Home  /  Design partners  /  Security

Evidence for vulnerability decisions.

Security teams triage continuously: escalate this CVE now, or defer. The call depends on external evidence that changes by the hour.

One decision, end to end.

The decision

Escalate or defer a CVE

A vulnerability lands in triage. The team, or an automated policy, decides whether it is exploited in the wild and whether it jumps the queue.

Evidence needed

What the call relies on

CISA Known Exploited Vulnerabilities state, EPSS scores, advisory publication times, and how fresh each of those observations is at decision time.

The failure

What stale evidence causes

Deferring a CVE that entered the exploited list yesterday, on the strength of last week's snapshot, is the failure mode audits find. Without preserved evidence the deferral cannot be reconstructed, only regretted.

Integration

How Dynamic Feed fits

The triage pipeline reads signed CVE and KEV data via REST or MCP. Each response records source, observation time and freshness state, signed at response time.

The receipt

What remains afterward

A Decision Receipt for the escalation or deferral: the KEV state as observed, the advisory evidence, timestamps and the verdict, independently re-verifiable later, when the question is asked.

Pilot result

What thirty days should show

Every triage decision in the covered workflow carries a verifiable receipt; a sampled receipt re-verifies in a clean browser; stale moments are visibly recorded rather than silently absorbed.

Where to next.

The product tour walks one observation to an independently verified receipt · verify one yourself · the 30-day pilot · REST docs · MCP connection.