A stack is a watchlist: the products you run, named once, so you hear when a CVE touches one of them. This page says what fires an alert, what does not, and where it goes.
These changes count, each tied to a product in your stack.
Everything else is routine. A source republishing a value it already holds is not a change at all. Routine changes are listed in a weekly digest and never alert on their own.
A probability that lands less than 5 points past a line waits. It becomes an alert if it moves 5 points past the line, or if it is still across the line at the next daily load.
When you give a version, we place it against the ranges the CVE record publishes for that product.
An alert is lowered, never dropped. The change stays listed. Only an exact not-affected answer lowers anything, because unknown beats a false clear.
Alerts that count are sent when the checker finds them. Record changes are digested daily. Routine changes are digested weekly, on the weekday you choose.
| Plan | Stacks | Products per stack | Seats | Alerts go to |
|---|---|---|---|---|
| Community | 1 | 5 | 1 | |
| Practitioner | 3 | Unlimited | 3 | Email and Slack |
| Advisor | 10 | Unlimited | 3 | Email and Slack |
| Custody | Unlimited | Unlimited | 10 | Email and Slack |
These are the plan allowances on the pricing page. Compare plans
The week nothing moves, a single line says so: nothing moved on what you watch this week. It goes by email, on your digest day, and only when no material or record change was found.
It is sent only when our checker's own receipt proves it read every public change for the whole week. When we cannot prove that, we send nothing. A missing all-clear means a gap on our side, never safety.
Each alert carries a proof link. A colleague opens it without an account. It shows the public CVE facts and the product you watch, and it writes nothing.