PatchMortem — patch failure triage and rollback orchestration.
Automated patch failure classification, rollback, and RBI-compliant audit trail for Indian BFSI enterprises.
PatchMortem is Zurlux Technologies' first product — an automated patch failure classification, rollback, and compliance audit platform built specifically for Indian BFSI enterprises. This page is the company view; architecture, supported platforms, and the agent specification live at patchmortem.com.
When a patch fails in production, PatchMortem captures the failure signal, classifies the root cause against 215 known failure patterns, determines the correct remediation based on asset risk and compliance scope, executes the rollback or repair, and writes a tamper-evident HMAC-SHA256 audit trail — all within two seconds of the failure signal.
What it does.
Semantic failure classification
A 4-stage pipeline — signal extraction, vector similarity search, LLM fallback, risk overlay — matches every failure against an errata corpus covering Windows Server, RHEL, Ubuntu, Kubernetes, VMware ESXi, SQL Server, and Oracle. Confidence 0.95+ on first match in production.
Automated rollback engine
60+ rollback methods including SNAPSHOT restore, PACKAGE_UNINSTALL, CLUSTER_RESOURCE_REPAIR, and KERNEL_ROLLBACK — auto-selected on asset topology, cluster state, and compliance scope. Nothing rolls back without a policy that permits it.
HMAC-chained audit trail
Every decision is written to an append-only, HMAC-SHA256 chained log designed for RBI IT Framework Section 4.2 evidence requirements. One-click export for RBI, PCI-DSS, SEBI, and IRDAI.
Compliance-aware risk engine
PatchMortem knows the difference between a dev box and a PCI-DSS-scoped production cluster. Approval tiers, rollback policies, and notification routing adjust automatically by compliance scope.
Native integrations
Microsoft Intune, SCCM/MECM, ManageEngine, NinjaOne, VMware vSphere, Ansible, Puppet, Chef, ServiceNow, and Jira. Your tools stay. PatchMortem adds the intelligence layer.
Cluster awareness
WSFC, Pacemaker, SQL Server Always On, and Network Load Balancing are detected before any action. Peer nodes are held so a remediation never takes out the quorum it was meant to protect.