Exposure management

Kestryn™

See everything.Hunt what matters.

Kestryn is the exposure-management platform that doesn’t stop at a list of findings — it finds, explains, prioritizes, and drives the fix, every step grounded in evidence and an auditable trail.

Built for sovereign and disconnected networks. Runs wholly inside your perimeter.

Dashboard

Open findings

1,312

last 30 days

Assets identified

386

durable identity

Unplaced hosts

7

counted, not placed

Sites reporting

5 of 6

one has no link — sweeping on cached policy

Open findings by severity

  • Critical41
  • High187
  • Medium604
  • Low480

Findings, last 30 days

6 May20 May4 Jun

DiscoveredResolved

Worst assets

AssetSiteWorstOpenLast seen
plc-gw-02Plant northCritical124 Jun 08:52
hv-node-03Plant northCritical94 Jun 08:51
hist-01Plant northHigh314 Jun 08:52
jump-01Head officeHigh64 Jun 08:49
ws-0417Head officeHigh44 Jun 08:50

Two of those tiles exist to show what the platform refuses to hide: hosts it could not place on a known segment are counted rather than tidied away, and the site with no link is named rather than dropped from the denominator.

What it does, and what it refuses to do.

A capability is easy to claim. A refusal is a commitment you can be held to in an RFP, so each one below is stated alongside the thing it protects.

An engine we own

Discovery, port scanning, service and version detection and OS family all come from Vestryn, written in-house.

No third-party scanner ships inside the product.

Disconnected by design

Site collectors run a cached, signed scan policy and keep sweeping with no link at all, spooling findings locally and sending them on when a window opens. Not less than 90 days offline, then a 30-day grace period.

A site that reconnects after months reports what it saw then, using its own observation time — never the time the console received it.

Identity that survives DHCP

Assets are keyed to a durable identity — agent, hostname, hardware address, then address — with a full lease history, so a host that changes address keeps its history instead of arriving as a new machine.

A contradicting address creates a new asset rather than merging, and an ambiguous attribute is disqualified and recorded. A mistaken merge is auditable rather than invisible.

Scans that cannot hurt the network

A per-zone traffic cap governs every concurrent scan across the estate, and site exclusions are defined per network segment.

If it cannot reach the governor it refuses to scan at all rather than run ungoverned. Exclusions cannot be overridden by a campaign, a schedule, or an operator at run time. Intrusive checks ship disabled and need two separate authorisations to enable.

Measured, not inferred

Every network adjacency records how it was observed and whether it was measured or inferred, enforced in the schema.

An inference can never be stored as a measurement. A host that cannot be placed on a known segment is counted and reported as unplaced rather than attached to an assumed one.

Endpoint identity without shared secrets

Each host generates its own key pair on first start; the private half never leaves the host. Enrolment tokens are use-counted, time-bounded and revocable before use.

The console holds no secret that could mint a host’s credentials, and there is no shared or fleet-wide enrolment secret. Revocation removes the identity, not a flag.

Discovery is identity, not a list of addresses.

An asset keeps its identity when its address changes — and where two sightings contradict each other, neither is merged into the other.

Five sightings.

Two addresses, a hostname, and the same address seen at two different sites. None of these is an asset yet — they are just things that were observed.

Five raw sightings: two addresses, one hostname, and one address seen at two sites.

One machine, however it was seen.

Three of them are the same machine. Its address changed twice and its identity did not, so it resolves to one asset rather than three entries in a list.

Three of the sightings resolve into a single asset whose address changed twice.

And one it will not merge.

Two sightings contradict each other, so neither is folded into the other. It stays on the books as unresolved until something settles it — a coverage gap you can see rather than one rounded away.

The fifth sighting contradicts another and is reported as an unresolved record rather than merged.

Open until it isn’t.

A finding that is seen again after being fixed is reopened, not quietly left closed — and a scan that cannot run under its governor does not run at all.

Findings
run 4 Jun 08:40 — 08:52governed · two authorisations on filecompleted · nothing narrowed
FindingSeverityHostsFirst seenState
CVE-2026-10442Critical1218 MayOpen
CVE-2026-10387fixed 21 May · seen again 4 JunCritical32 AprReopened
CVE-2025-99120High3111 MarOpen
CVE-2026-10501High629 MayFixed
CVE-2025-98004Medium446 FebOpen

The run header is the part a cautious operator reads first: that the scan was authorised, and that it finished rather than being narrowed into one that only looks complete.

A map that admits what it doesn’t know.

Every link names how it was observed. Solid lines were seen by a collector. The one dashed line is an inference — shown on request, never counted as measurement, and never stored as one.

Where something did not answer, the chain ends rather than inventing a link across the gap. A host that cannot be placed on a known segment is counted and reported as unplaced, so the coverage gap stays visible instead of being tidied away.

The attack path runs only over measured adjacencies — and the path itself is labelled an inference over them.

inferredno answer — chain endsABCDEFGHunplaced — counted, not assumed onto a segmentattack path — an inference over measured hops

The Kestryn agent

A component of the platform, not a product of its own. It contributes durable endpoint identity and inventory records, so an asset keeps its history when its address changes and the estate’s inventory reflects the hosts themselves rather than what a scan could reach that day.

Installs
Separately, as its own package. Zero-touch unattended enrolment.
Platform
Linux, amd64.
Identity
Its own key pair, generated on the host. The private half is never transmitted.
Ingestion
Off by default.
Vestryn

Powered by Vestryn

Vestryn is a clean-room network discovery and detection engine that replaces legacy scanners with a single, license-clean, signed binary — finding every host, fingerprinting its services and OS from the traces they leave, and feeding precise CVE matching.

See the engine

Prospica — the intelligence layer

AI held to the same standard as the map.

Prospica is the governed intelligence layer of the Appdirs platform — and in sovereign mode every external model and tool call is disabled in code, not policy.

It reasons over what Kestryn recorded, cites what it used, and keeps the reasoning itself on the record. A confidence that came from the model is recorded as the model’s, never as calibrated. It has no tools of its own: every consequential action waits for a person.

See how Prospica is governed

The platform, in short.

Deployment
Deployable wholly on-premise, with no external call in any product path. In sovereign mode every external model and tool call is disabled — enforced in code, not policy, as a runtime check in the call path.
Packaging
Native operating-system packages on hosts you provide. No pre-built image need be accepted.
Vulnerability sources
CVE enrichment from multiple feeds, including the CISA KEV catalogue, each on an independent cadence, with operator file import.
Prioritization
CVSS v3.1, v3.0 and v2, retained concurrently from multiple sources.
Finding lifecycle
Open, reopened, fixed and resolved, with first-seen and last-seen stamps and reopen-on-redetect.
Scheduling
Scheduled scans at fixed cadences, assignable to the central installation or a site collector.
Reporting
PDF, spreadsheet and CSV, scheduled or on campaign completion, with composable dashboards.
Integration
Email, collaboration, SIEM, service management, issue trackers, and a generic authenticated endpoint.
Access control
Enforced server-side, with the interface treated as presentation only. SSO via AuthX, enabled by configuration.

Kestryn hunts.Vestryn tracks.Prospica foresees.AuthX governs.