Back to the registry
Agent passport

Zafran Autonomous Workflows (add on)

Zafran · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Machine-speed exploitation has made manual vulnerability management workflows structurally obsolete. VM teams are still hand-stitching runtime context, manually validating exploitability, chasing down asset owners, and building reports from scratch - while attackers operate on timelines measured in hours, not weeks. The workforce cannot scale fast enough to meet the threat at its new speed.

Zafran Autonomous Workflows deploys Background Agents across the full detection-to-neutralization lifecycle, running continuously on a schedule or trigger without waiting for human initiation.

Show the rest of the publisher’s description (2 more lines)

The Zero Day Agent identifies assets impacted by emerging zero-day threats, including those without a named CVE, by correlating threat intelligence against SBOM data from any source. The Exploitability Agent validates real-world exploitability against runtime state, architecture, OS version, and package version - so every finding that reaches a human has already been confirmed against live environment conditions. The Ownership Agent correlates tags, login traces, EDR context, and asset metadata to route tickets to the right team automatically, eliminating the owner-chasing that consumes analyst time today. The Remediation Agent generates remediation scripts, simulates patch impact, and builds mitigation playbooks without manual effort.

Work Item Policies automate ticket creation, routing, and closure based on configurable rules, connecting directly to Jira and ServiceNow. All agent actions run with human-in-the-loop approval on sensitive workflows, so your team remains in control of every consequential decision while the repetitive correlation work happens automatically.

Highlights

Highlighted by the publisher on AWS Marketplace.

Four specialized agents cover the full VM workflow automatically. The Zero Day Agent identifies impacted assets before a CVE is named. The Exploitability Agent validates findings against live runtime conditions. The Ownership Agent routes tickets to the right team. The Remediation Agent generates scripts and playbooks - all without manual initiation.

Eliminate owner-chasing, deduplication, and manual exploitability validation for good. Autonomous Workflows handles the repetitive correlation work that consumes VM analyst time today, freeing your team to focus on decisions that require human judgment rather than tasks that can be automated.

Human-in-the-loop approval on every sensitive action. Agents run continuously on schedule or trigger, but consequential workflows always require explicit team sign-off. Full auditability across every automated action. Connects to Jira and ServiceNow via Work Item Policies for automated ticket creation, routing, and closure.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanyZafranAutomated

Plans and pricing as listed

4 listed
Zafran Agentic Exposure Management
  • Units
$10,000.00
P1M
Zafran Agentic Exposure Management
  • Units
$120,000.00
P12M
Zafran Agentic Exposure Management
  • Units
$240,000.00
P24M
Zafran Agentic Exposure Management
  • Units
$360,000.00
P36M

Refund terms

As stated by the publisher on AWS Marketplace.

https://www.zafran.io/legal/terms-of-use

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Publisher resources

3 links
See product videowww.zafran.ioSource
Publisher linkaws.amazon.comSource
Publisher linkaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
4 plans listed
Delivery
SaaS
support@zafran.io
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.