Zafran Autonomous Workflows (add on)
Zafran · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Machine-speed exploitation has made manual vulnerability management workflows structurally obsolete. VM teams are still hand-stitching runtime context, manually validating exploitability, chasing down asset owners, and building reports from scratch - while attackers operate on timelines measured in hours, not weeks. The workforce cannot scale fast enough to meet the threat at its new speed.
Zafran Autonomous Workflows deploys Background Agents across the full detection-to-neutralization lifecycle, running continuously on a schedule or trigger without waiting for human initiation.
Show the rest of the publisher’s description (2 more lines)
The Zero Day Agent identifies assets impacted by emerging zero-day threats, including those without a named CVE, by correlating threat intelligence against SBOM data from any source. The Exploitability Agent validates real-world exploitability against runtime state, architecture, OS version, and package version - so every finding that reaches a human has already been confirmed against live environment conditions. The Ownership Agent correlates tags, login traces, EDR context, and asset metadata to route tickets to the right team automatically, eliminating the owner-chasing that consumes analyst time today. The Remediation Agent generates remediation scripts, simulates patch impact, and builds mitigation playbooks without manual effort.
Work Item Policies automate ticket creation, routing, and closure based on configurable rules, connecting directly to Jira and ServiceNow. All agent actions run with human-in-the-loop approval on sensitive workflows, so your team remains in control of every consequential decision while the repetitive correlation work happens automatically.
Highlights
Highlighted by the publisher on AWS Marketplace.
Four specialized agents cover the full VM workflow automatically. The Zero Day Agent identifies impacted assets before a CVE is named. The Exploitability Agent validates findings against live runtime conditions. The Ownership Agent routes tickets to the right team. The Remediation Agent generates scripts and playbooks - all without manual initiation.
Eliminate owner-chasing, deduplication, and manual exploitability validation for good. Autonomous Workflows handles the repetitive correlation work that consumes VM analyst time today, freeing your team to focus on decisions that require human judgment rather than tasks that can be automated.
Human-in-the-loop approval on every sensitive action. Agents run continuously on schedule or trigger, but consequential workflows always require explicit team sign-off. Full auditability across every automated action. Connects to Jira and ServiceNow via Work Item Policies for automated ticket creation, routing, and closure.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
4 listed- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
https://www.zafran.io/legal/terms-of-use
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

