The product

PatchMortem — Patch failure triage and rollback orchestration.

Automated patch failure classification, rollback, and RBI-compliant audit trail for Indian BFSI enterprises.

PatchMortem is Zurlux Technologies' first product. It is an automated patch failure classification, rollback, and compliance audit platform built specifically for Indian BFSI enterprises. Full product documentation lives at patchmortem.com ↗

This page is the company view. Architecture, supported platforms, pricing, and the agent specification are at patchmortem.com.

What it does

When a patch fails in production, PatchMortem captures the failure signal, classifies the root cause against 215 known failure patterns, determines the correct remediation action based on asset risk and compliance scope, executes the rollback or repair, and writes a tamper-evident HMAC-SHA256 audit trail — all within two seconds of the failure signal.

Core capabilities

Semantic patch failure classification

A 4-stage pipeline — signal extraction, vector similarity search, LLM fallback, risk overlay — matches every failure against an errata corpus covering Windows Server, RHEL, Ubuntu, Kubernetes, VMware ESXi, SQL Server, and Oracle. Confidence 0.95+ on first match in production.

Automated rollback engine

60+ rollback methods including SNAPSHOT restore, PACKAGE_UNINSTALL, CLUSTER_RESOURCE_REPAIR, and KERNEL_ROLLBACK — auto-selected based on asset topology, cluster state, and compliance scope. Nothing rolls back without a policy that permits it.

HMAC-chained audit trail

Every decision is written to an append-only, HMAC-SHA256 chained audit log designed specifically for RBI IT Framework Section 4.2 evidence requirements. One-click export for RBI, PCI-DSS, SEBI, and IRDAI.

Compliance-aware risk engine

PatchMortem knows the difference between a dev box and a PCI-DSS-scoped production cluster. Approval tiers, rollback policies, and notification routing adjust automatically based on compliance scope.

Native integrations

Microsoft Intune, SCCM/MECM, ManageEngine, NinjaOne, VMware vSphere, Ansible, Puppet, Chef, ServiceNow, and Jira. Your tools stay. PatchMortem adds the intelligence layer.

Cluster awareness

Windows Failover Clustering, Pacemaker, SQL Server Always On availability groups, and Network Load Balancing are detected before any action is taken. Peer nodes are held so a remediation never takes out the quorum it was meant to protect.

Failure-rate intelligence

Across the estate, PatchMortem ranks patches by observed failure rate per KB, package, and OS build — so a risky patch is known before it is scheduled, not after.

An example triage result

Error0x800f0922
ComponentServicing stack (CBS)
CauseWinRE recovery partition below the 250 MB free space required to stage the update.
ClusterWSFC node 2 of 3 · peer patching paused
ActionRollback executed · host returned to serviceable state
FixExtend WinRE partition, then re-queue for the next window.
RecordAUDIT #4418-03

Deployment

Deployed on AWS ap-south-1 (Mumbai). All customer data is stored and processed in India. Multi-tenant architecture with PostgreSQL row-level security. mTLS between all services. Secrets managed via AWS Secrets Manager.

Full product site ↗ Start a pilot