See your entire attack surface. As one unified picture.
Three types of data. One unified workspace.
Asset Catalog Integration
Findings
Threat Intelligence
How connectors work
API connection
File upload
Connector filters
Every asset type, in one inventory
Every tool speaks a different language. Hackuity translates.
Common data model
CVSS normalization
Full source history
CPE consolidation
One server, detected by five tools. One asset in Hackuity.
FACTORIZATION PROCESS EXAMPLE
A.C.E IDENTIFIER WEIGHTS
One vulnerability. One entry. Every source accounted for.
By correlating vulnerability records by CVE and affected asset, Hackuity typically eliminates 10% to 45% of duplicate CVE findings, while preserving the discovery context from every reporting source.
Misconfigurations, outdated software, AD risks, and cloud policy violations don't have CVE IDs. Hackuity uses VulnDB Family, its proprietary finding repository, to normalize and deduplicate these non-standard findings across sources.
Fits your infrastructure. No compromise.
SaaS
On-Premises
Organize your attack surface. Spot the blind spots.
Perimeters & groups
Coverage visibility
Tags & custom fields
Role-based access
You've unified the picture. Now, what actually matters?
THE PROBLEM RAW DATA ALONE CAN'T SOLVE
How does this work in practice?
How does Hackuity collect data does it require deploying agents?
No, Hackuity is agentless. It leverages the APIs of your existing security scanners and asset managers (like Qualys, Snyk, Wiz, etc.) to collect asset properties and vulnerability findings on a schedule you configure.
Can I filter what each connector brings in?
Yes. Each connector offers granular filters by asset tag, perimeter, severity threshold, scan profile, or date. You control exactly what enters your Hackuity workspace.
What if the same server is reported by five different tools?
A.C.E evaluates each source entry against a weighted Decision Tree. Once a match is found (e.g. FQDN), the engine stops and creates a single unified asset enriched with data from all five sources. No double-counting.
Does Hackuity deduplicate non-CVE findings like misconfigurations?
Yes. Through VulnDB Family Hackuity's proprietary finding repository non-CVE findings (misconfigurations, outdated software, AD risks) are normalized and deduplicated across sources, even when they don't share a CVE ID.
What if automatic asset correlation fails?
If two assets have no overlapping identifier, A.C.E won't merge them automatically. In that case, an operator can manually merge them from the UI, preserving source history and deduplicated findings from both assets.
Note: manual merges are one-way once assets are merged, they cannot be split back apart, and the operation becomes irreversible after an 8-hour grace period.




