ExploitWatch is a monitoring aid only. It is not legal advice, not a compliance service, and not a substitute for qualified counsel. It checks CISA's public Known Exploited Vulnerabilities catalog daily against the dependency names you provide at signup and emails you when something matches. It does not determine whether the EU Cyber Resilience Act's Article 14 (or any other law) applies to your product, whether you are legally "aware" of a vulnerability under that Regulation, or whether a given CVE's exploitation actually affects your specific deployment or configuration.
You are solely responsible for evaluating every alert and for actually filing any required report with ENISA and/or your national CSIRT within whatever deadline applies to you. We make no guarantee that every relevant vulnerability will be caught, that a match is accurate or complete, or that the computed 24-hour/72-hour/ 14-day dates in an alert reflect your actual legal deadline — those figures assume your moment of awareness is the moment you receive the alert, which may not match your specific legal circumstances. Always consult a licensed attorney or your national CSIRT before relying on any alert to make a compliance decision.
The service is provided as-is with no warranty of any kind. We are not liable for any decision made, or not made, based on its output, including any regulatory penalty, missed deadline, or enforcement action.
Subscriptions are billed monthly via Stripe and may be cancelled at any time via the Stripe billing portal link sent at signup — cancelling stops both billing and future checks.