Patch coordination for regulated enterprises
The patch was ready in March.
The window was in July.
Scanners tell you what to patch. Deployment tools push it. Regulaxy runs the part in between — agreeing the window, getting the owner's sign-off, catching the systems that must not go down together, and writing all of it down.
Installs on your network. Works fully air-gapped.
- MarchPatch published
- AprilQuarter-end freeze
- MaySystem owner unavailable
- JuneNight already taken by another system
- JulyWindow agreed, approved, executed
An illustration of a typical case. Not customer data.
Why believe us
Built in production, inside a bank.
Regulaxy wasn't designed for a market and then sold into one. It was built by an infrastructure team to run their own patch operations on an air-gapped network, under Bank of Israel supervision.
No outbound internet required
No CDN, no telemetry, no phone-home. It runs on networks that have never seen the public internet.
Your database, your servers
Regulaxy installs into your environment. Your estate inventory never leaves your network.
Hebrew and English, RTL-native
Not a translated interface. Built right-to-left from the first screen.
The problem
Nobody's blocked on finding the vulnerability.
Your scanner produces the list on schedule. The list is not the bottleneck. The bottleneck is thirty system owners, each of whom will agree to a window — just not that one, and not this month, and not until the quarter closes.
So the coordination moves into a spreadsheet, a mail thread and a WhatsApp group. None of the three knows what is happening to the system next door.
- 02:40
The window nobody agreed to
The change was scheduled, the owner never confirmed, and it was rolled back at 02:40 because someone was still running end-of-month.
- Same night
The collision nobody caught
Two systems were patched the same night. They depended on each other. Nothing in the spreadsheet knew that.
- April
The evidence nobody kept
The audit asks who approved the change. The answer is in someone's sent items, and they left in April.
How it works
From a CVE list to a window somebody signed for.
Five stages. Each one ends in something a human actually receives — not a status on a screen.
Group
CVEs arrive from your scanner or your SOC feed. Regulaxy folds them into the thing you can actually schedule — the patch. One patch, many CVEs, many hosts.
producesOne schedulable patch
Rank
Each patch is scored against the systems it touches, using your own business-impact analysis — not CVSS on its own.
producesA score with its terms
Propose
Regulaxy proposes a window that respects the system's patch cadence, its tier, and what else is already booked that night.
producesA dated window
Agree
The system owner gets a calendar invite they can accept, not an email they can ignore. An SMS goes out before the window opens.
producesAn approval and an invite
Prove
The operator works a checklist during the window. A summary goes to the owner at the end, and the record stays in the audit log.
producesAn audit record
Figure 2 — the lifecycle of a maintenance window
Capabilities
What's in it.
Six of twelve. Every one of them ends in a single artifact you can point at.
Window scheduling
A five-step wizard that knows your estate. Pick the update type, the hosts, the owner, the window — it fills in what it already knows and remembers who was involved last time.
A dated, approved window
Collision detection
Regulaxy maps which systems talk to each other and refuses to let you book two connected systems into overlapping windows without telling you first.
A warning before you book
Business-impact scoring
Rank by what the system does for the business, not just by CVSS. Explainable: every point in the score is traceable to a term.
A score that shows its working
Calendar and reminders
Real Outlook invites — two copies, so the coordinator can accept their own meeting. SMS to the system owner before the window opens.
Two ICS invites and an SMS
Checklists
Build the form once per update type. The operator fills it in at 3am; the summary mails itself to the owner when it's done.
A signed, mailed form
Evidence and export
Styled Excel and CSV out of every table, an audit log of every change, and a record that survives the event being deleted.
An export and an audit log
Proof
You can look at it before you talk to us.
Regulaxy ships with a complete demo estate built in — real system topology, a deliberate collision between two linked systems, and a populated CVE register. You can drive the whole product without a database, without a licence, and without a sales call.
- hosts
- 401hosts
- business systems
- 50business systems
- maintenance events
- 285maintenance events
That same estate is where every screenshot on this site comes from. It is generated from one seeded generator, so a re-shot screenshot six months from now shows the same data.
The inventory screen, one filter applied, two annotations
Waiting on sign-off to publish the demo estate
The inventory screen resolves one host row out of three read-only sources, and marks the ones already past their due date.
Integrations
Fits what you already run.
Regulaxy doesn't replace your scanner, your deployment tool or your ticketing system. It coordinates around them, and it reads the inventory you already keep rather than asking you to enter it again.
- Identity and access
- Active Directory
- LDAP
- Mail and calendar
- Microsoft Exchange
- Outlook
- ICS
- SMTP
- Databases
- Microsoft SQL Server
- Oracle
- Inventory and topology
- Dynatrace
- SolarWinds
- WSUS
- Feeds and export
- CSV
- JSON
- Excel
- Notifications and tickets
- SMS gateway
- SOAP ticketing
Security and deployment
Deployed where your data already is.
On-premises, always
Regulaxy installs on your servers, against your database. There is no Regulaxy cloud, and no version of this product where your estate inventory leaves your network.
Air-gap native
No CDN, no external fonts, no runtime downloads. Updates ship as a file you carry in.
Roles and audit
Administrators and operators are separated at the API, not just in the UI. Every change is logged, and the log survives deletion of the thing it describes.
Regulaxy
Application server and database, on your side
- Active Directory — identities and contacts
- Exchange — calendar invites
- SQL Server and Oracle — inventory and databases
- Dynatrace and SolarWinds — topology and equipment
For Israeli banking supervision, Regulaxy is designed around the patch-management, emergency-change and audit-trail requirements of Bank of Israel Proper Conduct of Banking Business Directive 364 — which replaced 357, 361 and 363.
We supply the evidence. Compliance itself belongs to the bank, and no vendor can hold it on your behalf.
- §61.4
- Patch managementPatches applied within a timeframe matching the asset's criticality
- §97
- Emergency changesA defined approval procedure and a named authorised approver
- §98
- Audit trailRetention of a record of the activities performed during the change
Pricing
Priced by the estate you manage.
One meter: the number of hosts Regulaxy coordinates. Unlimited users, all modules, on-premises, and no per-seat charge for the system owners who only ever receive an invite.
managed hosts
Show us your worst window.
Bring the one that keeps slipping. Thirty minutes, your estate, no slides.
- The system with four owners
- The cluster nobody will take down
- The quarter-end freeze