Skip to main content
Regulaxy
Datasheets

Regulaxy — platform datasheet

One page: what the product does, what it explicitly does not do, what it integrates with, and what deploying it on an air-gapped network requires.

Updated

Revision 1.0

The PDF hasn't been uploaded yet. Everything in it is on this page.

What it is

Regulaxy is patch coordination software for regulated organisations. It starts with the vulnerability list your scanner produced and ends with an approved, scheduled and documented maintenance window.

What it does

  • Groups vulnerabilities by the patch that closes them. One patch, many vulnerabilities, many hosts.
  • Ranks against business impact, and shows the components of the score.
  • Proposes a window at a cadence derived from exposure and criticality.
  • Takes written approval from the system owner, as a timestamped calendar invitation.
  • Warns on collisions between windows on connected systems — at the moment the date is chosen.
  • Sends a reminder to the system owner before the window opens.
  • Runs an execution checklist closed in real time and mailed as a summary.
  • Exports evidence — who approved, what was done, what failed.

What it explicitly does not do

It is not a vulnerability scanner, not a deployment agent, and not a CMDB. It takes the list from the scanner, hands a date to whoever installs, and owns what happens in between.

That boundary is deliberate. A tool that tries to be both ends usually skips the middle, and the middle is where schedules break.

Deployment

LocationInside your network
Air-gappedSupported. No outbound internet call
DatabaseYour SQL Server
Sign-inCorporate directory or OIDC
UsersNo seat limit

Regulation

The product is designed around the requirements of §61.4 of Bank of Israel Directive 364, and produces the audit trail contemplated by §98.

Related