# Managing vulnerabilities requires knowing your business context

**URL:** https://mazehq.com/blog/managing-vulnerabilities-requires-knowing-your-business-context
**Date:** 2026-08-19

Security teams lose 14.1 hours a week chasing false positives ([Security Boulevard](https://securityboulevard.com/2025/10/survey-surfaces-extent-to-which-cybersecurity-teams-are-drowning-in-alerts/)). That matches what we hear from customers, and it’s because most scanner findings are safe to ignore.

Knowing which findings are just noise is the hard part. Without context, a real threat looks no different from a harmless finding. And while our agents gather a lot of context, sometimes information can be scattered across your team’s knowledge and nowhere else.

That’s why we’re excited to launch our new feature, custom context.

Uncovering whether a CVE is [exploitable](https://mazehq.com/blog/exploitability) in your system, and if so how large is the blast radius, requires a lot of context. Investigate any one particular finding and the logic branches fast. Every answer opens three more questions, and the branches are different for every CVE.

Experienced engineers can usually make the right call on instinct and a little bit of digging. But instinct lives in one person’s head, and that doesn’t scale. You need a reliable system to ignore irrelevant findings while flagging all real risks.

## Bring your own context

Custom context is Maze’s new capability that lets you upload any piece of information you want Maze agents to know about. The best custom context is the stuff only your team knows.

Maze agents already see your code, build, runtime, and cloud configuration. They learn details like which assets are internet-facing, what a role can access, and which resources carry a pci=true tag. What they can’t know are the ins and outs like what that tag means to you, which data is most sensitive for your business or which app is revenue-critical.

![](https://mazehq.com/wp-content/uploads/2026/08/custom-context-current-branded-1.png)## How Maze agents use context

Every Maze investigation runs on context. When a new vulnerability is detected, Maze agents first determine whether it’s exploitable in your environment. They do this by comparing the exploitability conditions of the CVE against your code and infrastructure. If the vulnerability isn’t exploitable, the agents close it. Then they rescore the rest based on the real likelihood and impact of an attack.

You don’t have to explain any data points or how they should be weighed. The agents understand your environment and judge every finding against it.

Custom context becomes one more input the agents pull from. Your uploaded knowledge sits alongside everything the agents discover on their own, and it shapes both the exploitability call and the rescoring.

Say some of your assets sit behind an Okta group that your cloud provider is unaware of. The agents see internet-facing assets and score vulnerabilities on them accordingly, because the Okta policy controlling access lives outside your cloud where no scanner can see it. Tell Maze about it, and those findings get scored the way you already know they should be.

## Add context in minutes

Adding your context is simple. Upload any file to the Maze platform. You don’t need to structure it in any specific way, just share the information in whatever format is easiest for you. The agents will learn what it means, where to apply it, and how to apply it.

Once it’s live, every new investigation takes your context into account. Investigations that used it are flagged, so you can see your knowledge showing up in the results. And if your context changes the severity of an existing finding, Maze flags that too.

## Try custom context in your environment

Custom context puts all the knowledge you upload to work in every investigation. Gain control of your vulnerabilities by letting agents triage them for you. Learn more about Maze [h](https://mazehq.com/)[e](https://mazehq.com/platform)[re](https://mazehq.com/).