Your queue, already sorted
Every repo gets one of four tiers: Crown Jewel, Key Asset, Standard, Peripheral. Findings inherit it.
Most of your repos are not the problem
A fraction hold customer data or face the internet. Knowing which means effort goes where a breach would hurt.
A threat model you can defend
Every attribute shows the file that grounds it, so the model holds up with a developer, an auditor, or your board.
Nothing new to set up
It reads your repos through the GitHub or GitLab connection Konvu already has. No clone, no CI job.
The same CVE, two different answers
A critical CVE in an internet-facing service holding customer data is an incident. The identical finding in a dormant internal tool is a backlog item. Severity scores the vulnerability. It says nothing about what that vulnerability threatens.
Exploitable, confirmed. Internet-exposed, holds customer data.
Fix now · Remediation Engineer opened PR #318
Exploitable, confirmed. Internal only, no customer data, dormant 14 months.
Backlog · no page, no ticket on the developer
One finding, two answers. The asset decides which.
Crown Jewel: internet-exposed production surface holding customer data.
Exposure
Access
Blast radius
Stakes
Attackers
Runtime
Detected values cite a path. Guesses are capped and never outrank them.
Six questions, asked of every repository
Exposure, access, blast radius, stakes, plausible attackers, and where the code runs. Each answer cites the path, README line, or manifest that grounds it, so the tier is something your team can argue with.
Thousands of repos, ranked in one pass
Dormant repos are settled from activity data Konvu already has, before any model call. The expensive analysis spends its time on the repos that could change a decision.
23 Crown Jewel · 96 Key Asset · 402 Standard · 763 Peripheral
