Know your products.
Keep their cybersecurity under control as they evolve.
A manufacturer does not manage one security file. It manages projects, products, equipment, variants, software versions, components, dependencies and years of change. The first challenge is therefore to keep a reliable picture of what really exists — before talking about vulnerabilities, threats or risk.
VAST structures this knowledge around Projects and Assets. Each Asset represents a product or equipment that lives in the platform, with its versions, technical composition, relationships and history. As the product evolves, VAST keeps the context teams need to search, understand the impact of a change and support the cybersecurity activities that depend on it.
Projects & Assets · Asset Inventory · Versions & Dependencies · Portfolio Search · Vulnerability & VEX · Threat & Risk · Reporting
Everything starts from product knowledge. Risk and the CRA are not the starting point: they become reliable because that knowledge already exists.
Projects & Assets
Start by knowing which products exist, which project they belong to and what state they are in.
In an industrial organization, product cybersecurity cannot be managed product by product in separate files. Different teams work across several projects, often on product families that share components, suppliers or software building blocks. Without a common structure, knowledge quickly becomes fragmented.
VAST uses Projects to organize the work and Assets to represent the products or equipment that need to be secured. Users can move from a portfolio view to a project and then to a specific Asset without losing context. This hierarchy gives teams a common reference: they know which product they are discussing, which version is concerned and which information belongs to it.
The Asset becomes the reference point around which technical and cybersecurity information can evolve over time.
à intégrer
Asset Manager & Asset Inventory
See the product as it really exists, not only as a row in an inventory.
A product name and a version number are not enough to understand its cybersecurity surface. Teams need to know what the product contains, where software runs, which applications provide product functions, what data is handled, which accounts are used, how components communicate, and how the product is maintained or updated.
The Asset Inventory provides this technical knowledge base in VAST. It brings together and connects the important product elements: **Hardware, Software and SBOM, Accounts, Data, Business Apps, Interconnections, Tools and Updates**. Dependencies and relationships between these elements gradually create a much more useful picture than a simple administrative inventory.
The goal is not documentation for its own sake. This knowledge helps teams find a dependency, understand a communication path, locate a component, place a vulnerability in context or prepare a cybersecurity assessment without rebuilding the product every time.
à intégrer
Versions & history
The product changes. Its Asset must keep telling the right story.
A new release can change several things at once: a library moves to a new version, an application changes a dependency, an interface appears, a technical account evolves, or the update mechanism is strengthened. If the inventory stays frozen, the cybersecurity work around it immediately starts losing context.
In VAST, the Asset is designed to evolve with the product. Versions and revisions preserve what was true at a given point in time while the next state is being built. Teams can understand how the product changed without overwriting its history, and cybersecurity activities can stay connected to the right technical state.
That continuity is what turns an inventory into real **Asset Intelligence**.
à intégrer
Dependencies & product relationships
A technical dependency is more than an SBOM entry.
Knowing that a package is present is useful. Knowing **where it is used, what depends on it and which products contain it** is much more valuable. In connected and embedded products, the same library, component or technology may appear across several applications, versions and projects.
VAST keeps the useful relationships around the Asset so product composition does not remain a flat list. Teams can explore dependencies and understand the possible consequences of a change, obsolescence issue or supply-chain problem much faster.
When the question becomes "what depends on this element?", the information is already part of the product context.
à intégrer
Portfolio search
"Where do we use this component?" should not start a multi-day investigation.
A Product Security team rarely works on one isolated Asset. When a library is compromised, a supplier reports an issue or a technology must be removed, the important question immediately becomes cross-product: which Projects, Assets and versions are affected?
VAST lets teams search product knowledge across the portfolio. A library, component, CVE, license, technology, supplier or another criterion can become the starting point to find affected products and open their context directly.
This is valuable even before Risk Assessment: it reduces the time needed to understand the real scope of an issue and decide where effort should be focused.
