Operations · Monitoring & Incidents
Incident response that leaves a record an auditor reads
ThreatZ runs a vehicle cybersecurity incident from the advisory to a named ending, as one traceable chain: the advisory, the bills of materials that carry it, the vehicles in each market, and the clock each market starts.
Works from bills of materials (CycloneDX, SPDX). It never needs your source.
Clocks armed per market — EU CRA Art. 14 · UNECE R155 (Annex 5) · R156 · GB 44495. Mapped to ISO/SAE 21434. Private cloud or on-premise — air-gapped supported.
See it run
One real advisory, arrival to a named ending
The film was recorded on a running build, against one real advisory: CVE-2023-38545, curl's SOCKS5 heap overflow, fixed upstream in curl 8.4.0.
Wordless by design: the product's own text is the narration.
The film keeps the abstention in, and the market recorded with no reporting instrument. Neither was cut to make the product look better. The sections below walk through what the film shows.
The relation canvas, mid-anchor. No cutaways to a deck.
An advisory lands at 03:00
When an advisory lands, the question is not “are we affected?” — it is “can you prove what you did about it?”
Seven named steps, in the order they happen. Each one leaves something on the record.
- ArrivalThe advisory, and the timestamp it arrived.
- AnchorThe tie to the component; who confirmed it, when.
- AssessA severity across four axes, or an abstention naming what was missing.
- GateClocks armed: one per market, per regulation — or “no instrument” recorded.
- DispatchThe child incident, carrying your directive and declared criteria.
- VerifyEvidence validated fail-closed against the declared mode, then stored.
- CloseOne of four named endings; reports per audience preset.
Pillar 1 · Where does it land?
Anchored to the vehicle, not to a ticket
AI and the graph propose where a CVE lands. A named human confirms the tie, and the anchor is recorded with who confirmed it and when. Nothing is anchored on a proposal — only on a confirmation.
Three methods are tried in order — a deterministic SBOM join, a name match, then a graph-grounded semantic match. The first is allowed to find nothing: the exact join is not stretched to fit, and the looser methods only get a turn after it has declined.
The tie is to a component in a bill of materials. From there the chain runs to the vehicles that carry that bill in each market — which is where the clocks start. The result is a tie an auditor can trace back to a person, not a tool's opinion.
Proof on screen
incident → software unit → system component— the chain the auditor followsconfirmed by— a named person, with a timestamp2 confirmed · 0 proposed · 0 disputed— the anchor set at the moment nothing is still a proposal
Pillar 2 · How bad — without the meeting?
Computed, or it abstains
Severity is computed, not argued. It derives from the anchored graph tie — the confirmed link between the advisory and the components that carry it — across four impact axes.
Where the reachable set rates none of those axes, the product does not guess. It records that severity was not computed, and names what was missing.
A severity that is always present tells an auditor nothing about how it was reached. One that can say not yet, and why, is one whose Critical can be traced.
When the data does support a rating, the severity is computed from that same confirmed anchor — so the record shows how the number was reached, and the named human who stood behind the tie it rests on.
Both states appear in the film.

Pillar 3 · Which clock, which market?
Every market's clock, armed from registered fleet
Clocks are armed per regulation, per market, from the registered fleet — EU CRA Art.14, UNECE R155/R156, GB 44495. Each market starts its own clock, on its own instrument, against the registered fleet in that market.
A market with no reporting instrument is not left blank. It is recorded as having none — which is a different fact from “not applicable”, and an auditor reads the difference.
Where a deadline is missed, the record shows a breach as a breach. It does not quietly re-date it.
Proof on screen
authority clock timeline— every market's clock, on one screena breached final-report row— the miss shown as a breach, not re-datedseven live early-warning countdowns— seven early-warning clocks running at once in the film's dataUnited States is a registered fleet market with no incident-reporting instrument— a market recorded as having none, rather than left blank5 registered VINs have unresolved regions— the fleet register shows how many VINs still have no resolved region
Pillar 4 · Fixed — says who?
The fix is proven by a bill of materials, not a promise
Remediation closes by one of three declared modes, chosen before the work starts — not selected afterward to fit whatever got done.
For a CVE, the proof is a bill of materials: the SBOM shows the component moved to a version that clears the finding. ThreatZ consumes bills of materials — CycloneDX, SPDX — and never sees source. That is precisely why a supplier can be held to the proof: the evidence is the artefact, not their account of it. How the supplier receives the finding, and why they cannot close it themselves, is below.
Evidence is validated fail-closed before it is stored. A file that doesn't check out doesn't get filed as proof.
Proof on screen
Proof of remediation — how is this finding being closed?— the mode is chosen before the workmode A · eliminated at source … closes as fixed-version-bump— the SBOM at the clearing version is the proofthe upload card— validated fail-closed before it is stored
Pillar 5 · Closed — into what?
