A tool born of one specific annoyance.
Too many mornings spent going through feeds to check whether one of the night's sixty CVEs hit a server we ran. The answer was no 99% of the time. The problem is the 1%.
Why we exist
The CVE program published more than 40,000 vulnerabilities last year. A team that read every record would spend more than two hours per working day on it, for a relevance rate below 1%. Nobody does. Instead, people read three feeds, miss a fourth, and discover the flaw on the day it is exploited.
Triage is mechanical work: comparing a product identifier and a version against a list. That is exactly what a machine does well and what a human does badly at eight in the morning. We built the machine, and kept the human for the decision: what to fix first, and what can wait.
What we do, and what we don't
We do targeted vulnerability monitoring: we start from what you declare, cross-check seven feeds, prioritize by real-world exploitation, track through to the fix, and warn you about end-of-support dates before they hit.
We are not an active network scanner: we don't probe your network. We are not a code analysis tool: we don't read your repositories. We are not a compliance platform: we don't produce standards-based audit reports. For those three needs, other tools are better, and we say so page by page.
Where the product stands
TechWatchAlert is a young product, and it is more honest to write that than to let you find out. Running in production: feed synchronization, matching against declared stacks, prioritization, notification channels, end-of-support tracking and the read API. Still stabilizing: visual workflows and the Vigie assistant.
Our availability target is 99.5% per calendar month, taken as-is from our terms of use. We don't sell 24/7 on-call or a 99.95% commitment: neither exists today, and a security vendor that promises what it can't deliver has already lost what matters most.
Our commitments
- Real sovereignty, not decoration. The application, the CVE database and your inventories are hosted in the Paris region. No subprocessor outside the EU has access to them.
- Your data is not the product. Your inventory is used to filter the CVE feed, and for nothing else: no resale, no model training, no sharing. It is written in the privacy policy, with the list of subprocessors and their countries.
- Reversibility by default. You export everything, whenever you want, without writing to us and at no cost.
- Dated, sourced figures. When we publish a figure, we say where it comes from and how old it is. When we get something wrong, tell us and we fix it.
What you won't find here
No customer testimonials in quotation marks: we will only publish real ones, named and dated, with their author's written consent. In the meantime, the pricing page describes usage scenarios, presented as such.