Every CVE says it matters. Signal tells you if it actually does.

Signal turns the global vulnerability feed into environment-specific, continuously current, evidence-backed intelligence. You stop searching feeds and start knowing exactly what in your stack is exposed, and why.

CHANNEL: GLOBAL CVE FEED RESOLVING LIVE
A live-looking diagram of many overlapping noisy signal traces resolving into a single steady, glowing orange line, illustrating how Signal isolates what matters from the global vulnerability feed.
Noise: not applicable to your stack Signal: confirmed, evidence-backed

CH.00 · THE PROBLEM

The feed doesn't know what you run.

Thousands of CVEs publish every month. Almost none apply to your specific stack. Nothing in the raw feed tells you which ones do. Most teams end up drowning in noise, or trusting a shortcut that quietly gets it wrong.

01

You get the whole feed

Traditional CVE dashboards show you everything published, everywhere. Working out what's actually relevant is still your job, CVE by CVE, every day.

02

Matching by hand doesn't scale

CVE records don't name vendors and products the way people do. Lexical matching alone has, in practice, compared one product's version range against a completely different one. Nobody confirmed the two were the same thing first.

03

Uncertainty quietly becomes "safe"

Most tools collapse "we don't know" into "not affected." That's the single worst failure mode in vulnerability management. Signal is built so unknown never silently becomes no.

51%

of sysadmins say timely security patch implementation takes up too much time. 2026 State of Sysadmin Report

CH.01 · LIVE ENVIRONMENT

This is the actual product.

Every screenshot on this page is a live, unedited capture from a real Signal environment, including the parts that are still a work in progress for that environment's owner.

A real environment, 11 technologies, 2,206 matched CVEs. Read the bottom line of the pressure panel: 1,759 confirmed, 447 awaiting version data. That's not a bug. It's the four-state applicability model working exactly as designed, at real scale. Most tools would either hide the 447, or worse, quietly call them "not affected." Signal shows you both numbers, every time.

When something is genuinely urgent, Signal doesn't bury it in a severity list. Active exploitation (KEV) and zero-day status surface as unmistakable badges at the top of the queue, not buried in a CVSS number.

CH.02 · HOW SIGNAL WORKS

One pipeline. Five disciplined stages. Nothing skipped.

Every vulnerability that reaches you has passed through the same gated sequence. Each stage answers exactly one question before handing off to the next.

CH.01 · INGEST

Ingest

Continuous ingestion of the global CVE corpus, enriched with CISA KEV (confirmed active exploitation) and FIRST.org EPSS (exploitation probability).

CH.02 · IDENTIFY

Identify

Is this CVE even about a product you run? Signal resolves that with graded confidence: authoritative or probable. It never presents a guess as certainty.

CH.03 · APPLICABILITY

Applicability

Does it apply to how you've actually deployed it? Signal returns one of four outcomes: confirmed, potential, insufficient coverage, or not applicable.

CH.04 · VERSION

Version analysis

Is your installed version inside the affected range? The verdict is confirmed, not affected, or indeterminate. Indeterminate gets reported, never hidden.

CH.05 · SCORE

Score & recommend

CVSS, active exploitation, exploitation probability, asset criticality, and deployment scope combine into one auditable score, paired with one specific instruction.

CH.03 · EXPLAINABLE BY DESIGN

Every score comes with its receipts.

Signal doesn't hand you a bare CVSS number and call it prioritization. Every finding carries a deterministic, versioned operational score, along with a human-readable trail showing exactly which evidence produced it.

  • CVSS base score, CISA KEV status, and EPSS probability combined into a single formula, not just listed side by side
  • Asset criticality and deployment scope weighted into the same formula
  • Fixed, change-controlled tier thresholds. Critical means the same thing every time
  • No black box, no silent formula drift, no "trust the vendor score"

CH.04 · WHAT SETS IT APART

Built to stay right as the world changes.

Self-growing registry

Signal notices new vendor/product pairs appearing in the vulnerability corpus and proposes them for governed admission. No manual onboarding queue required.

Drift correction

When a known product's naming or aliases shift, Signal notices and corrects coverage automatically, before it can silently drop findings.

Four-state applicability

"Not applicable" is a claim Signal has to earn with evidence. It's never a default fallback under uncertainty.

