At Jamaica Broilers Group, the problem was ordinary enough to be dangerous. A lean IT team had to keep software updated across the business. Microsoft applications were only part of the job. Third-party programs, including Adobe software, required attention too. Manual patching consumed time; updates slipped. In Vicarius’s published case study, the company describes moving endpoint patching from once every three months to within a week.
- vRx combines finding, ranking and fixing software vulnerabilities.
- Patches, scripts and selective in-memory protection provide different repair paths.
- The buying test: can your team verify the fix, without disrupting the business?
There is an entire cybersecurity business hidden inside that interval. A scanner can tell you a computer is vulnerable. Someone must then decide whether the finding matters, obtain a fix, choose a maintenance window and confirm the repair worked. Every step sounds reasonable. Together, they can turn a known defect into a long-term houseguest.
01The handoff is the product opportunity
Vicarius began in 2016 with Michael Assraf, Yossi Ze’evi and Roi Cohen. Its early proposition was less glamorous than catching a mysterious hacker: bring security and IT into the same repair process. Security wants exposure reduced. IT wants applications running. Both can be right while the vulnerable machine remains untouched.
The company’s 2022 funding announcement described this conflict explicitly. Its platform was then called TOPIA. Today, vRx combines vulnerability discovery, contextual prioritization and remediation. The expertise runs through endpoint software, vulnerability research and the practical mechanics of changing systems. It is selling the completion of work that other tools identify.
Cyflare, a managed security services provider, supplies the sharpest customer explanation. Its old scanner produced findings that still needed manual prioritization and patching. “It gave us a report. That’s it,” chief customer officer Eric Dowsland says in the vendor’s case study. A very efficient messenger had delivered another pile of homework.
“It gave us a report. That’s it.”Eric Dowsland · Chief Customer Officer, Cyflare
02Three ways out of the waiting room
vRx offers several routes from finding to action. vPatch deploys available updates. vScript handles changes that require executable instructions rather than an installer: a configuration adjustment, for example. vShield provides patchless protection for selected vulnerabilities. Risk prioritization helps decide which exposed assets deserve attention first, rather than treating every severity score as a marching order.
The patchless option is the distinctive wrinkle. Vicarius describes instrumentation inside a running application’s memory, where protection can inspect and block exploitation attempts without rewriting the application binary. It buys breathing space when a patch has not arrived, a restart is awkward or a legacy application cannot be replaced immediately. A hospital or factory does not welcome “just reboot it” as a business strategy.
The limits matter. Vicarius’s technical explanation says the underlying vulnerable code remains. Coverage is selective, and some exploit patterns are harder to distinguish from legitimate activity. The protection requires an endpoint agent. For supported cases it is a compensating control; a validated permanent patch remains the destination. Buyers should test the actual applications and vulnerabilities they need covered.

03The chicken business offers a useful test
Jamaica Broilers did not begin by automating every machine indiscriminately. Its team concentrated on laptops and desktops. Server updates remained more complicated, and the customer feedback mentions a desire for a cloud testing environment. The persuasion came from solving the third-party patching work that its existing approach handled poorly, with support helping through the setup learning curve.
That is a practical procurement lesson: pick a troublesome workflow, measure its delay and evaluate the replacement there. The published quarterly-to-weekly change is a customer account, not a promise that every estate will behave identically. Production servers, maintenance windows and unusual software dependencies deserve their own trial. A fast workstation rollout cannot certify a delicate server.
04The bill follows the endpoints
Vicarius makes money through software subscriptions. Its current pricing page requests a custom quote, generally based on managed endpoints, package, volume and contract term. Annual and multi-year agreements are available; managed security providers may receive consumption-based pricing. Buyers therefore need an estate count and a scope discussion, not merely enthusiasm for a demo.
The distribution model includes service providers and resellers. Pax8 lists Vicarius in its marketplace. Cyflare’s case study describes managing multiple customer environments through one console without expanding the team in proportion. For an MSSP, the attraction is quite concrete: adding a client should not automatically mean adding another person to chase updates.
Investors have financed that proposition. A $24 million Series A in February 2022 was led by AllegisCyber Capital, JVP and AlleyCorp. The January 2024 announcement added a $30 million Series B led by Bright Pixel, with AllegisCyber, AlleyCorp and Strait participating. The stated plans included international expansion and further AI development.

05The AI gets a supervisor

In March 2026, Vicarius introduced a second flagship product, vIntelligence. It connects existing security tools, validates exposures and supplies guidance, either independently or alongside vRx. That makes incumbents such as Tenable and Qualys possible inputs as well as buying alternatives. The market position is remediation and exposure management, with integration becoming part of the sales argument.
September brought ScriptAI inside vRx. Vicarius says it generates and validates detection and remediation scripts in under an hour. Its published safeguards include researcher review, a deterministic pass-or-fail judge, signed evidence and a sequence covering prechecks, application, verification and rollback. The interesting engineering choice is to give generated code a gatekeeper before production.
06Count the repairs
Vicarius’s September announcement reports more than 1,000 customers in 80 countries. That breadth makes the repair problem commercially plausible; it does not make every automation claim universal. The company now sells both the ability to judge exposure and the ability to act on it. Those are useful neighbors to have.
The idea a reader can copy is smaller than a platform purchase. Follow one vulnerability from discovery to verified closure. Name its owner. Count the handoffs. Record what actually changed on the machine. Then decide which steps can safely be automated. A ticket may be beautifully organized, correctly assigned and entirely incapable of protecting a computer.
Open the toolbox
Explore the Vicarius platform, pricing options, vSociety research and company articles.
Watch the Meet vRx product walkthrough or browse Vicarius Studios. Read the newsroom for announcements.