Vulnerabilities
- Repeated syncs update the same record instead of stacking duplicates
- Tracks the weakness itself, separate from each instance it turns up in
- Source CVE and CVSS kept intact alongside a normalized level
- Expression-based rules exclude noise before ingestion, not after
- Overdue vulnerabilities roll into an escalation list you can hand to an auditor
- Dismissals stay on record with a reason, never a silent close
Purpose-built for CVEs, not generic findings
Openlane pulls findings from your cloud providers into vulnerability records for you, deduplicated by the source's own identifier with the CVE as fallback — so a resync updates what's there instead of flooding you with duplicates.
Each record keeps its CVE and CVSS rating next to a normalized security level, so you prioritize by one consistent scale instead of translating labels between tools.
Track each vulnerability from discovery to fix against its remediation SLA, pull everything overdue into an escalation and audit-prep list, and record a defensible no — with a reason on file — when a fix isn't happening.
Ingest CVEs from Google Cloud,
GitHub, and Microsoft Defender

GitHub
Collect repository metadata and security alerts to support vulnerability and asset tracking.

Google Cloud Security Command Center
Collect Security Command Center findings for security posture reporting.

Microsoft Defender for Cloud
Collect Microsoft Defender for Cloud findings for security posture and vulnerability tracking.










