// CWE/CVE remediation, SAST triage, SBOM/VEX, OAuth 2.0, Okta SSO/MFA, CAB change management.
A 30-day CVE remediation SLA across every owned service teaches you fast that most findings are noise. Reachability is the difference between a real fix and a version bump performed as theater — which is the entire premise of Reachble.
At Capital One this means CWE analysis across every owned application, run on findings from an LLM-driven vulnerability scanner built to catch chained exploit paths conventional SAST misses, with each result dispositioned through model-assisted review and valid fixes shipped alongside merger delivery. It also means the Okta MFA integration for the agent-facing application, and being its SME and L2 escalation point.
SBOM and VEX — CycloneDX, OpenVEX — are where compliance meets code. A VEX statement is a claim about your own software that a machine should be able to check. Most organizations produce them by hand, in a spreadsheet, which is another way of saying they produce them once.
CAB change management belongs here too. In a regulated environment, the review is part of the system.