incipient.ai
← Intelligence Hub

Architecture · 2026-06-29 · 9 min

Beyond Vulnerability — a Unified Control Framework and AI Across the Lifecycle

One asset graph, one ownership map, one risk register, one set of dashboards — extending from vulnerabilities to InfoSec, BC/DR, access, change, and HIPAA/SOC 2/PCI audit evidence, accelerated by an AI engine with human-in-the-loop.

Vulnerability management is the beachhead, not the destination. The same platform, schema, ownership model, and reporting engine that unify vulnerabilities extend naturally to every other risk and security control — making them the foundation for a single source of truth across the Risk & Security function.

The promise: one asset graph · one ownership map · one risk register · one set of dashboards — across every control domain.

Beyond vulnerability — a unified controls platform

Vulnerability management is operational today; the same model absorbs the rest of the control landscape on a roadmap:

Control domainScope
Vulnerability managementFindings, patches, SLAs, KEV (operational)
Information securityISO 27001, NIST CSF controls
Storage controlsClassification, encryption, retention
Business continuityBCP, DR, RTO / RPO tracking
Access & identityReviews, joiner-mover-leaver
Change managementApprovals, rollback, audit trail
Compliance & auditSOC 2, PCI, HIPAA evidence
Third-party riskVendor assessments, attestations

For a healthcare manufacturer, the payoff is concrete: HIPAA and FDA audit evidence — the control tests, their pass/fail status, and the remediation trail — come out of the same engine that runs vulnerability SLAs, instead of a scramble of spreadsheets before every audit.

The control data model

What makes this "one platform" rather than eight tools is a shared schema. Controls and their rules, actions, and status are captured in one model, and the evidence of each control's execution in another:

Control (input) model — Control, Control Type, Control Rule, Control Detail, Action, Action Type, Plan, Configuration — captures every control and its rules and actions, with version control, for audit and compliance.

Evidence (output) model — Evidence, Evidence Detail, Evidence Status (pass / fail / custom), Evidence Rule, Evidence Action, Rule Status — captures the result of every control test, keyed to an application and artifact.

Control ──< Control Rule ──< Action           (what should be true, and what to do)
   │
   └──► test run ──► Evidence ──< Evidence Detail
                        │
                        └── Evidence Status: PASS / FAIL / NEEDS ATTENTION

Because evidence is keyed by Application ID, control status rolls up from a single control to an application to a whole portfolio — which is exactly what a portfolio dashboard needs.

Reporting that rolls up and drills down

The evidence model powers a layered set of dashboards, refreshed daily:

  • Portfolio control summary — for executives and application/business owners: counts of controls Met / Needs Attention / Not Met per application, with trend, driven by the Application ID.
  • Control summary details — for control owners: pass/fail counts per control against an owner-set passing threshold, with status and trend.
  • Evidence drill-down — for stakeholders: the individual evidence items behind each control, pass/fail with reason, over a selected date range.

One number — "how many controls are Not Met, and where" — is answerable from the top, then traceable all the way down to the failing evidence item.

AI across the lifecycle

Machine-learning and large language models accelerate every stage and reduce the manual load on the security team:

StageAI capability
IdentifyAnomaly detection on scan results, auto-classification of new assets, false-positive filtering at ingest
PrioritizePredictive exploit-likelihood (ML), business-context risk scoring, threat-intel correlation at scale
RemediateSuggested patches & code fixes (LLM), auto-generated remediation playbooks, rollback-risk prediction
ReportNatural-language executive summaries, plain-English query of findings, trend forecasting & anomaly alerts

The engine is LLM-powered triage + ML scoring models + threat-intel embeddings — with human-in-the-loop for high-risk actions. That last clause is the whole game: AI drafts the fix, prioritizes the queue, and writes the summary, but a human approves anything that changes a regulated system — the same HITL governance and harnessed-agent discipline this hub covers throughout.

The path to implement

  1. Make the vulnerability platform the template — one schema, one ownership model, one reporting engine.
  2. Onboard adjacent control domains (InfoSec, storage, BC/DR, access, change, compliance, third-party) to the same model.
  3. Key evidence by application so status rolls up from control to portfolio.
  4. Add an AI engine for triage, scoring, remediation drafting, and reporting — with HITL on high-risk actions.
  5. Serve audit evidence (HIPAA, SOC 2, PCI, FDA) from the same repository, continuously — not at audit time.

Incipient's GovPilot is this unified control and evidence engine, LineageLens is the one asset graph beneath it, and AI Harness runs the AI engine with governed, human-in-the-loop actions. It is the MCP/agent governance marketplace pattern applied to security controls: one registry, one risk register, one audit trail.

Talk to us about a unified control framework →