Security Intelligence

Proactive Security
Not Reactive Alerts

Continuous CVE scanning from three authoritative sources, automatic risk scoring, config drift detection, and CIS compliance — all without sending a byte of your data anywhere.

See It in Action How It Works ↓
Risk Intelligence

Per-host CVE Risk Score

LocalM computes a composite 0–100 risk score for every host, accounting for CVSS severity, KEV active exploitation, patch age, and exposed attack surface.

72
HIGH RISK
centos9-prod-01

Risk Score Breakdown

Critical CVEs (KEV Active)+38 pts
High CVEs (CVSS ≥ 7.0)+22 pts
Medium CVEs (CVSS 4–6.9)+8 pts
Patch Age Penalty (90+ days)+4 pts
⚠ KEV Active: CVE-2024-6387 (regreSSHion)
CISA has confirmed active exploitation in the wild. CVSS 8.1. Recommend immediate patching of openssh.
Three Sources

Broadest CVE coverage possible

LocalM cross-references three authoritative vulnerability databases, refreshed on a configurable schedule, with no cloud dependency.

🟥

NIST National Vulnerability Database

The authoritative US government CVE database. Full CVSS v3.1 scoring, CWE classifications, and CPE application matching. LocalM pulls NVD feeds directly — no paid API key required.

240,000+ CVEs indexed CVSS v3.1 CPE Matching

Refreshed every 24h via NVD JSON feeds. Covers virtually all known software vulnerabilities with standardised scoring.

🔥

CISA Known Exploited Vulnerabilities

CISA's KEV Catalog is the definitive list of vulnerabilities being actively exploited in the wild. These aren't theoretical — attackers are using them right now. LocalM highlights any KEV hit with maximum urgency.

1,100+ KEV entries Active Exploitation CISA Official

A CVE-CVSS 5.5 that is on the KEV list is infinitely more dangerous than a CVSS 9.8 that isn't. LocalM treats KEV as highest priority.

📦

OSV.dev — Open Source Vulnerabilities

Google's open-source vulnerability database covers Python packages, npm, Go, Rust, and more — areas NVD often misses. Essential for any host running application stacks.

30+ ecosystems Python / npm / Go OSS Packages

Closes the gap between OS-level CVEs and application dependency vulnerabilities. LocalM scans pip, npm, and gem in addition to system packages.

Auto-Patching

Four risk tiers. Your call on automation.

Configure exactly how much automation you want. Patch KEV-active criticals automatically. Require sign-off for everything else. Fully customisable per host group.

81–100
CRITICAL

Auto-patch immediately. CISA KEV active exploitation confirmed. No approval gate. Full audit logged.

⚡ Patch immediately
61–80
HIGH

Queue for patch within 24h. Single approver sign-off required before execution. Revert pre-generated.

✔ Approve & patch 24h
31–60
MEDIUM

Schedule for next maintenance window. Two-approver sign-off. Optional defer with 30-day re-notification.

📅 Schedule maintenance
0–30
LOW

Logged and tracked. No automatic action. Addressed during routine patching cycles. Still auditable.

📋 Routine patching
Config Drift

Know the instant a config changes

LocalM baselines every security-sensitive file across your fleet. Periodic SSH re-scans detect any modification — expected or not. Acknowledge legitimate changes, escalate unexpected ones.

  • Tracks sshd_config, sudoers, /etc/pam.d/*, sysctl.conf, fstab
  • SHA-256 hash comparison + LLM-generated diff summary
  • Acknowledge expected changes; escalate unexpected ones
  • Full tamper-evident audit trail in SQLite (append-only)

Config Drift — centos9-prod-01

Last checked 4 mins ago
/etc/sshd_configNo changes · Baseline 2026-05-01
/etc/sudoersModified 14 mins ago · SHA changed
/etc/pam.d/suUnexpected change · 2 lines added
/etc/sysctl.confNo changes · Baseline 2026-05-01
/etc/fstabNo changes · Baseline 2026-05-01
CIS Compliance

CIS Benchmark compliance scoring

SSH-based checks aligned to CIS Benchmark controls. Per-host pass/fail scores trend over time, so you can measure improvement. LLM generates remediation steps for every failed check.

  • CIS RHEL 9, Ubuntu 22.04, Debian 12, RHEL 8 profiles
  • Controls: IAM, network, file permissions, audit, services
  • Score trending — see posture improve week over week
  • LLM writes the remediation playbook for each failure

CIS Posture — Fleet Overview

Benchmark: CIS RHEL 9 v2.0

centos9-prod-01

74%
148/200 controls pass

ubuntu22-web

61%
122/200 controls pass

rhel9-db-01

69%
138/200 controls pass

fedora38-dev

88%
176/200 controls pass
Data Sovereignty

Your data never leaves the room

LocalM is architected from first principles for air-gap environments. Every component runs on-premise. Zero cloud dependencies. Full GDPR compliance by design.

🔐

No Cloud LLM

Ollama runs the AI locally — Qwen 2.5, Llama 3.1. Your infrastructure data, logs, and CVE context never reach OpenAI, Anthropic, or any external API.

🗄️

Local Databases

SQLite for structured data. ChromaDB for vector embeddings. Both run on your own disk. No SaaS backend. No data exfiltration possible.

🌐

Offline-Capable

After initial knowledge base seeding, LocalM operates entirely without internet. Perfect for air-gap networks, defence environments, and classified infrastructure.

📋

Append-Only Audit

Every action — playbook run, approval, login — is written to a tamper-evident audit log. Full accountability for compliance auditors and security teams.

🏛️

GDPR by Design

No personal data exported. No analytics beacons. No licence phone-home. Data residency is wherever you deploy it — your data centre, your rules.

🇬🇧

UK Built & Hosted

Developed in England. All intellectual property owned by a UK company. Ideal for public sector, NHS, and organisations with UK data residency requirements.

Use Cases

Built for regulated industries

When data sovereignty is a legal requirement, not just a preference, LocalM is the only AIOps platform that qualifies.

🏦

Financial Services

FCA-regulated firms need security tooling that doesn't send trading data, customer PII, or system configurations to third-party clouds. LocalM's air-gap architecture satisfies PCI-DSS, SOX, and FCA operational resilience requirements out of the box.

PCI-DSSFCA RegSOXOn-Prem
🏥

Healthcare / NHS

Patient data in server logs or configurations can never leave NHS infrastructure. LocalM monitors clinical systems, surfaces vulnerabilities in medical software stacks, and auto-remediates — all without a single byte leaving the trust's network boundary.

NHS DSP ToolkitDSPTCyber EssentialsGDPR
🏭

Manufacturing / OT

Operational technology networks are often truly air-gapped. LocalM's offline mode lets you monitor Linux-based SCADA servers, HMIs, and production systems from within the OT network — no external connectivity required. No exceptions.

Air-GapOT/ICSIEC 62443Offline

See your CVE exposure in 60 seconds

Connect a single Linux host to LocalM and get a complete CVE risk score with KEV highlights in under a minute. Your data never leaves your network.