CVE Visibility Platform
Kotak Mahindra Bank
The security team got vulnerability reports as PDFs every quarter. By the time anyone read them, the data was already stale. Nobody could answer a simple question: is CVE-2024-XXXXX running in production right now?
I built a Python service that pulls container scan results and joins them against what is actually scheduled in the cluster — not what is in the registry, what is running. A critical CVE in an internal batch job gets deprioritised. A medium CVE in an internet-facing pod gets flagged immediately.
What changed
- Security team went from 3-day manual triage to about 20 minutes.
- Auditors get the same dashboard engineers use — no more separate compliance reports nobody trusts.
- First time the platform team got a thank-you email from security.
Stack: Python, Kubernetes API, container scanning, a lot of Slack threads