It ends with a named ending
Four endings, declared in advance: fixed, mitigated, deferred, not applicable. Nothing closes into an ending that wasn't on the list.
“Deferred” is tagged holding — never an ending. The parent incident stays open on it. A deferred finding cannot be mistaken for a closed one, on this record or in a report pulled from it.
Reports generate per audience preset, including a regulator or authority pack — the same record, re-cut for who is reading it.
The record itself is append-only, and every row carries who wrote it — so what the authority receives is the same append-only history, re-cut for them — not a tidied-down version of it.
Proof on screen
the closure endings panel— fixed, mitigated, deferred, not applicable — the only four ways outdeferred · holding — never an ending— the parent stays openthe report generator, pressed on camera— the regulator/authority preset, generated from the same record
Suppliers
Suppliers execute inside your process
When an advisory dispatches to an affected project, the child incident carries your directive and the criteria you declared — not a summary of them, the criteria themselves. A supplier works the finding against your definition of done.
This is what federated means here: the supplier works inside their own project, on their own timeline, while the incident still answers to the programme that dispatched it — one incident, worked in two places, not two incidents reconciled by email.
The programme is the only gate out. A child incident does not close itself, and it does not close outside the record you hold on it.
Proof on screen
Dispatched: <parent>— the child incident, carrying your directive and the declared criteria into the supplier's projectits own stage set— worked on the supplier's timeline, inside the record you holdStandards
Evidence for the standards your auditor already reads
ThreatZ's incident record supports evidence for the following, section by section — it does not certify compliance on your behalf.
- ISO/SAE 21434§9, §10, §11, §12, §13, §15 — the anchored advisory, the severity or abstention, the proven fix and the named ending, on one record
- UNECE R155Annex 5 — the monitoring-and-response loop, end to end, with a named human on the anchor
- UNECE R156supports evidence for the proof of remediation behind an update
- EU CRA Art. 14the early-warning and final-report clocks per market, with a breach shown as a breach
- GB 44495the PRC market's clock, armed from the registered fleet there
Background reading: cybersecurity monitoring as R155 Annex 5 evidence · EU CRA Article 14 alongside R155. Related on this site: SBOM & CVE monitoring · TARA · Assurance · Pricing.
Deployment & sovereignty
Where the evidence runs is your decision
Private cloud or on-premise — air-gapped supported. The topology is yours to choose, not a default you inherit.
ThreatZ is also listed on AWS Marketplace — a procurement channel for organisations that buy through it, not a deployment topology; the private-cloud and on-premise options above apply regardless of how the purchase is made.
FAQ
Questions an auditor, a PSIRT lead or a supplier manager asks
How does this satisfy UNECE R155 Annex 5?
Annex 5 asks for a monitoring-and-response loop with evidence behind it. ThreatZ's record supports evidence for that loop, end to end — anchored advisory, computed or abstained severity, per-market clock (EU CRA Article 14, UNECE R155 and R156, GB 44495, each armed from your registered fleet, with a market that has no instrument recorded as such), proven remediation, named ending — and generates a report per audience preset, including a regulator or authority pack, for the authority conversation. It is evidence, not certification.
Does ThreatZ need our source code?
No — it consumes bills of materials. CycloneDX and SPDX inputs are what the graph and the remediation proof are built from.
Where does it deploy?
Private cloud or on-premise — air-gapped supported.
How does ThreatZ decide which vehicles an advisory affects?
It tries three methods in order: a deterministic SBOM join, a name match, then a graph-grounded semantic match. AI and the graph propose the tie; a named human confirms it before anything downstream treats it as fact. The anchor is to a component in a bill of materials; the vehicles are the registered fleet carrying that bill in each market, which is what the clocks are armed from.
Can a supplier work the incident without access to our programme?
The dispatched child incident carries your directive and declared criteria into the supplier's own project. They work it there; your programme remains the only gate the finding can close through.
What happens when the graph cannot rate an impact axis?
The product does not guess. It records that severity was not computed and names what was missing — for example, “not computed — missing: the reachable set rates no impact axis”. A later confirmation can still compute it once the data supports a rating.
What counts as proof that a CVE is fixed?
An SBOM showing the affected component moved to a version that clears the finding. Evidence is validated fail-closed before it is stored, so a file that doesn't check out is never filed as proof.
What does the walkthrough involve?
One advisory, run from arrival to a named ending on a live build — the same run as the film, stopped wherever your questions stop it. Bring whoever owns the VSOC/PSIRT queue and whoever owns the type-approval conversation.
What do we need to have ready?
Bills of materials in CycloneDX or SPDX for the software you want anchored, and the registered fleet per market for the clocks. Nothing from source.
Supplying the subsystem rather than building the vehicle? →
See the whole record, end to end — before an auditor asks for yours.
Book a walkthroughOne advisory, start to finish, on a live build. Booked on vxlabs.ai.