Your judgment, kept separate

Acknowledge, dispute, or suppress a finding without it silently overwriting Signal's own evidence-based verdict. Fully auditable, both directions.

CH.05 · BUILT FOR WHAT YOU ACTUALLY RUN

From the edge to the data center.

Signal's registry keeps expanding on its own as new technology appears in the global vulnerability corpus. Engineered around the stacks security teams actually operate:

MicrosoftRed HatOracleVMware Palo Alto NetworksFortinetSonicWallCisco ApacheVeeamSplunkKeycloak PostgreSQLMySQLCitrixNginx

CH.06 · BUILT TO BE TRUSTED

The same rigor you'd expect from intelligence you rely on.

Sequential

Disciplined pipeline

Every technology Signal supports passes through the same gated pipeline, end to end. Nothing skipped, nothing shortcut.

Continuous

KEV coverage

CISA KEV status is pulled in as part of Signal's regular ingestion cycle, not tracked separately or imported once. When CISA adds a vulnerability, Signal's coverage catches up on the same cycle as everything else.

100%

Explainability

Every scored threat must show its reasoning. No exceptions, no silent black-box scores.

Row-level

Database-enforced isolation

Every customer's environment data is isolated at the database layer using row-level security. That protection doesn't depend on application logic alone.

CH.07 · JOIN NOW

You won't be customer #10,000.

Join now and you're talking to the people building Signal, not a support queue. Your environment, your feedback, and your priorities shape what gets built next.

Direct roadmap input

What founding customers ask for is what gets built next. Not a feature-request form that disappears into a backlog.

Early-partner pricing

Pricing that reflects joining while Signal is still being built, not the rate a mature platform charges its ten-thousandth customer.

Real access to the team

You're reaching the people who build Signal directly, not a ticket queue.

CH.08 · PLANS

Free tells you what's happening globally. Paid tells you what matters to you.

Free is real, factually-rigorous intelligence in its own right. Upgrade when you want that same rigor applied to the exact technology you run.

Signal is under active development. Core threat matching is production-grade, tested, and monitored. Some features are still being refined based on customer feedback.

Free

Global threat situational awareness

R 0

Free during early access. Standard pricing may apply later.

  • Global CVE feed with real-time KPI monitoring
  • Operational Threat Pressure scoring: global view
  • Severity distribution, attack vector analysis, top affected vendors
  • Up to 10 threat feed refreshes per day
  • Up to 10 CVE intelligence queries per month
  • No environment context. Upgrade to Pro for stack-aware intelligence
Get started free

Enterprise

Multi-environment operational threat intelligence

R 2,499/mo
  • Everything in Pro
  • Up to 3 independent managed environments (Production, Staging, Dev)
  • Each environment maintains its own stack, pressure scores, and threat list
  • Multi-environment switching
  • Environment lifecycle management: archive, reactivate, set primary
Get started with Enterprise

Prices exclude VAT where applicable. Billed monthly or annually via PayFast (PCI DSS-compliant checkout).

Prefer a walkthrough before you sign up? Request one at info@visionzero.co.za

CH.09 · QUESTIONS

Common questions before you sign up.

Does Signal support multiple environments?

Yes. Enterprise plans support up to 3 independently managed environments, each with its own technology stack, pressure scores, and threat list.

How is this different from raw NVD or KEV feeds?

Those feeds tell you what's been published, globally. Signal tells you which of those apply to what you actually run, with the evidence trail behind that verdict.

Is this a replacement for a vulnerability scanner?

No. A scanner tells you what's installed. Signal tells you which of the world's disclosed vulnerabilities matter for that installed footprint, and how urgently.

Do I need to install anything?

No agents, no scanners. You describe your environment; Signal does the matching against the CVE corpus continuously.

What if Signal doesn't support a technology I use?

Signal's registry grows automatically. Every CVE we ingest is scanned for vendor and product references we don't yet recognize, and likely matches get queued for review. If a technology you use isn't covered yet, you can request it directly from inside the app. Every request is reviewed by our engineering team, not left to an algorithm alone.

Stop searching feeds.
Start knowing what's actually exposed.

Prefer a walkthrough before you sign up? Request one at info@visionzero.co.za