← News

Clone Systems rebuilds CloneGuard with private AI that ranks what to fix first

Clone Systems said it rebuilt CloneGuard, its vulnerability scanning and penetration-testing platform. The release quadruples the detection library, adds authenticated web/API testing, extends internal scans to remote hosts via lightweight agents, and adds a privately hosted AI assistant that ranks findings by what to fix first — with plans starting at $185/year and online checkout (company).

SAFETY desk — same-day company primary that vulnerability scanning is shipping with private, in-house AI remediation ranking — not “paste findings into ChatGPT” — while authenticated and agent-based coverage closes gaps scanners usually miss.

Authenticated testing, as the same wire has it: unauthenticated testing reports what is visible from outside an application. Most business logic sits behind the login. CloneGuard now signs in with customer-supplied test credentials and assesses the web applications and APIs that only a logged-in user can reach. An API is an application programming interface — the machine-to-machine doors an app exposes. The same capability extends to Clone Systems’ web application penetration testing, which the company says now runs from inside a valid session against privileged workflows and role-based permissions. File that behind-the-login picture as Clone Systems’. This desk did not log in to a customer app.

Internal scanning, still company: lightweight endpoint agents on Windows, macOS, and Linux report software inventory to the platform, extending internal scanning to remote and work-from-home machines that a network scan cannot reach. Because the platform already holds the inventory, the company says vulnerability checks run against it in seconds and can run daily. When a new vulnerability is published, affected hosts are identified immediately rather than at the next scan window. File that agent / inventory / daily-check picture as Clone Systems’. This desk did not install an agent.

Findings, company: tagged against the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog — CISA’s KEV list of flaws already exploited in the wild — and linked to the exploitation context behind them. Each scan also renders an interactive attack-path view showing how findings chain together, so remediation starts with what an attacker would reach first. File the KEV tags and the attack-path view as Clone Systems’. This desk did not walk an attack path.

Named voice on the release: Elyse Hamilton, vice president of business development at Clone Systems. She says the uncomfortable part of scanning behind the login is that you find more, and that is why the company did not ship the scanning without the assistant — a longer list only helps if someone tells you which three things to fix on Monday. File the name, title, and that fix-these-first line as hers, via Clone Systems. Her quotes are color only beyond that attributed line and stay in Sources.

Private AI assistant, still company: every CloneGuard report leads with a fix-these-first section. For the findings that matter most, the assistant names the affected software and the specific action required. It answers questions about a customer’s environment in plain language and compares any two scans to show what has been remediated and what is new. The assistant runs entirely inside Clone Systems’ environment. The company contrasts that with scanning platforms that ask customers to supply their own public large-language-model API key, which sends vulnerability data outside the customer’s control. A large language model, or LLM, is the kind of AI that writes and answers in sentences. The CloneGuard assistant requires no customer API key, never transfers customer data to an outside provider, and never uses customer data to train any model. File that in-house / no-customer-key / no-outside-transfer / no-training picture as Clone Systems’. This desk did not ask the assistant a question. This desk is not claiming the assistant auto-patches production without a person reviewing the fix.

Availability and pricing, company: CloneGuard is available today with published pricing and online checkout, with no sales call required. Plans start at $185 a year for external vulnerability scanning of a single IP address, and every subscription includes Clone Systems’ U.S.-based security operations center, staffed around the clock by certified analysts. A security operations center, or SOC, is the team that watches alerts. More than 100 resellers — including managed service providers, payment processors, hosting companies, and Qualified Security Assessors (QSAs) — deliver CloneGuard under their own brands. A QSA is a person or firm certified to check Payment Card Industry compliance. File the available-today / $185 / 24/7 SOC / 100-plus-resellers lines as Clone Systems’. This desk did not buy a scan.

About-box context, optional and company-attributed: Clone Systems has provided managed security and compliance services since 1998, and has been a PCI SSC Approved Scanning Vendor since 2007. PCI SSC is the Payment Card Industry Security Standards Council — the group that writes the card-data security rules. An Approved Scanning Vendor, or ASV, is a firm allowed to run the official scans those rules require. Headquartered in Philadelphia with operations in Larnaca, Cyprus. File those history and location lines as Clone Systems’. This desk did not audit the PCI listing.

Plain English for the rest of the card: vulnerability scan = an automated check for known security weaknesses. authenticated testing = logging in so the scanner can see what a signed-in user sees. KEV = CISA’s list of flaws already exploited in the wild. SOC = security operations center, the team that watches alerts. LLM = large language model, the kind of AI that writes and answers in sentences. API = the machine-to-machine doors an app exposes. ASV = Approved Scanning Vendor, a firm allowed to run official PCI scans. QSA = Qualified Security Assessor, certified to check card-data compliance.

PRIMARY here: Clone Systems’ 15 Sep 2026 PR Newswire company release — Tier A PRIMARY company source, the original record. The CloneGuard AI Assistant product page is product-home context, not a second originating newsroom. The rebuilt CloneGuard announce, the company-claimed 4x detection library, authenticated web/API testing, Windows/macOS/Linux endpoint agents for remote hosts, CISA KEV tagging, the interactive attack-path view, the privately hosted fix-these-first assistant, the no-customer-LLM-API-key / no-outside-transfer / no-training-on-customer-data lines, the available-today / $185-per-year-single-IP / 24/7 U.S. SOC / 100-plus-resellers terms, the Hamilton title, and the 1998 / PCI ASV-since-2007 / Philadelphia / Larnaca about-box are company-attributed. The 4x library line and the reseller count stay company-attributed — not independently verified here. NOT claimed: independent detection benchmarks, that the assistant auto-patches production without human review, a customer-logo roster, that this desk tested CloneGuard, a stock tip, or investment advice. Distinct from the already-filed sps-commerce-max-ga, stackhawk-wingman, digicert-ai-trust-manager, esentire-atlas-aidr, coder-claude-code-agent-relay, and wso2-agent-manager-ga.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 15 Sep 2026 Clone Systems announced a rebuilt version of CloneGuard, its vulnerability scanning and penetration testing platform. A vulnerability scan is an automated check for known security weaknesses. Penetration testing means trying to break in the way an attacker would. The company PRIMARY is Clone Systems, Inc.’s PR Newswire release “Clone Systems Rebuilds CloneGuard With 4x the Vulnerability Detection, Private AI Remediation, and Authenticated Testing You Can Buy Online,” dated September 15, 2026, 16:51 ET, SOURCE Clone Systems Inc., and datelined PHILADELPHIA. That company wire is the filing event. These are company claims. This desk did not run CloneGuard. The “4x” detection-library line is Clone Systems’ claim — not an independent benchmark this desk ran.

Sources