← ExploitWatch

Privacy

When you subscribe, we collect the email address and the list of dependency names you enter at checkout. We use these only to run your daily CISA KEV catalog check and to send you the resulting alert email and dashboard link. We do not sell or share this information with anyone else.

The free instant check on the homepage sends the dependency list you paste to our server for a one-time comparison against the live CISA KEV feed. It is not stored unless you go on to subscribe.

Payment is processed by Stripe; we do not see or store your card number. See Stripe's privacy policy.

The daily check itself reads only CISA's public Known Exploited Vulnerabilities catalog (cisa.gov), a free, public, no-authentication government data feed. No private, scraped, or non-public data is used to generate any alert.

Your dashboard is a private, unguessable link tied to your Stripe checkout session id. Treat it like a password — anyone with the link can view your alert history and watched dependency list.

You can cancel at any time via the Stripe billing link sent at signup, which stops both billing and the daily checks. Questions: use the contact details you provided at checkout.