vciy
Prices and capabilities checked 22 August 2026

Your scanner found it. Keep the evidence for what you did next.

Keep your scanner and public feeds. VCIY adds a dated record of your call, the evidence behind it and watches for material changes. Open one CVE to inspect the sources, then decide whether searchable history or a record for your reviewer is worth paying for.

01

Three jobs, and where we actually sit in them.

Not everyone who lands here has the same day. These are the three we sell into: the pain first, then what changes, then where the line is.

Evidence Owner

You hand your answer to someone who doesn't trust you by default: an auditor, a client, another CNA.

We accepted the risk on this CVE in March. The auditor wants to know what we knew in March. I have a screenshot in a Confluence page.

Every answer I hand over has to be re-derivable by someone who doesn't trust me, or it isn't evidence.

I answer the same CVE question for eleven different clients this week. If two of them compare notes, the answers need to actually match.

As-of reconstruction

BUILT

Ask what the EPSS score was on a past date and get that date's value. Nothing learned later can leak in: it's a SQL predicate, not a filter applied afterward. ~9ms, no model in the path.

Published receipt

BUILT

Every refresh binds adapter sha, corpus version, battery id and sha, and the score per gate to a date, and refuses to publish unless the artifact it hashed is the one actually serving.

Per-client isolation

NOT SHIPPED

No tenant boundary yet. Every seat sees the same corpus: fine for one org, not yet for a book of clients.

Incident Responder

You decide, in minutes, whether a live CVE is real for something you run.

An alert cites a CVE and I have minutes, not hours, to decide if it's real.

NVD, the vendor advisory, KEV, an EPSS lookup, an internal wiki: five tabs, stitched together by hand, under time pressure.

The CVEs I actually get paged about are from this year. A model trained months ago has never seen them.

Compound answer, one query

BUILT

Weakness class, current exploitation likelihood, KEV status and due date, in one turn: the five tabs collapse to one.

Post-cutoff coverage

BUILT

Every CVE in the corpus postdates every frontier model's training cutoff. On the frozen post-cutoff battery (same questions, same rubric, same adversarial judge for all three) we score 90.86; Opus 5 scores 0.0, Gemini 0.2. Method and hash on the validation page.

Exploit mechanics: which parameter, which sink

NOT SHIPPED

The corpus holds weakness class and affected product, not payload shape. If you're writing a detection rule against it, this isn't that tool yet.

Remediation Owner

You decide what gets patched and defend the call, to a CISO, or to a deploy calendar.

The scanner hands me 40,000 findings and a CVSS number. A 9.8 on a box nobody can reach isn't my top priority, and I have no defensible way to say so.

Security opens a ticket to patch. I run four versions of that library across eleven services and the ticket doesn't say which.

Someone upstairs asks 'are we exposed to the thing in the news' at 4pm and wants an answer by 5.

Defensible deferral record

BUILT

The decision you made in March reconstructs with March's EPSS score. Today's different number doesn't retroactively make you wrong.

Dated, attributed KEV + EPSS

BUILT

Refreshed on CISA's and FIRST's own cadence, never trained into a model: a live feed with history behind it, not a snapshot.

Which of your running versions is affected

NOT SHIPPED

No SBOM ingestion, no version-range resolution. We tell you the CVE is against a product you run, not which of your four running versions.

02

The buyer's ledger.

The purchase decision is in the last column. Every price and product capability links to the publisher or marketplace that states it.

AlternativeWhat it already providesPublished price
as of 22 Aug 2026
What vciy adds
FIRST EPSS + NVD + CISA KEVDated EPSS lookups and full archive; CVE change history; current known-exploited catalogue and due dates.$0Free records, built in
vciy reads the same sources; you're not paying twice.
TenableScanning, asset coverage, prioritization and reporting. Vulnerability Management lists up to 250 assets online.$3,700/yr+ Dated evidence trail
Runs alongside your scanner, no migration, keeps what a scan pass doesn't: who knew what, when.
Qualys VMDRAsset inventory, vulnerability detection, prioritization, compliance controls and optional patching.from $2,195+ Dated evidence trail
Same pairing: vciy adds the reproducible record Qualys doesn't keep.
vciy PractitionerMaterial-delta queue, searchable decision history, interpretation and export. Single seat.$2,490/yrBuy saved time
Payback line: four analyst hours a month.
Recorded Future Vulnerability IntelligenceExploit lifecycle, organization-specific watch lists, alerts and integrations.$56,250/yrCustody: $20,000
The dated evidence trail, at 65% less, without the 4-user cap.
VulnCheckCommercial exploit and vulnerability intelligence plus free KEV, NVD++ and XDB products.quoteDifferent lane
vciy's deterministic delta records, not exploit-code coverage: the two stack, not substitute.
GreyNoiseObserved exploitation, vulnerability timelines, attacker counts, alerts and dynamic blocklists.quoteDifferent lane
GreyNoise watches the internet; vciy watches your named stack. Different sensors, same shelf.
03

Where vciy wins on capability.

Checked against each vendor's own published pages. A blank cell means genuinely not publicly disclosed, not a claim that the capability is absent.

CapabilityvciyTenableQualys VMDRRecorded FutureVulnCheck
Standing watchlist on your named stack, in-app alerts and opt-in Slack Built Not disclosed Not disclosed CVE criteria, not your stack Not disclosed
Dated, source-attributed evidence trail Built Not disclosed Not disclosed Lifecycle stage, not dated history Not disclosed
Free tier on the base CVE records Yes: EPSS, NVD, KEV No No No Yes: KEV, NVD++, XDB
Entry price$2,490/yr$3,700/yr$2,195/yr$56,250/yrquote only
Verified 24 Aug 2026 against each vendor's own site: Tenable, Qualys, Recorded Future (pricing: AWS Marketplace), VulnCheck. "Not disclosed" reflects the limit of public marketing copy, not a sales claim about the product.

Choose your plan.

Compare current record allowances, watches, seats and billing options in one place. The vendor prices above are the dated comparison; our pricing page carries the current offer.