Skip to content

Capability

Exposure Management

Separate reachable, unreachable, and unknown findings with a replayable witness; prioritize the paths that change modeled annual loss; send quantified context to Jira or ServiceNow; and recompute residual risk only after verified closeout evidence returns.

Design partnerPublic capability

What Valty does

CTEM, reachability witnesses, KEV/EPSS/SSVC, ITSM deadline queues, and proof-backed residual recompute. Valty turns this domain's signals into priced, proof-backed risk you can act on.

Where the boundary sits

Design-partner workflow. Incomplete trace or graph data remains unknown, and ticket status alone is never treated as closure evidence.

Best next step for CISO, security operations: choose “CISO evidence-source map” to review the workflow, evidence boundary, and fit for your environment.

Exposure Management product surface
Exposure ManagementReachability witness, financially ranked findings table, Jira/ServiceNow remediation record, closeout evidence card, and residual-risk recompute trailOpen full-size product view ↗

Exposure to closure

Prioritize what is reachable. Open the work. Reprice the residual.

Reachability evidence separates exploitable paths from explicit unknowns. Quantified findings can move into Jira or ServiceNow, then return through evidence collection and residual-risk recompute when the ticket closes.

Reachability

Reachable, unreachable, or unknown

Package and function context carries a replayable witness or proof. Incomplete source coverage produces an explicit unknown state.

Materiality

Confirmed exposure receives full pricing weight

Reachable-unvalidated findings are discounted; unreachable findings are zeroed with an audit note rather than disappearing.

Work

Quantified context travels into Jira or ServiceNow

The ticket carries the risk delta and remediation proof requirement, so the operating queue preserves why the work was funded.

Close

Ticket closeout triggers evidence and residual recompute

A verified closeout enters the same evidence pipeline and refreshes the residual-risk model instead of treating ticket status as proof.

Closure sequence

Reachability stays attached through verified closure.
Close → reprice
01FindingReachable
02WorkAssigned
03EvidenceVerified
04ResidualRepriced
Closure rule

Unknown remains unknown. Only collected proof, not ticket status, can verify closure and trigger a residual-exposure update.

See the CISO operating path

Proof matrix

Capability proof requirements

Every claim shows its source, confidence, and limits, so you can trust the number before you act on it.

ClaimSourceConfidenceFreshness
Capability claimCTEM, reachability witnesses, KEV/EPSS/SSVC, ITSM deadline queues, and proof-backed residual recomputeDesign partnerPublic capability
Evidence artifactReachability witness, financially ranked findings table, Jira/ServiceNow remediation record, closeout evidence card, and residual-risk recompute trailSource-linkedReviewed before publish
BoundaryDesign-partner workflow. Incomplete trace or graph data remains unknown, and ticket status alone is never treated as closure evidence.Claim-reviewedQuarterly or on product change