à intégrer
Once products are known, security becomes actionable.
Vulnerabilities, threats and risk are read in the real context of the product — not as isolated feeds.
Vulnerabilities & VEX
A CVE becomes useful when you know where it exists and what it means for the product.
Vulnerability feeds create alerts. They do not always know how a component is actually used inside your equipment. VAST places the vulnerability back into the Asset and its version: which component is affected, which products contain it, how it is used and which decisions have already been made.
Teams can then investigate exploitability, document the conclusion, follow remediation and produce VEX information when needed. New information does not replace the history; it enriches product knowledge and helps show which decisions may deserve another review.
Threat Engine
Identify the threats that deserve attention for the product, without turning the assessment into a catalog exercise.
A generic threat database may contain a large amount of information without telling teams which threats actually matter for a specific product. VAST Threat Engine uses the context already built around the Asset to help identify relevant threats.
Threat knowledge can come from complementary spaces: VAST knowledge, recognized sources such as MITRE ATT&CK, and organization-specific catalogs when the business, technology or previous experience requires more targeted coverage.
The website does not need to explain the internal mechanics. What matters to the user is simple: threat knowledge joins product knowledge instead of living in a separate database.
Risk Assessment
Risk Assessment becomes stronger when it does not begin by rebuilding the product context.
Risk Assessment remains a major VAST capability, but it comes after understanding the Asset. The analyst starts with structured context: product, version, components, dependencies, data, interfaces, vulnerabilities and relevant threats. More time can therefore be spent on reasoning and less time collecting the same information again.
The assessment also stays connected to the facts that supported it. When the product changes, VAST can help identify the elements that may affect an existing assessment and focus the review where it matters. Important decisions remain under human control and their justification stays traceable.
Dashboards & portfolio visibility
See one product in detail while keeping visibility across the portfolio.
The same platform must answer very different questions. An Asset Manager wants to know whether the technical knowledge of a product is complete. A Product Security team wants to see open vulnerabilities or shared components. A manager wants to identify issues that cross several projects. An analyst wants to open the items that need review.
VAST dashboards let users move from a consolidated view to the Project, the Asset and the source information. The goal is not to create a decorative score, but to make the state visible and support drill-down to the context behind each indicator.
à intégrer
CRA compliance & evidence
The CRA reinforces an operational reality: manufacturers need to keep knowing and following their products after they reach the market.
Compliance does not begin with a final report. It first depends on knowing which products and versions exist, what they contain, which vulnerabilities affect them, which decisions were made and which evidence can still be found over time.
VAST was designed around that continuity. Asset Inventory, versioning, portfolio search, vulnerability management, threat analysis, Risk Assessment and Evidence Management work from the same product knowledge. The platform helps teams structure and maintain the information needed for their CRA process without reducing compliance to a checklist.
See how VAST supports CRA readiness
à intégrer
Reporting & evidence
Evidence is much easier to produce when information has been maintained throughout the lifecycle.
When Projects, Assets, versions, assessments and decisions live in the same environment, reporting no longer starts with manual data collection. VAST can produce views and reports from the known product state and keep the connection to the information behind them.
Sharing remains controlled. A customer, integrator or auditor may need to understand a decision without receiving the complete internal architecture of the product.
Share the ingredients, not the recipe.
à intégrer
Integrate with your tools
Your engineering tools remain your engineering tools.
VAST is not designed to replace ALM, PLM, development tools, pipelines or SBOM sources. Those systems continue to produce the information that describes the product. VAST brings the cybersecurity-relevant information together, adds the context teams need and connects it to the activities that use it.
The platform becomes a cybersecurity continuity layer across information that already exists, without asking teams to rebuild their engineering work inside a security tool.
à intégrer
Show us one of your products. Start by seeing what VAST can understand about it.
From a Project and an Asset, VAST builds the context that supports search, version tracking, dependency analysis, vulnerability handling, threat and risk assessment, and evidence over time.