Breakglass
See it work
For the one IT person at a small hospital, and the MSSP behind them

What can you safely do before the fix can be installed?

Breakglass watches the government's list of flaws attackers are already using. When one hits software your hospital runs, it proves the flaw matters here, applies one pre-approved, reversible protection, and proves patients can still book. If they can't, it undoes the change by itself.

INC-0006 · CVE-2025-55182
Patient portal · /portal/messages
Recorded run
✓ Semgrep: the portal's code reaches the flawed part
✓ ClickHouse: 68 requests on that route in 5 min, 5 unblocked
✕ Shut the portal down → denied by policy
✓ Applied BG-CTL-PORTAL-REQUIRE-SESSION-FOR-ACTIONS
✓ A scripted patient still booked
Exposure closed in
0:40
✓ CONTAINED
KEV 1,739 entries · polled 13:37 PDTRecordedMatched against Mercy Valley, a fictional 25-bed hospital
CVE-2023-22894 Strapi Strapi · added Oct 8, 2026
Not in estate
CVE-2021-3199 ONLYOFFICE Docs · added Oct 8, 2026
Not in estate
CVE-2016-3081 Apache Struts · added Oct 8, 2026
Not in estate
CVE-2015-5477 ISC BIND · added Oct 8, 2026
Not in estate
The problem

Attackers now move before the fix does.

Picture Hollis, the only IT person at a 25-bed rural hospital. This morning a flaw in the patient portal's framework joined the list of flaws attackers are using. The portal vendor hasn't shipped a fixed build. Hollis can leave the portal exposed, or take it offline and stop patients from booking. Both answers are bad.

A small hospital gets the same flaw and the same urgency, with no security team.

How it works

Signal, proof, one bounded action, a hard policy, measured, undoable.

No one presses a button. Every step is logged, and every screen says whether it's live, replayed or simulated.

01WatchPolls CISA's list of flaws attackers are already using. A new entry lands in the advisory store and starts an investigation by itself.
CISA KEV · MongoDB
02Prove it matters hereTwo independent checks: the code reaches the flawed part, and that route is being hit right now. One without the other changes nothing.
Semgrep · ClickHouse
03Choose one controlAn agent picks one ID from a catalog of pre-approved, reversible controls: turn off one feature, add one blocking rule, tighten one setting.
Guild · OpenAI
04Refuse the drasticShutting a service down is denied by the credential policy, not by the model's manners. A phone call asks a human instead.
Guild policy · ElevenLabs
05Prove care still worksRisky-route traffic must fall to zero and a scripted patient must still book. If not, it reverts by itself.
ClickHouse · Playwright
Safety

The model chooses. The policy decides.

Would a hospital ever let an AI change its systems? Only if the AI can't do anything drastic, by construction.

It outputs a control ID, never rule logic.

Every possible change is written, tested and reviewed before an incident. The agent can only name one.

A credential proxy refuses the drastic, and DENY wins.

The agent never holds the admin credential. Guild's auto-created allow-all rule is deleted; anything not explicitly allowed is denied.

Patient-critical routes are never on the "may disable" list.

So an attacker can't trigger Breakglass into knocking out booking, sign-in or records.

From INC-0006, a recorded run: the agent asked to take the portal offline; the proxy refused before any credential was attached. Recorded run

Proof

"200 OK" isn't proof. A patient booking is.

After every control, two things must be true: zero requests get through to the risky route, and a scripted patient signs in and books an appointment. Otherwise the control comes off, by itself, and the next candidate is tried.

Exposure closed
0:40
From the moment CVE-2025-55182 reached the advisory store to a verified close, against a federal due window measured in days. Recorded run

And the A/B grading Breakglass against an unmanaged copy uses a scoring rule committed before the first run. See the evals.

fig. 4 Verification · risk down, care up

ClickHouse, per 10 s
probes that got through to /portal/messages, per 10 s
2004:23:1004:24:50control applied0
patient journeys passing, % (one every 30 s; held between runs)
100004:23:1004:24:50control applied100%
Sign in✓ 100 ms
jordan.lee → /portal
Find a slot✓ 12 ms
8 slots listed
Book✓ 58 ms
Next-Action: book → 200
Confirm✓ 1 ms
Booked · MV-UH8F
✓ EXPOSURE 0 UNBLOCKED / 20s✓ PATIENT JOURNEY · PLAYWRIGHT✓ CRITICAL ROUTES 0 × 5xx
Where it fits

Others prioritize and recommend. Breakglass applies, verifies and undoes.

Vulnerability management

Tenable, Rapid7 and Qualys VMDR prioritize by exploitability and drive remediation workflows. They assume someone can patch.

Compensating controls and runtime defense

Zafran maps vulnerabilities to compensating controls; Miggo does application detection and response. Both are funded and close.

Breakglass's wedge

The closed loop for the patch gap: two-factor proof → one pre-approved reversible control → care verified → auto-revert, under a policy the agent can't exceed.

Why this is different

Breakglass is a safety case for every agent action: prove exposure, constrain the credential, protect the patient journey, and reverse the action when the proof fails.

Pricing

$49 per protected service a month. Every pilot starts in shadow mode.

For four weeks Breakglass watches and proposes but changes nothing. Write authority is earned control type by control type, once its proposals match what your engineers would have done.

See plansPilots by request: @SidraMiconi on X