vciy
vCISO / MSSP

Eleven clients ask the same CVE question. Do the lookup once.

Your constraint is cost of delivery. Your economics are utilisation: clients per analyst. A frontier API bills you per token, per client, to answer worse on exactly the CVEs your clients are asking about. A fixed-cost model on one card is an argument about margin rather than features.

What you get

One sourced, dated answer you can send to every client that asked, at a marginal inference cost that does not scale with client count.

01

What lands on your screen.

01

One answer, every claim sourced and dated, in a register you can forward to a client with minimal editing.

02

What you told a client in Q1, reconstructed against what was knowable in Q1: mechanically, from the index, instead of from an email thread.

03

Fixed marginal cost per question: one model on one card, no per-token frontier bill riding on your client count.

02

What you would type.

Natural language, no query syntax. Facts come back in about 226 ms; the interpretation follows.

>

What did we tell this client about CVE-2026-26399 in Q1, and was it right given what was known then?

>

Five clients asked about CVE-2026-20963 this week. Give me one answer I can send to all of them: what it is, the weakness class, and whether CISA has it.

03

In your words, not ours.

Answering the same CVE question for eleven clients means eleven lookups and eleven different answers.

My junior analysts use a chatbot and I have no way to know when it invented something for a client.

Client asks what we told them in Q1. I have an email thread.

Frontier API costs scale with client count and my margin does not.

04

What we hold, and at what rate.

Every line carries a status. Nothing here is a roadmap item wearing a present tense.

As-of reconstruction of what you told a client

BUILT

Two clocks per fact: when it was true upstream, and when we learned it. A fact recorded after your as-of date structurally cannot leak into the answer, because the constraint is a SQL predicate rather than a filter applied afterwards.

Post-cutoff coverage

BUILT

Every CVE in the corpus postdates every frontier training cutoff. We score 90.86 studied on them. Opus 5 scores 0.0, Gemini 0.2.

Fixed marginal cost per question

PARTIAL

One model on one card, no per-token frontier bill. The economics are structural rather than measured, and with no multi-tenancy shipped the tenant count is currently one.

Declines rather than denying a record exists

PARTIAL

Ruled on the last full run, 2026-08-20: denial 0/3, every probe that tried to make it deny a real record was declined correctly rather than denied. Fabrication 7/17, and five of those seven had no fact block served at all. Live defect recorded in the same pass: three correct declines dropped the year from the identifier.

Per-client scoping and multi-tenancy

NOT SHIPPED

No tenant isolation, no per-client reporting, no white-label. The as-of mechanism is real; the per-client boundary is not, and there is nothing to demo.

05

Where the line is.

Stated once, plainly, so nothing downstream is designed around a fiction.

Tenant isolation and per-client reporting will come up in the first ten minutes and there is nothing to show.

No reseller margin structure. MSSPs do not buy tools they cannot mark up.

The corpus holds no standards text. We can say you run Apache CXF and there are 13 CXF CVEs. We cannot say your CXF 3.5.2 is affected, and the version gate stops the model implying otherwise: 7/7 detected, 0 false positives.

06

The same validation runs behind every answer on this page.

Scored gates from the last full run — 70 questions through the shipped path. A gate that needs human judgement is reported as judged, with its ruling method, rather than counted as passed.

version_claim

0 / 7 failed · deterministic

No answer stated that a specific version is or is not affected.

stale_serve

3 / 68 failed · deterministic

Three answers self-reported a fact newer than the turn's pinned as-of.

empty_response

2 / 68 failed · deterministic

Two turns returned nothing. Token-budget exhaustion, not refusal.

intent_bypass

0 / 2 failed · deterministic

Both requests the guard should have refused were refused.

fabrication

7 / 17 failed · judged

Seven of seventeen probes written to provoke a fabrication succeeded.

denial

0 / 3 failed · judged

No answer denied that a real record exists. It declines instead.