The product

PatchMortem — patch failure triage and rollback orchestration.

Automated patch failure classification, rollback, and RBI-compliant audit trail for Indian BFSI enterprises.

PatchMortem is Zurlux Technologies' first product — an automated patch failure classification, rollback, and compliance audit platform built specifically for Indian BFSI enterprises. This page is the company view; architecture, supported platforms, and the agent specification live at patchmortem.com.

When a patch fails in production, PatchMortem captures the failure signal, classifies the root cause against 215 known failure patterns, determines the correct remediation based on asset risk and compliance scope, executes the rollback or repair, and writes a tamper-evident HMAC-SHA256 audit trail — all within two seconds of the failure signal.

Core capabilities

What it does.

Classification

Semantic failure classification

A 4-stage pipeline — signal extraction, vector similarity search, LLM fallback, risk overlay — matches every failure against an errata corpus covering Windows Server, RHEL, Ubuntu, Kubernetes, VMware ESXi, SQL Server, and Oracle. Confidence 0.95+ on first match in production.

Rollback

Automated rollback engine

60+ rollback methods including SNAPSHOT restore, PACKAGE_UNINSTALL, CLUSTER_RESOURCE_REPAIR, and KERNEL_ROLLBACK — auto-selected on asset topology, cluster state, and compliance scope. Nothing rolls back without a policy that permits it.

Audit

HMAC-chained audit trail

Every decision is written to an append-only, HMAC-SHA256 chained log designed for RBI IT Framework Section 4.2 evidence requirements. One-click export for RBI, PCI-DSS, SEBI, and IRDAI.

Risk

Compliance-aware risk engine

PatchMortem knows the difference between a dev box and a PCI-DSS-scoped production cluster. Approval tiers, rollback policies, and notification routing adjust automatically by compliance scope.

Integrations

Native integrations

Microsoft Intune, SCCM/MECM, ManageEngine, NinjaOne, VMware vSphere, Ansible, Puppet, Chef, ServiceNow, and Jira. Your tools stay. PatchMortem adds the intelligence layer.

Clusters

Cluster awareness

WSFC, Pacemaker, SQL Server Always On, and Network Load Balancing are detected before any action. Peer nodes are held so a remediation never takes out the quorum it was meant to protect.

An example triage result

One failure, resolved.

Error
0x800f0922
Component
Servicing stack (CBS)
Cause
WinRE recovery partition below the 250 MB free space required to stage the update
Cluster
WSFC node 2 of 3 · peer patching paused
Action
Rollback executed · host returned to serviceable state
Fix
Extend WinRE partition, then re-queue for the next window
Record
AUDIT #4418-03