LIVE STATUS: /uptime·SECURITY · CISA KEV · CVE/OSV · ADVISORIES · TLS CERTS
DATA WITH RECEIPTS · ED25519 · RFC 3161·--:--:-- UTC
Home  /  Security evidence
SECURITY-EVIDENCE VERTICAL · GRC · COMPLIANCE · AUDITORS · MSSPs · INCIDENT RESPONSE

Signed security evidence, what was known-exploited, and what your certs showed, provable later.

For an audit, a compliance review, or an incident timeline, the question is always the same: what was known, when? Was a CVE on CISA's known-exploited list on the day in question? What did a domain's TLS certificate present at the time? We turn the live CISA known-exploited-vulnerabilities catalog, per-package OSV lookups, security advisories and live TLS cert checks into Ed25519-signed, provenance-stamped, archived records, captured as they happen, so anyone can re-check them months later without trusting your word or ours. Evidence of what was reported at a time, not a scan, not an assessment, not a guarantee of security.

THE PROBLEM

A screenshot isn't evidence.

Audits, compliance frameworks and incident reviews all turn on a point-in-time fact: what was known when. Was this CVE on CISA's known-exploited list on the date you patched? What TLS certificate and protocol did this endpoint present during the assessment window? Most of what gets offered to answer that is a screenshot pasted into a spreadsheet, or a note that says "we checked on the 3rd", pulled together long after the fact. None of it is independent, and anyone reviewing it can question the date, the source, or whether it was edited.

For ISO 27001, SOC 2, the Essential Eight, or an incident timeline, what holds up is an independent, third-party record, what an authoritative source (CISA, NVD/CVE, OSV) reported, or what a TLS endpoint actually presented, captured at the moment it existed, signed and timestamped, and re-checkable by an auditor later. Not a recollection, not a screenshot anyone could have changed. That's what this vertical provides: a signed, archived record of what was reported at a time.

WHAT WE PROVIDE

A signed record of what was reported anyone can check.

Live security signals, delivered the same way every datapoint we publish is, signed, sourced, and archived.

LIVE READING

Right now, what's known.

This is a live exploited_vulnerabilities reading, fetched in your browser from POST /v1/batch, the number is the total CVEs CISA currently lists as known-exploited-in-the-wild, with the catalog version it came from (Source: CISA Known Exploited Vulnerabilities catalog). The second figure is a live cert_check on this very domain, days until our own TLS certificate expires, measured by a direct handshake. Both are captured as signed, provenance-stamped readings.

CISA known-exploited CVEs · catalog 2026.06.12

1,619

1,619 CVEs are currently on CISA's known-exploited-in-the-wild catalog (version 2026.06.12), each confirmed exploited, not merely disclosed. And our own TLS certificate on dynamicfeed.ai has 75 days to expiry, valid on TLS 1.3. Both captured as signed, provenance-stamped readings.

CISA KEV observed 2026-06-12T16:46:48Z · cert checked live · Ed25519-signed · sample
how to read this

This is a signed record of what an authoritative source reported, and what a TLS endpoint presented, at a time, the CISA KEV catalog is what CISA listed as known-exploited; the cert reading is our own live observation of the handshake. It is evidence of what was reported at a time, not a vulnerability scan, not a penetration test, not a security assessment, and not a guarantee that you, or any endpoint, are secure. CISA KEV and CVE/NVD are US-gov public domain; OSV is open (CC-BY-4.0, Google/OSV); the cert reading is our own live TLS observation.

WHO IT'S FOR

Teams who need a record that holds up.

security & GRC teams

Point-in-time evidence on file

Capture a signed record of whether a CVE was on CISA's known-exploited list, and what an endpoint's cert presented, on the date in question, an auditable account neither you nor a reviewer has to take on trust.

compliance & auditors

Re-checkable control evidence

For ISO 27001, SOC 2 or the Essential Eight, attach a signed, timestamped record of what an authoritative source reported, re-verifiable in the auditor's own code, instead of a screenshot in a spreadsheet.

MSSPs

Evidence for your clients

Produce signed, provenance-stamped records of known-exploited status and cert posture across the estates you manage, a third-party record you can hand a client or their auditor.

incident responders

Build the timeline

When a post-incident review asks "was this known-exploited then?", a signed record captured at the time gives the timeline a documented, re-checkable basis, not a reconstruction after the fact.

vendor & third-party risk

Document a vendor's posture

Record what a vendor's domain presented on TLS, and which advisories affected their stack, at the time of review, a signed record of what was reported, kept for the file.

security lawyers & insurers

Evidence that re-checks

An Ed25519-signed, archived datapoint anyone can independently verify, a tamper-evident, independently re-checkable record that a reading existed at a time, useful when what was known, and when, is later questioned.

HOW TO USE IT

One call → a signed record.

1

Call the feed

One keyless MCP or REST call: exploited_vulnerabilities, check_vulnerability (by package), security_advisories, or cert_check with a domain. No key to get started.

2

Get what was reported

The response carries the known-exploited catalog, a package's vulnerabilities, recent advisories, or the live TLS reading for a domain, each with its source and exact measurement time.

3

Keep the signed record

Every response is Ed25519-signed and provenance-stamped, and written to the append-only archive, so you can produce it months later for an audit or a review.

4

Verify it independently

An auditor, or either party, can re-check the signature on the public verify page or with the open-source verifier, no need to trust us.

PRICING

One price, the whole platform.

Security evidence is part of Dynamic Feed, not a separate bill. Start free and keyless; paid tiers (Builder, Scale, Enterprise) are in early access — request access and tell us your workload. The same signed, sourced, archived records on every tier.

self-serve, every tier

Every tier is self-serve, even Enterprise. Mint a key and you are live in seconds, no waiting. Need conditions at a site on a date, signed for a claim? See weather evidence. Need AIS, tides and GPS at sea? See the maritime vertical. Want the GNSS-jamming angle? See GPS integrity. Want your own source wrapped the same way? See done-for-you.

WHAT "SIGNED" MEANS, IN PLAIN WORDS

A record, not a certification.

read this before you rely on it

We provide a signed record of what authoritative sources reported, CISA's known-exploited catalog, the CVE/NVD and OSV corpora, security advisories, and what a TLS endpoint presented at a time. It is evidence of what was reported at a time, not a vulnerability scan, not a penetration test, not a security assessment or audit, and not a guarantee that you, or any system, are secure. Signing and anchoring make a datapoint tamper-evident, it existed at a specific time, and any later change is detectable against the signature, they do not prove it is true, accurate or complete; we make no accuracy guarantees about the upstream source, and this is not a security certification. The CISA KEV catalog and CVE/NVD are US-gov public domain; OSV is open (CC-BY-4.0, Google/OSV); the cert reading is our own live TLS observation. This is an independent, signed record, evidence of what was reported, not a safety or security certification.

THE FUTURE, HERE AND NOW

Fully automated. Run by AI, end to end.

No sales calls and no waiting. Mint a key and you are live in seconds, on any tier, for signed security evidence.