Financial services · Seal Security

Close critical CVEs within your SLA. No upgrade required.

Seal backports the security fix into the open-source version you already run. Same version line, same API, no code changes. Your scanner sees a fixed version.

$15T+
in assets under custody, administration and management across Seal's financial services customers
2
global systemically important banks among them
20,000+
unique CVEs patched across 9 ecosystems
72 hrs
from disclosure to sealed package
Trusted by PayPal Kiteworks Censys Semperis Tufin
Where the clock comes from

Every regulator wants proof you patch on time.

Obligation Window it sets What you are held to
PCI DSS v4.0.1 One month Requirement 6.3.3: critical security patches installed within one month of release.
DORA (EU) Your policy A documented patch and update process inside your ICT risk management framework.
NYDFS Part 500 Your policy Section 500.5: timely, risk-prioritised remediation of vulnerabilities.
SOX ITGC Change control Every change reviewed and approved. A version-preserving patch is the smallest change you can put in front of a CAB.
This page is not compliance or legal advice. Seal Security does not make anyone compliant. It removes one blocker: the absence of a fix you can deploy inside the window you committed to.
The consequence

A missed patch window becomes a signed exception. Examiners read those.

The upgrade is the right long-term move. It is the wrong tool for a one-month clock. So the exception gets signed, carried forward, and read by the next examiner.

What changes with Seal

The patch arrives on the version line you already approved. You ship the fix now and schedule the upgrade on your own timeline, instead of the other way round.

Why now

AI finds the vulnerability in minutes. Your upgrade still takes months.

Frontier AI models such as Anthropic's Claude Mythos find and exploit vulnerabilities faster than most human researchers. Expect more critical CVEs in your scanner, with working exploits close behind.

⏳

The clock does not stretch

PCI DSS still gives you one month for a critical. A major-version upgrade still needs a full regression cycle. More findings means more signed exceptions.

🤖

Seal remediates at AI speed

Seal's remediation agent backports and verifies the fix on the exact version you run. Sealed packages ship within 72 hours of disclosure, so patching keeps pace with discovery.

How we do it

The fix, without the migration. A sealed version is your exact version plus the security patch, 6.5 lines on average.

Running in your build
spring-beans
4.3.30.RELEASE 4.3.30.RELEASE-sp1
CVE-2022-22965 · critical 9.8 sealed · no CVE
4.3.x reached end of life on 31 Dec 2020
CachedIntrospectionResults.java · spring-beans 5.3.18
31 Mar 2022
  PropertyDescriptor[] pds = this.beanInfo.getPropertyDescriptors();context
  for (PropertyDescriptor pd : pds) {context
+    if (Class.class == beanClass && (!"name".equals(pd.getName())the fix
+        && !pd.getName().endsWith("Name"))) {the fix
+        continue;  // only name variants of Classthe fix
+    }the fix
+    if (ClassLoader.class … ProtectionDomain.class) {the fix
+        continue;  // nobody needs to bind to thosethe fix
    if (logger.isTraceEnabled()) {context
Shipped in 5.3.18 and 5.2.20 only. Never in 4.3.x.

Verified against your version, not the newest one

Every backport is built and tested before it ships.

Builds clean against 4.3.30.RELEASE
Spring 4.3 test suite passes
Public API byte-compatible, no call sites change
Spring4Shell payload no longer binds

Delivered where your builds already look

A distinct version your tooling can resolve, pin, and audit.

JFrog Artifactory
Seal remote repository, resolves transparently
Sonatype Nexus
Same coordinates, sealed version
Seal CLI in CI
Discovery, substitution, scanner sync
Signed evidence
Patch source, SBOM entry, provenance

No application code changes. No manifest rewrites. Version pins stay yours.

The finding closes on the next scan

A real version bump, so your system of record moves on its own.

Finding
Severity
Status
CVE-2022-22965
Critical 9.8
No fix for 4.3.x Fixed in 4.3.30.RELEASE-sp1

Synced back to Snyk · Black Duck · GHAS · Wiz · Checkmarx · Aqua

the security fix · 6 lines
+ if (Class.class == beanClass && …
+    continue;
+ if (ClassLoader.class … ) continue;
How we do it

The fix, without the migration. A sealed version is your exact version plus the security patch, 6.5 lines on average.

Running in your build
spring-beans
4.3.30.RELEASE CVE-2022-22965 · critical 9.8 · no fix for 4.3.x
sealed ↓
4.3.30.RELEASE-sp1 sealed · no CVE
No application code changes. No manifest rewrites. Version pins stay yours.
  1. 01
    Isolate
    Take only the added lines from the release that fixes it.
  2. 02
    Backport
    Apply them to the end-of-life version you actually run.
  3. 03
    Verify
    Build it, test it, prove the vulnerability is gone.
  4. 04
    Deliver
    The sealed version lands in your artifact repo and CI.
  5. 05
    Close
    Your scanner sees a fixed version and the finding closes.
🔎

Starts from the scanner you run

Seal ingests findings from Snyk, GitHub Advanced Security, Checkmarx, Wiz and Trivy. It does not replace them. It gives their critical and high findings a fix.

🗂

Leaves the paper trail auditors want

A sealed version is a distinct published artifact. It lands in your lockfile, SBOM and change history, so the finding closes with a dated change, not a carried exception.

🛡

Passes vendor due diligence

Seal Security holds SOC 2 Type II and ISO 27001. Patches are delivered at build time, into the registry you already control.

⏱

Fits the release you already have

No API changes means no regression cycle for a new major. It rides your next scheduled release, inside the window.

"Thanks to Seal's product, we swiftly addressed security vulnerabilities in our outdated code packages, saving us valuable time."
Gad Meyer · Director of Software Engineering, PayPal
Next step

Close this quarter's criticals on the versions you run.

FAQ

Common questions