Keep your scanner and public feeds. VCIY adds a dated record of your call, the evidence behind it and watches for material changes. Open one CVE to inspect the sources, then decide whether searchable history or a record for your reviewer is worth paying for.
Not everyone who lands here has the same day. These are the three we sell into: the pain first, then what changes, then where the line is.
You hand your answer to someone who doesn't trust you by default: an auditor, a client, another CNA.
We accepted the risk on this CVE in March. The auditor wants to know what we knew in March. I have a screenshot in a Confluence page.
Every answer I hand over has to be re-derivable by someone who doesn't trust me, or it isn't evidence.
I answer the same CVE question for eleven different clients this week. If two of them compare notes, the answers need to actually match.
Ask what the EPSS score was on a past date and get that date's value. Nothing learned later can leak in: it's a SQL predicate, not a filter applied afterward. ~9ms, no model in the path.
Every refresh binds adapter sha, corpus version, battery id and sha, and the score per gate to a date, and refuses to publish unless the artifact it hashed is the one actually serving.
No tenant boundary yet. Every seat sees the same corpus: fine for one org, not yet for a book of clients.
You decide, in minutes, whether a live CVE is real for something you run.
An alert cites a CVE and I have minutes, not hours, to decide if it's real.
NVD, the vendor advisory, KEV, an EPSS lookup, an internal wiki: five tabs, stitched together by hand, under time pressure.
The CVEs I actually get paged about are from this year. A model trained months ago has never seen them.
Weakness class, current exploitation likelihood, KEV status and due date, in one turn: the five tabs collapse to one.
Every CVE in the corpus postdates every frontier model's training cutoff. On the frozen post-cutoff battery (same questions, same rubric, same adversarial judge for all three) we score 90.86; Opus 5 scores 0.0, Gemini 0.2. Method and hash on the validation page.
The corpus holds weakness class and affected product, not payload shape. If you're writing a detection rule against it, this isn't that tool yet.
You decide what gets patched and defend the call, to a CISO, or to a deploy calendar.
The scanner hands me 40,000 findings and a CVSS number. A 9.8 on a box nobody can reach isn't my top priority, and I have no defensible way to say so.
Security opens a ticket to patch. I run four versions of that library across eleven services and the ticket doesn't say which.
Someone upstairs asks 'are we exposed to the thing in the news' at 4pm and wants an answer by 5.
The decision you made in March reconstructs with March's EPSS score. Today's different number doesn't retroactively make you wrong.
Refreshed on CISA's and FIRST's own cadence, never trained into a model: a live feed with history behind it, not a snapshot.
No SBOM ingestion, no version-range resolution. We tell you the CVE is against a product you run, not which of your four running versions.
The purchase decision is in the last column. Every price and product capability links to the publisher or marketplace that states it.
| Alternative | What it already provides | Published price as of 22 Aug 2026 | What vciy adds |
|---|---|---|---|
| FIRST EPSS + NVD + CISA KEV | Dated EPSS lookups and full archive; CVE change history; current known-exploited catalogue and due dates. | $0 | Free records, built in vciy reads the same sources; you're not paying twice. |
| Tenable | Scanning, asset coverage, prioritization and reporting. Vulnerability Management lists up to 250 assets online. | $3,700/yr | + Dated evidence trail Runs alongside your scanner, no migration, keeps what a scan pass doesn't: who knew what, when. |
| Qualys VMDR | Asset inventory, vulnerability detection, prioritization, compliance controls and optional patching. | from $2,195 | + Dated evidence trail Same pairing: vciy adds the reproducible record Qualys doesn't keep. |
| vciy Practitioner | Material-delta queue, searchable decision history, interpretation and export. Single seat. | $2,490/yr | Buy saved time Payback line: four analyst hours a month. |
| Recorded Future Vulnerability Intelligence | Exploit lifecycle, organization-specific watch lists, alerts and integrations. | $56,250/yr | Custody: $20,000 The dated evidence trail, at 65% less, without the 4-user cap. |
| VulnCheck | Commercial exploit and vulnerability intelligence plus free KEV, NVD++ and XDB products. | quote | Different lane vciy's deterministic delta records, not exploit-code coverage: the two stack, not substitute. |
| GreyNoise | Observed exploitation, vulnerability timelines, attacker counts, alerts and dynamic blocklists. | quote | Different lane GreyNoise watches the internet; vciy watches your named stack. Different sensors, same shelf. |
Checked against each vendor's own published pages. A blank cell means genuinely not publicly disclosed, not a claim that the capability is absent.
| Capability | vciy | Tenable | Qualys VMDR | Recorded Future | VulnCheck |
|---|---|---|---|---|---|
| Standing watchlist on your named stack, in-app alerts and opt-in Slack | Built | Not disclosed | Not disclosed | CVE criteria, not your stack | Not disclosed |
| Dated, source-attributed evidence trail | Built | Not disclosed | Not disclosed | Lifecycle stage, not dated history | Not disclosed |
| Free tier on the base CVE records | Yes: EPSS, NVD, KEV | No | No | No | Yes: KEV, NVD++, XDB |
| Entry price | $2,490/yr | $3,700/yr | $2,195/yr | $56,250/yr | quote only |
Compare current record allowances, watches, seats and billing options in one place. The vendor prices above are the dated comparison; our pricing page carries the current offer.