What the product does
The exact data available depends on the selected connector, source licence and customer asset scope.
Guardian Vulnerability Management connects supported asset and vulnerability sources to one customer-readable posture, remediation queue, evidence trail and resolution-review process.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains supported source identifiers, observation dates, affected scope, remediation status, action history and approved evidence. Customer views do not expose credentials, raw upstream payloads or unrelated tenant data.
The commercial schedule identifies the licensed source, covered assets or seats, assessment scope, synchronisation, retention, customer users, provider relationship and any managed remediation activity. Connector licensing and Damocles service are separate inputs even when sold as one solution.
Guardian does not imply universal asset discovery, complete vulnerability coverage, unlimited scanning, guaranteed remediation or automatic acceptance of a source-reported resolution.
The exact data available depends on the selected connector, source licence and customer asset scope.
Leadership, IT teams and providers receive different depth while using the same underlying records.
Platform-only delivery and managed remediation support remain separate commercial responsibilities.
Customers can have thousands of findings without a clear answer on which assets are exposed, which vulnerabilities can be exploited, who owns the change, or whether a reported resolution reflects a real fix. Different tools also use different severity, asset, status and exception models.
Guardian normalises the supported source information into a consistent customer workflow. The source technology remains responsible for discovery and assessment; Guardian is responsible for customer scope, prioritisation, ownership, remediation state, evidence and reporting.
Use severity, affected assets, internet exposure, business criticality, known exploitation context and remediation dependency to identify the work that matters first.
Give each required change an accountable owner, due date, status, expected outcome and source drilldown.
Use source state, patch state, rescans, configuration evidence or approved exceptions before accepting closure.
The exact data available depends on the selected connector, source licence and customer asset scope.
Map supported devices, servers, workloads and groups to the correct customer, business role and remediation owner.
Present severity, affected scope, first and last observation, current status and source context in a consistent model.
Combine technical severity with exposure, criticality, exploit context, age and customer policy to focus remediation.
Record approved exceptions, compensating controls, review dates, evidence and decision ownership.
Create actions for patching, upgrading, configuration, isolation, removal or another approved treatment.
Distinguish no-longer-observed, fixed, restart-required, exception, accepted and evidence-review states where supported.
Leadership, IT teams and providers receive different depth while using the same underlying records.
Material vulnerability exposure, overdue remediation, affected critical assets and movement over the selected period.
Affected assets, source evidence, recommended treatment, owners, due dates and linked actions.
Where supported, identify available patches, installed state, required restart, failure and exception conditions.
Authorised customer posture and remediation without exposing other tenants or unrelated upstream data.
Measured open, new, resolved, returned and accepted states using real retained history.
Customer-readable summaries linked to the asset, finding, action, evidence and source record.
Platform-only delivery and managed remediation support remain separate commercial responsibilities.
Configure authentication, customer mapping, asset scope, synchronisation, source-health checks and safe field translation.
Review duplicate assets, stale records, missing ownership, inconsistent severity and unsupported fields.
Help the customer define risk-based queues, target timelines, exception rules and escalation thresholds.
Track assigned work, chase overdue actions, coordinate evidence and escalate blocked remediation where contracted.
Review rescans, patch state, configuration evidence and source changes to support closure decisions.
Provide agreed vulnerability, remediation, exception and service-health reporting through Guardian.
The source continues to perform the technical assessment while Guardian manages the customer lifecycle around it.
Authorise the source, customer scope, asset mapping and synchronisation method.
Convert supported assets and findings into consistent customer records and source-health state.
Apply severity, exposure, asset criticality, age, exploit context and customer policy.
Create the remediation action, owner, due date, treatment and evidence requirement.
Patch, upgrade, reconfigure, remove, isolate or apply the approved compensating control.
Review source state and evidence, then record closure, residual risk, exception or further work.
The product can be used with different supported source technologies and customer operating models.
Give a small IT team one prioritised queue instead of a large vendor report that lacks local ownership.
