vciy
Decision Vault

You deferred it in March. They're asking in September.

Open the decision you made, with your reason and the evidence the index held when you recorded it. The next reviewer can inspect the basis of the call, even after the public feeds change.

Start without an account. Sign in to keep it. Your first 100 records are free.

Open the thing you would keep.

A record holds the verdict, rationale, author, recording time, review date and frozen source evidence. Each amendment adds a version to its hash chain.

The example is VCIY's own Log4Shell record, made public for inspection. Customer records are private. Sharing names a person who signs in to see that record.

Get the independent export verifier
VCIY's own public exampleMitigated

CVE-2021-44228 Log4Shell

Upgraded log4j-core to 2.17.1 across every service during the December 2021 disclosure window.
Recorded
12 September 2026
Evidence
Frozen when the record was created
Check
Inspect the evidence and verify the hash chain
Open this decision record

Retrospective worked example: the 2021 action was recorded in September 2026. Its frozen evidence is from record creation, not 2021. Customer records are private.

From the CVE to your ticket.

  1. Choose the call

    Open a CVE and choose accept, defer, patch by a date, not affected or mitigated. The record starts with that CVE and verdict.

    Try it on the Ray CVE
  2. Add your reason

    Sign in, write the rationale and set a review date. VCIY supplies the evidence it holds and stamps the recording time on its server.

  3. Keep the record

    Copy the record's paragraph into your ticket, with its link. Reviewers can follow the decision to the evidence instead of rebuilding the case from a comment.

Already being asked? Reconstruct March.

Open the CVE and choose a historical date to read the facts the index held then. A record created today still carries today's recording time, even when its rationale describes an earlier decision. Historical coverage is limited to the sources and dates held.

Open the CVE and choose a date

Know when to look again.

Practitioner and Custody add watches for material changes. The original record keeps its frozen evidence; a new finding is a reason to review the call.

A new CISA KEV listing, a change to the CISA remediation deadline, a change in public exploitation status, and exploit probability crossing 10%, 50% or 90% in either direction all count as a move. An exploit-probability change that crosses none of those lines does not. A source republishing a value it already holds is not a change at all.

See how watchlists work

Keep one call or the team's whole register.

All plan terms and limits

Under Custody, records cannot be deleted or altered, by anyone, including you. Changes are new versions. The shared register and access history let the organisation trace both the decision and its review.

At your plan's record limit, existing records stay readable and exportable; the next new record needs more capacity. Read the retention and exit terms.