Regulaxy — platform datasheet
One page: what the product does, what it explicitly does not do, what it integrates with, and what deploying it on an air-gapped network requires.
- Updated
Revision 1.0
The PDF hasn't been uploaded yet. Everything in it is on this page.
Regulaxy platform datasheet — downloadable PDF, A4
Until the file exists, this page is the full document
What it is
Regulaxy is patch coordination software for regulated organisations. It starts with the vulnerability list your scanner produced and ends with an approved, scheduled and documented maintenance window.
What it does
- Groups vulnerabilities by the patch that closes them. One patch, many vulnerabilities, many hosts.
- Ranks against business impact, and shows the components of the score.
- Proposes a window at a cadence derived from exposure and criticality.
- Takes written approval from the system owner, as a timestamped calendar invitation.
- Warns on collisions between windows on connected systems — at the moment the date is chosen.
- Sends a reminder to the system owner before the window opens.
- Runs an execution checklist closed in real time and mailed as a summary.
- Exports evidence — who approved, what was done, what failed.
What it explicitly does not do
It is not a vulnerability scanner, not a deployment agent, and not a CMDB. It takes the list from the scanner, hands a date to whoever installs, and owns what happens in between.
That boundary is deliberate. A tool that tries to be both ends usually skips the middle, and the middle is where schedules break.
Deployment
| Location | Inside your network |
| Air-gapped | Supported. No outbound internet call |
| Database | Your SQL Server |
| Sign-in | Corporate directory or OIDC |
| Users | No seat limit |
Regulation
The product is designed around the requirements of §61.4 of Bank of Israel Directive 364, and produces the audit trail contemplated by §98.