Manage authorised customer vulnerability posture, actions and reporting through a provider-scoped Guardian workflow.
Normalise supported sources or business units into one executive and remediation model while retaining source traceability.
Connect vulnerability findings to endpoint patch state, restart conditions, failures and exception follow-up where supported.
Record compensating controls, expiry dates, evidence and owner review for vulnerabilities that cannot be immediately removed.
Show material exposure, remediation progress, overdue work and evidence without claiming unsupported compliance outcomes.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Implementation begins with asset authority, source capability and the customer remediation model. Damocles confirms the customer relationship, asset ownership, supported source, authentication method, synchronisation schedule, retention, required fields and source-health checks. Sample records are reviewed before broader import so customer and provider scope can be validated. The customer defines asset groups, criticality, owners, remediation timelines, exception authority and evidence requirements. Existing service-management or patching workflows are mapped so Guardian actions complement the customer process rather than create a competing queue. Go-live includes a baseline review, duplicate and stale-asset checks, priority validation, user access, reporting and a documented process for source failure, unsupported records and later connector changes.
The public product remains stable even when the selected vulnerability connector changes. A supported connector must provide authenticated access, explicit customer mapping, stable source identifiers, asset and finding fields, synchronisation state and safe error handling. Guardian stores the source reference needed for traceability while presenting a consistent customer model. The selected connector may be a commercial platform, a self-hosted assessment source, a patch-management source or another approved system. The proposal names the implementation and supported fields; the public website describes the product outcome without making one vendor mandatory. New connector requests are assessed for tenant isolation, API support, data ownership, rate limits, field quality, source health, retention, supportability and commercial impact before being represented as available.
Every reported result should be traceable to a source, asset, action and review decision. Guardian retains supported source identifiers, observation dates, affected scope, remediation status, action history and approved evidence. Customer views do not expose credentials, raw upstream payloads or unrelated tenant data. Reports distinguish measured vulnerability state from interpretation. Trend is shown only where retained records support it, and a source that stops reporting is not silently represented as proof that the issue was fixed. Where evidence is attached or referenced, access remains customer and role scoped. Superseded findings, exceptions and closure decisions retain an auditable history according to the approved workflow.
Pricing and entitlement follow the measurable asset, seat, target or service unit defined in the proposal. The commercial schedule identifies the licensed source, covered assets or seats, assessment scope, synchronisation, retention, customer users, provider relationship and any managed remediation activity. Connector licensing and Damocles service are separate inputs even when sold as one solution. Guardian Core does not automatically include a commercial vulnerability licence or unlimited assets. Guardian Assurance provides the vulnerability and remediation operating model; the source technology and quantities remain explicit product components. The customer owns timely access, asset context, remediation decisions and approved change. Damocles owns the connector and managed activities listed in the service schedule. Unsupported systems, remediation engineering and emergency response remain separate unless included.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
Yes where a supported connector exists and the customer can provide authorised access, stable asset ownership and the required source fields.
Potentially. Each source must retain traceability and customer ownership, and duplicate or conflicting records need an agreed reconciliation model.
The selected assessment source performs technical discovery and testing. Guardian manages the customer posture, remediation, evidence and reporting around supported results.
Managed patching and remediation coordination may be included through selected products. Broader engineering and application remediation are separately scoped.
Approved exceptions record the owner, rationale, compensating control, evidence, expiry and review date rather than simply hiding the finding.
Guardian shows the source-health or unavailable state. Missing data is not converted into a zero-risk result.
Guardian does not imply universal asset discovery, complete vulnerability coverage, unlimited scanning, guaranteed remediation or automatic acceptance of a source-reported resolution.
Unsupported fields, inaccessible assets, stale agents, source outages and records without confirmed customer ownership remain visible as limitations or are excluded according to the approved policy.
Penetration testing, secure code review, cloud review and specialist engineering remain separate where deeper validation or implementation work is required.
We will map the current assessment technology, connector requirements, covered assets, prioritisation, actions, evidence and managed responsibilities.