CVERiskPilot scans your code for vulnerable dependencies, secrets, and IaC misconfigs — then maps every finding to NIST 800-53, SOC 2, CMMC, FedRAMP, ASVS, and SSDF automatically. More than a scanner. The CVE triage dashboard lets your team analyze, prioritize, and track every vulnerability from discovery to remediation — AI classifies true positives, false positives, and needs-review. One command. Six frameworks. 135 controls. Zero config. Free CLI. No credit card. Veteran Owned.
No reviews yetBe the first to leave a review for CVERiskPilot
Maker
📌
I built a free CLI that closes that gap. One command scans your dependencies, secrets, and infrastructure-as-code, then chains every finding through CWE → NIST 800-53 → SOC 2 / CMMC / FedRAMP / ASVS / SSDF automatically.
It also auto-triages findings so your team isn't chasing false positives in test fixtures and .env.example files.
Try it right now — no signup, no credit card, nothing leaves your machine:
npx @cveriskpilot/scan --preset startup
Would love your feedback. What compliance frameworks should we add next? HIPAA and PCI-DSS are on the roadmap.