Practical instruments for people who have to budget for compliance and track what is actually being exploited. Nothing here asks you to create an account, and nothing here collects your data unless you explicitly ask us to get in touch.
Governance Estimate Generator
An instant budgetary planning range across nine frameworks — CMMC Levels 1 and 2, NIST SP 800-171, NIST 800-53/RMF, ISO/IEC 27001, SOC 2, HIPAA, CIS Controls and the NIST AI RMF. Calculates in your browser; nothing is transmitted.
Open the estimatorThreat Landscape Heat Map
Actors against sectors, vectors against tactics, controls against sectors — computed daily from the CISA Known Exploited Vulnerabilities catalog and actor tracking, with every date carried from its source or left blank.
Threat Intel Board
A customer-safe view of actively exploited CVEs and tracked actors, refreshed through the day. Attribution is repeated with citation and confidence — never originated by us.
Why the dates on our feeds are sometimes blank
Most free threat feeds calculate a due date when the source does not state one. We do not. If a date is not published by an authoritative source, we leave it empty rather than compute something that looks authoritative and is not. The same discipline applies to attribution: we repeat what a named researcher assessed, with their confidence level and the date they said it, and we do not originate attribution of our own.