticality is Low.1.0
Compensating controlA WAF, segmentation or mitigation is in place.1.0

Governed agents. Human accountability.

Each Meridian agent has a defined purpose, a bounded toolset, an autonomy tier and a complete audit trail. Structural controls establish what the agent can access and where human approval is required.

01Suggest
The agent proposes. A person acts.Prioritisation context, chain hypotheses, remediation drafts.
02Approve
The agent acts after a named person signs.Validation runs, ticket creation, pull requests.
03Auto
The agent acts inside a pre-approved playbook with a declared blast radius.Re-detection checks, enrichment, SLA clocks. Never a change to production.
Rules of engagementDefine permitted assets, techniques and boundaries, with controls enforced by the platform.
Audit trailRecord each action, input and human decision so reviewers can reconstruct how an exposure progressed.
Two owners, not one fieldSeparate accountability for remediation from authority to accept risk, and route decisions to the appropriate owner.
Closure by re-detectionConfirm closure through re-detection. Manage risk acceptance and false positives as reviewed, time-bound decisions.