Hexaware launches Zero Vulnerability to close the AI remediation gap

Hexaware's new managed offering aims to verify that critical vulnerabilities are genuinely fixed in production, not just marked closed.

A brightly lit control room features a large, curved video wall displaying a vibrant digital network graphic, with multiple computer workstations and chairs arranged in rows.

Hexaware Technologies has announced Zero Vulnerability, a managed cybersecurity offering designed to help enterprise security and engineering teams reduce the backlog of unresolved vulnerabilities that AI-powered scanning tools are generating at an accelerating rate. The service is delivered through Zerovity, the company's AI-led delivery layer, and covers the full remediation lifecycle from initial finding ingestion through to verified closure in production.

The launch is anchored in a specific market failure that Hexaware positions itself to address. The Verizon 2026 Data Breach Investigations Report, cited in the company's release, found that only 26% of critical Known-Exploited Vulnerabilities were fully remediated last year, down from 38% the year prior, and that median resolution time rose from 32 to 43 days. According to Hexaware, 99% of AI-discovered vulnerabilities remain unremediated, a figure the company attributes to a mismatch between the speed of discovery tooling and the finite capacity of remediation teams.

What Zero Vulnerability does

Zero Vulnerability is structured around four stages: prioritisation, routing to the correct team or owner, fixing, and production verification. That last step is the key differentiator Hexaware is emphasising. In practice, many vulnerability management programmes close findings on a dashboard without confirming the underlying code or configuration has actually changed. Hexaware says its platform enforces a verification gate before closure.

Coverage spans custom application code, SaaS and PaaS environments, third-party software, and operating systems, which the company says require different remediation actions and different ownership structures. The platform integrates with existing security tools and workflow systems rather than requiring enterprises to replace their current stack.

Hexaware published internal evaluation data to support the offering. Across four detection lanes run on production codebases, 334 initial findings were consolidated down to 14 verified real vulnerabilities. A developer-validated review of a further 262 findings also surfaced an authentication-bypass weakness that pattern-based detection rules had not caught.

Mohit Vaish, EVP and Business Head for Cybersecurity at Hexaware, said the objective was straightforward: "make risk fall faster than new findings arrive."

Market context

The vulnerability remediation market is under sustained pressure from two directions simultaneously. AI-assisted scanning and penetration-testing tools, including those built on large language models, have significantly lowered the cost of finding weaknesses, producing far more findings than most security teams can process. At the same time, regulators in the UK, EU and US are tightening expectations around remediation timelines: NIS2 in Europe and the SEC's cybersecurity disclosure rules in the United States both create liability pressure around material unresolved vulnerabilities.

Hexaware is entering a space occupied by established managed security service providers and a growing cohort of specialist remediation-automation vendors. The competitive question for enterprise buyers is whether a services-led approach, which Hexaware is offering, provides better outcomes than point-product automation tools that promise to auto-remediate findings without human-in-the-loop validation. Hexaware's internal data, showing a 95% false-positive rate in one evaluated pipeline, illustrates why the company is betting that pure automation without contextual triage produces noise rather than results, though buyers will want independent benchmarks before drawing conclusions.

The offering is positioned as part of Hexaware's broader Zero Friction Enterprise framework, which groups several service lines under a shared brand. The company is listed on India's NSE and operates globally; it did not disclose pricing or name any launch customers in this release.