Public sources, one format
Advisories from CISA KEV, NVD, GitHub, OSV and the EU database are merged into one model, with exploitation-likelihood scores where they exist. You can browse them all in our public database.
Every week brings alarming headlines about vulnerabilities. Almost none of them affect your site. AegiFlow compares each published advisory against the exact software versions your service runs, and tells you plainly: affected, clear, or not enough information.
Over 16,000 advisories are normalized from public sources and refreshed daily. A conclusion is only as good as the inventory behind it, so stale information is shown as Unknown instead of being rounded up to «safe».
Every capability has a narrow responsibility, an operational state and evidence that explains the result.
Advisories from CISA KEV, NVD, GitHub, OSV and the EU database are merged into one model, with exploitation-likelihood scores where they exist. You can browse them all in our public database.
For every pairing of advisory and service it records the verdict, the evidence behind it, how fresh the inventory was and when it was last checked.
Public indexes and DNS are read to find every hostname under your domain, without sending your servers a single request. The one that matters is a record pointing at a service that no longer exists: somebody else can claim that name and serve content from an address that still carries your brand.
Everything else here is observation. This is the one capability that sends traffic somebody could object to, so it needs a separate authorization naming an exact hostname, a rate ceiling, a contact who can stop it, and an expiry date. Capped at twenty requests a second, never internet-wide, revocable in one click.
A signed collector pushes the list of installed components outward. It never opens a way into your server and never reads your content.
The visitor path remains short. Configuration, verification and rollback stay visible to the operator at every stage.
Advisories are gathered, de-duplicated and prioritized away from your traffic.
Package names and versions are matched exactly — no guessing by product family.
A real match opens one case and a proposal that stays reversible.
AegiFlow does not turn missing evidence into a reassuring zero. Every state links to its source, freshness and next action.
How this capability behaves in production — grounded in the platform's documented, current operation.
Threat Radar normalizes CISA KEV, NVD, GitHub Advisory, OSV and ENISA EUVD into one evidence model, scored with EPSS — over 16,000 advisories and growing daily. Then it asks the only question that matters: does this match the exact packages and versions your service actually runs? Browse the public database at aegiflow.com/threat-radar/database/.
For every advisory-service pair, the ledger records affected, protected, not affected — or unknown. Unknown stays visible until the inventory is fresh enough to answer. No advisory silently deploys a virtual patch, and no stale inventory is presented as safety.
Ownership, certificate, origin health and rollback must pass before traffic protection changes.