Exposure management
Kestryn™
See everything.Hunt what matters.
Kestryn is the exposure-management platform that doesn’t stop at a list of findings — it finds, explains, prioritizes, and drives the fix, every step grounded in evidence and an auditable trail.
Built for sovereign and disconnected networks. Runs wholly inside your perimeter.
Two of those tiles exist to show what the platform refuses to hide: hosts it could not place on a known segment are counted rather than tidied away, and the site with no link is named rather than dropped from the denominator.
What it does, and what it refuses to do.
A capability is easy to claim. A refusal is a commitment you can be held to in an RFP, so each one below is stated alongside the thing it protects.
- An engine we own
Discovery, port scanning, service and version detection and OS family all come from Vestryn, written in-house.
No third-party scanner ships inside the product.
- Disconnected by design
Site collectors run a cached, signed scan policy and keep sweeping with no link at all, spooling findings locally and sending them on when a window opens. Not less than 90 days offline, then a 30-day grace period.
A site that reconnects after months reports what it saw then, using its own observation time — never the time the console received it.
- Identity that survives DHCP
Assets are keyed to a durable identity — agent, hostname, hardware address, then address — with a full lease history, so a host that changes address keeps its history instead of arriving as a new machine.
A contradicting address creates a new asset rather than merging, and an ambiguous attribute is disqualified and recorded. A mistaken merge is auditable rather than invisible.
- Scans that cannot hurt the network
A per-zone traffic cap governs every concurrent scan across the estate, and site exclusions are defined per network segment.
If it cannot reach the governor it refuses to scan at all rather than run ungoverned. Exclusions cannot be overridden by a campaign, a schedule, or an operator at run time. Intrusive checks ship disabled and need two separate authorisations to enable.
- Measured, not inferred
Every network adjacency records how it was observed and whether it was measured or inferred, enforced in the schema.
An inference can never be stored as a measurement. A host that cannot be placed on a known segment is counted and reported as unplaced rather than attached to an assumed one.
- Endpoint identity without shared secrets
Each host generates its own key pair on first start; the private half never leaves the host. Enrolment tokens are use-counted, time-bounded and revocable before use.
The console holds no secret that could mint a host’s credentials, and there is no shared or fleet-wide enrolment secret. Revocation removes the identity, not a flag.
Discovery is identity, not a list of addresses.
An asset keeps its identity when its address changes — and where two sightings contradict each other, neither is merged into the other.
Five sightings.
Five raw sightings: two addresses, one hostname, and one address seen at two sites.
One machine, however it was seen.
Three of the sightings resolve into a single asset whose address changed twice.
And one it will not merge.
The fifth sighting contradicts another and is reported as an unresolved record rather than merged.
Open until it isn’t.
A finding that is seen again after being fixed is reopened, not quietly left closed — and a scan that cannot run under its governor does not run at all.
The run header is the part a cautious operator reads first: that the scan was authorised, and that it finished rather than being narrowed into one that only looks complete.
A map that admits what it doesn’t know.
Every link names how it was observed. Solid lines were seen by a collector. The one dashed line is an inference — shown on request, never counted as measurement, and never stored as one.
Where something did not answer, the chain ends rather than inventing a link across the gap. A host that cannot be placed on a known segment is counted and reported as unplaced, so the coverage gap stays visible instead of being tidied away.
The attack path runs only over measured adjacencies — and the path itself is labelled an inference over them.
The Kestryn agent
A component of the platform, not a product of its own. It contributes durable endpoint identity and inventory records, so an asset keeps its history when its address changes and the estate’s inventory reflects the hosts themselves rather than what a scan could reach that day.
- Installs
- Separately, as its own package. Zero-touch unattended enrolment.
- Platform
- Linux, amd64.
- Identity
- Its own key pair, generated on the host. The private half is never transmitted.
- Ingestion
- Off by default.
Powered by Vestryn
Vestryn is a clean-room network discovery and detection engine that replaces legacy scanners with a single, license-clean, signed binary — finding every host, fingerprinting its services and OS from the traces they leave, and feeding precise CVE matching.
See the engineProspica — the intelligence layer
AI held to the same standard as the map.
Prospica is the governed intelligence layer of the Appdirs platform — and in sovereign mode every external model and tool call is disabled in code, not policy.
It reasons over what Kestryn recorded, cites what it used, and keeps the reasoning itself on the record. A confidence that came from the model is recorded as the model’s, never as calibrated. It has no tools of its own: every consequential action waits for a person.
See how Prospica is governedThe platform, in short.
- Deployment
- Deployable wholly on-premise, with no external call in any product path. In sovereign mode every external model and tool call is disabled — enforced in code, not policy, as a runtime check in the call path.
- Packaging
- Native operating-system packages on hosts you provide. No pre-built image need be accepted.
- Vulnerability sources
- CVE enrichment from multiple feeds, including the CISA KEV catalogue, each on an independent cadence, with operator file import.
- Prioritization
- CVSS v3.1, v3.0 and v2, retained concurrently from multiple sources.
- Finding lifecycle
- Open, reopened, fixed and resolved, with first-seen and last-seen stamps and reopen-on-redetect.
- Scheduling
- Scheduled scans at fixed cadences, assignable to the central installation or a site collector.
- Reporting
- PDF, spreadsheet and CSV, scheduled or on campaign completion, with composable dashboards.
- Integration
- Email, collaboration, SIEM, service management, issue trackers, and a generic authenticated endpoint.
- Access control
- Enforced server-side, with the interface treated as presentation only. SSO via AuthX, enabled by configuration.
Kestryn hunts.Vestryn tracks.Prospica foresees.AuthX governs.