At Nullify, one of the questions we ask ourselves most often is:
How do human security engineers make decisions?
When an engineer triages a vulnerability, they are not looking at the finding in isolation. They are drawing on what they know about the system around it.
They know which services are important, which workloads handle sensitive data, where trust boundaries sit, what is exposed, which controls are already in place, and which classes of vulnerability the organisation cares about most.
That context changes the decision. Exploitability is part of it - as team needs to know whether a vulnerability can actually be used in the application as it exists. But even after that question has been answered, there may still be more exploitable findings than the team has the capacity to fix.
They still need to decide which ones matter most.
We saw this directly last year when customers told us they would still rescore our priority score themselves. They were not disputing the technical analysis. They had their own way of assessing impact, based on context that Nullify did not yet have.
That made the limitation clear: agents do not just need more vulnerability data. They need to understand the environment in which the vulnerability exists.
They need to know how the affected system fits into the wider architecture, what data it handles, what the business depends on it for, and why the security team would treat one issue differently from another.
That is what Vault provides.
Vault gives Nullify long-term memory of the organisation. It can ingest cloud architecture, codebase metadata, bug bounty reports, security policies and the knowledge buried across internal documentation.
From that, Nullify builds a working model of the environment across cloud, code and infrastructure. This means Nullify can assess a finding with more than its severity and exploitability. It can reason about the workload around it and ground the impact score in how the organisation itself thinks about risk.
That distinction matters because impact is not universal; the same vulnerability might sit in a low-risk internal service in one environment and a customer-facing authentication flow in another. The technical issue may be identical, but the decision should not be.
This is also why AI triage does not automatically solve the backlog problem.
A system can do an excellent job of identifying which findings are exploitable and still leave the team with too much work. Without business context, it has no reliable way to decide which of those exploitable findings deserves attention first.
Exploitability tells the agent what can happen. Vault helps it understand what it would the impact would be in the scenario of the exploit happening.
Over time, Vault continues to adapt to the organisation’s product security priorities. The security team still defines what matters, sets policy and handles exceptions. The difference is that their context can be applied consistently, instead of being reconstructed manually for every finding.
That is the direction we think security agents need to move in - not just better at analysing vulnerabilities, but better at understanding how security teams make decisions.