Signed security evidence, what was known-exploited, and what your certs showed, provable later.
For an audit, a compliance review, or an incident timeline, the question is always the same: what was known, when? Was a CVE on CISA's known-exploited list on the day in question? What did a domain's TLS certificate present at the time? We turn the live CISA known-exploited-vulnerabilities catalog, per-package OSV lookups, security advisories and live TLS cert checks into Ed25519-signed, provenance-stamped, archived records, captured as they happen, so anyone can re-check them months later without trusting your word or ours. Evidence of what was reported at a time, not a scan, not an assessment, not a guarantee of security.
A screenshot isn't evidence.
Audits, compliance frameworks and incident reviews all turn on a point-in-time fact: what was known when. Was this CVE on CISA's known-exploited list on the date you patched? What TLS certificate and protocol did this endpoint present during the assessment window? Most of what gets offered to answer that is a screenshot pasted into a spreadsheet, or a note that says "we checked on the 3rd", pulled together long after the fact. None of it is independent, and anyone reviewing it can question the date, the source, or whether it was edited.
For ISO 27001, SOC 2, the Essential Eight, or an incident timeline, what holds up is an independent, third-party record, what an authoritative source (CISA, NVD/CVE, OSV) reported, or what a TLS endpoint actually presented, captured at the moment it existed, signed and timestamped, and re-checkable by an auditor later. Not a recollection, not a screenshot anyone could have changed. That's what this vertical provides: a signed, archived record of what was reported at a time.
A signed record of what was reported anyone can check.
Live security signals, delivered the same way every datapoint we publish is, signed, sourced, and archived.
- Live CISA known-exploited catalog. Our
exploited_vulnerabilitiestool returns the CISA KEV catalog, CVEs confirmed exploited in the wild (not merely disclosed), with the date each was added, the catalog version, and FIRST.org EPSS scores. Source: CISA Known Exploited Vulnerabilities catalog (US-gov, public domain) + FIRST.org EPSS. - Per-package vulnerability lookup. Our
check_vulnerabilitytool looks a package up across the OSV.dev corpus, the known vulnerabilities, CVE IDs, CVSS vectors and fixed versions affecting it. Source: OSV.dev (Google), CC-BY-4.0. - Security advisories. Our
security_advisoriestool returns recent advisories, id, CVE, summary, severity, ecosystem and affected package, from the GitHub Advisory Database. A record of what was published at a time. - Live TLS cert checks. Our
cert_checktool performs a direct TLS handshake to a domain and records what it presented, validity, issuer, expiry, days-to-expiry, TLS protocol version and SANs. This is our own live observation of the endpoint. - Signed, sourced & archived. Every reading is Ed25519-signed over its exact bytes, carries its source / URL / measurement timestamp, and is written to an append-only signed archive, so a point-in-time record can't be quietly rewritten after the fact.
- Verify it yourself. A public verify page and the open-source verifier let an auditor, or either party, re-check a signature independently, in their own code, without trusting us.
Right now, what's known.
This is a live exploited_vulnerabilities reading, fetched in your browser from POST /v1/batch, the number is the total CVEs CISA currently lists as known-exploited-in-the-wild, with the catalog version it came from (Source: CISA Known Exploited Vulnerabilities catalog). The second figure is a live cert_check on this very domain, days until our own TLS certificate expires, measured by a direct handshake. Both are captured as signed, provenance-stamped readings.
1,619
1,619 CVEs are currently on CISA's known-exploited-in-the-wild catalog (version 2026.06.12), each confirmed exploited, not merely disclosed. And our own TLS certificate on dynamicfeed.ai has 75 days to expiry, valid on TLS 1.3. Both captured as signed, provenance-stamped readings.
This is a signed record of what an authoritative source reported, and what a TLS endpoint presented, at a time, the CISA KEV catalog is what CISA listed as known-exploited; the cert reading is our own live observation of the handshake. It is evidence of what was reported at a time, not a vulnerability scan, not a penetration test, not a security assessment, and not a guarantee that you, or any endpoint, are secure. CISA KEV and CVE/NVD are US-gov public domain; OSV is open (CC-BY-4.0, Google/OSV); the cert reading is our own live TLS observation.
Teams who need a record that holds up.
Point-in-time evidence on file
Capture a signed record of whether a CVE was on CISA's known-exploited list, and what an endpoint's cert presented, on the date in question, an auditable account neither you nor a reviewer has to take on trust.
Re-checkable control evidence
For ISO 27001, SOC 2 or the Essential Eight, attach a signed, timestamped record of what an authoritative source reported, re-verifiable in the auditor's own code, instead of a screenshot in a spreadsheet.
Evidence for your clients
Produce signed, provenance-stamped records of known-exploited status and cert posture across the estates you manage, a third-party record you can hand a client or their auditor.
Build the timeline
When a post-incident review asks "was this known-exploited then?", a signed record captured at the time gives the timeline a documented, re-checkable basis, not a reconstruction after the fact.
Document a vendor's posture
Record what a vendor's domain presented on TLS, and which advisories affected their stack, at the time of review, a signed record of what was reported, kept for the file.
Evidence that re-checks
An Ed25519-signed, archived datapoint anyone can independently verify, a tamper-evident, independently re-checkable record that a reading existed at a time, useful when what was known, and when, is later questioned.
One call → a signed record.
Call the feed
One keyless MCP or REST call: exploited_vulnerabilities, check_vulnerability (by package), security_advisories, or cert_check with a domain. No key to get started.
Get what was reported
The response carries the known-exploited catalog, a package's vulnerabilities, recent advisories, or the live TLS reading for a domain, each with its source and exact measurement time.
Keep the signed record
Every response is Ed25519-signed and provenance-stamped, and written to the append-only archive, so you can produce it months later for an audit or a review.
Verify it independently
An auditor, or either party, can re-check the signature on the public verify page or with the open-source verifier, no need to trust us.
One price, the whole platform.
Security evidence is part of Dynamic Feed, not a separate bill. Start free and keyless; paid tiers (Builder, Scale, Enterprise) are in early access — request access and tell us your workload. The same signed, sourced, archived records on every tier.
Every tier is self-serve, even Enterprise. Mint a key and you are live in seconds, no waiting. Need conditions at a site on a date, signed for a claim? See weather evidence. Need AIS, tides and GPS at sea? See the maritime vertical. Want the GNSS-jamming angle? See GPS integrity. Want your own source wrapped the same way? See done-for-you.
A record, not a certification.
We provide a signed record of what authoritative sources reported, CISA's known-exploited catalog, the CVE/NVD and OSV corpora, security advisories, and what a TLS endpoint presented at a time. It is evidence of what was reported at a time, not a vulnerability scan, not a penetration test, not a security assessment or audit, and not a guarantee that you, or any system, are secure. Signing and anchoring make a datapoint tamper-evident, it existed at a specific time, and any later change is detectable against the signature, they do not prove it is true, accurate or complete; we make no accuracy guarantees about the upstream source, and this is not a security certification. The CISA KEV catalog and CVE/NVD are US-gov public domain; OSV is open (CC-BY-4.0, Google/OSV); the cert reading is our own live TLS observation. This is an independent, signed record, evidence of what was reported, not a safety or security certification.
Fully automated. Run by AI, end to end.
No sales calls and no waiting. Mint a key and you are live in seconds, on any tier, for signed security evidence.