vciy
Event-Driven Discovery

Bring changes in your stack's CVE evidence to the next patch review.

Get a change to investigate, tied to a service and version you supplied. Custody connects your live service roster to CVE monitoring so the review starts with the identities you run.

Add one exporter to the OpenTelemetry pipeline you already run. Service names, versions, and images arrive as resource metadata, nothing else, and become your live subject: the roster of what is actually running. From then on there is one contract: if news is not about an identity you sent, we do not send it.

01

Not the firehose

We do not want your telemetry. Two hundred replicas of a service collapse to one identity; the same self-description arriving every flush interval carries one bit of news, still alive; and your spans, metrics, and logs are dropped at the door, unstored and unlogged. What we keep is attendance: distinct service and version, first seen, last seen. A Fortune 50's terabytes of telemetry are, to us, a contact sheet. If you would rather skip the collector entirely, the same endpoint accepts a periodic identity roster, a cron and a curl.

02

About 90% faster to first knowledge*

A fast-moving CVE that touches your roster becomes a push, not a discovery. Feeds publish, the delta fires, your identities match, your phone buzzes. Teams on a weekly scan-and-map cycle learn in days; you learn the same day.

*Derived below from public feed cadences and stated assumptions. Push delivery is best effort and rides our feeds and our uptime, both published.

How the 90% is derived
  • Baseline lane · scanner cadence 168 hours (assumption: one weekly authenticated scan) plus relevance mapping 24 hours (assumption: an analyst maps findings to owned services within a day). Baseline: 168 to 192 hours.
  • VCIY lane · EPSS publishes daily, so a score move reaches publication within 24 hours; KEV additions publish same day; delta to identity match to push is engineered under one hour, stated here as a bound, and measured figures replace this line when the run log publishes.
  • Worked example · an exploit probability jumps Monday 03:00. It publishes in that day's EPSS release and your push arrives the same day. The weekly shop's scanner runs Sunday and their analyst maps findings Monday: seven to eight days later.
  • Headline · 168 to 192 hours down to 8 to 24 hours is an 87% to 96% reduction depending on the moving source. We publish about 90%, and this panel is the derivation.
03

What it prints

Three services running that nobody declared. Five declared entries runtime has not seen in a month. A freshness line with a real timestamp. Each number opens its derivation, like every other number on this site.

04

Privacy by construction

Two locks. Your own collector, configured to strip everything except resource attributes, keeps span, metric, and log data off the wire entirely; that configuration is generated for you at sign-in, not published as a standalone document today. Our ingress drops any payload that arrives anyway, unstored and unlogged, by our own ingest code before anything is written.

05

Installed with you, at scale on your hardware

We wire it in a working session with your SRE and observability team; your people hold the config. Cloud plans cover up to 5,000 active identities (a distinct service and version counts once, replicas collapse, and identities retire after 30 days unseen); higher volumes are available on request, and heavy telemetry runs On-Prem, LAN-local on your hardware, where nothing leaves your network.

06

This is a Custody feature

Live identities, the delta lists, the scorecard they feed, and the working-session install ship with Custody: $10,000 a year, founding subscribers keep the price for life, five seats on your domain, and a direct line to the builder.