Every CVE looks urgent. Signal tells you which ones are.
Signal matches new CVEs against the products and versions you run, then shows what’s exposed, what to fix first, and the evidence behind every call.
Diagram: five inputs, the global CVE feed, vendor and CNA records from the source, CISA KEV, FIRST EPSS and your stack, flow into Signal. Most vulnerabilities come out as grey noise that doesn’t touch your stack and fade away. The rest are sorted into one of four verdicts: Confirmed, Potential, Insufficient coverage, or Not applicable. Every verdict is kept, including insufficient coverage. An example finding card shows CVE-2026-24858, Fortinet FortiGate, Confirmed, production and internet-facing, priority Act Now, upgrade FortiOS to 7.6.6 or later, evidence attached.
THE PROBLEM
The feed doesn’t know what you run.
Thousands of CVEs are published every month. Almost none apply to your specific stack. Nothing in the raw feed tells you which ones do. Most teams end up drowning in noise, or trusting a shortcut that quietly gets it wrong.
You get the whole feed
Raw CVE feeds show you everything published, everywhere. Working out what’s actually relevant is still your job, CVE by CVE, every day.
Product names don’t match
The same product appears under different names in different CVE records, and similar names can mean different products. Matching on names alone misses real exposure and flags things you don’t run.
Mentions aren’t exposure
Most alerting tells you a CVE mentions a product you use. It doesn’t tell you whether your version is affected, or admit when it can’t tell.
of CVEs published in the last 30 days had product data from NVD. Signal doesn’t rely on NVD alone.Signal data, September 2026. NIST limited NVD enrichment in April 2026.
FOUR VERDICTS
Four answers. No guessing.
A CVE that names a product you run isn’t the same as a CVE that affects your version. Signal gives every match one of four answers, based on the evidence it has.
Confirmed
Your installed version is inside the affected range. Signal scores it and tells you how urgently to act.
Potential
The CVE matches a product you run, but your version can’t be confirmed either way. It stays on your list with the reason.
Insufficient coverage
Signal doesn’t have vulnerability data for a technology you run yet. The dashboard flags it instead of showing zero risk.
Not applicable
Every source shows your version is outside the affected range. Only then is the CVE removed from your list.
IN THE PRODUCT
See which vulnerabilities actually match your environment.
Environment Intelligence takes the technology stack you describe and turns the global feed into a ranked list of what needs your attention. Available on Pro and Enterprise.
Every match is ranked into Act Now, Prioritise, Investigate or Monitor. Matches whose version can’t be confirmed wait in Needs review, with the reason.
A probable identity match is labelled as probable. Every finding carries its own trail: the version verdict, how the product was identified, and the evidence behind it.
HOW IT WORKS
CVE-2026-24858, from global feed to instruction.
Here’s every step between a CVE being published and knowing exactly what to do about it.
Critical, CVSS 9.8
An authentication bypass affecting a range of FortiOS-family products, published to the global CVE feed.
Fortinet FortiGate
Signal matches the CVE to the product you run using its official product identifier, not just its name. This is a match at the highest confidence level.
Confirmed
The CVE affects FortiOS 7.6.0 through 7.6.5. Your version, 7.6.4, is inside that range.
Production, internet-facing
Deployment context that raises operational exposure, not just a severity label.
Act Now
CVSS 9.8, on CISA’s list of actively exploited flaws, an 86% exploitation probability, and a production, internet-facing deployment. Score: 10 out of 10.
Upgrade to 7.6.6 or later
A later fix, 7.6.7, is already known in this branch, so the minimum patch doesn’t read as the finish line.
EXPLAINABLE BY DESIGN
You can see why Signal gave a finding its priority.
Signal doesn’t hand you a bare CVSS number and call it prioritisation. Every scored finding shows its priority and a plain-language trail of exactly which evidence produced it.
- CVSS base score, CISA KEV status and EPSS probability combined into a single formula, not just listed side by side
- Deployment scope and internet-facing exposure weighted into the same formula
- The same thresholds for every finding: 9.0 and above is Act Now, 7.0 and above Prioritise, 4.0 and above Investigate, anything lower Monitor.
- No black box, no silent formula drift, no “trust the vendor score”
The trail behind one Act Now finding: each factor that raised its score, and the sources behind the version verdict.
Score scale from 0 to 10, with thresholds at 4.0 Investigate, 7.0 Prioritise and 9.0 Act Now. The example finding, CVE-2026-24858, starts at CVSS 9.8. KEV, EPSS, production and internet-facing factors raise it to the 10.0 cap: Act Now.
COVERAGE AND CONTROL
Coverage that grows. Decisions that stay yours.
Coverage keeps growing
When new products appear in CVE records, Signal flags them automatically. Only very high-confidence matches are added without an engineer reviewing them first.
Missing a product? Ask for it
Request any technology you run from inside the app, on Pro and Enterprise. An engineer reviews every request.
Your judgement, kept separate
Acknowledge or suppress a finding without changing Signal’s own verdict. If Signal’s priority for that finding changes later, it comes back to you for review.
BUILT FOR WHAT YOU ACTUALLY RUN
From the edge to the data centre.
Signal recognises more than 1,500 products from the vendors security teams rely on. A few of them:
Missing something you run? Request it from inside the app.
PLANS
Free tells you what’s happening globally. Paid tells you what matters to you.
Free is real, factually rigorous intelligence in its own right. Upgrade when you want that same rigour applied to the exact technology you run.
Converted at an approximate, periodically-updated exchange rate for reference only. All plans are billed in ZAR via PayFast.
Free
Global threat situational awareness
Free during early access. Standard pricing may apply later.
- Global CVE feed with real-time KPI monitoring
- Operational Threat Pressure scoring: global view
- Attack vector analysis across the global feed
- No environment context. Upgrade to Pro for stack-aware intelligence
Pro
Stack-aware vulnerability intelligence for your environment
- Everything in Free
- Full Vulnerability Dashboard: search, filter and page through CVEs from the last 90 days
- Severity distribution and top affected vendors, with corpus-wide vendor totals
- Technology stack intelligence: automatically identify which CVEs affect your environment
- Environment Dashboard: threat intelligence scoped to your specific stack
- Exposure scoring: CVEs ranked by CVSS, KEV status, EPSS and your deployment context
- Automatic prioritisation: Act Now, Prioritise, Investigate or Monitor for every CVE
- KEV-listed tracking within your environment
Enterprise
Multi-environment operational threat intelligence
- Everything in Pro
- Up to 3 independent managed environments (Production, Staging, Dev)
- Each environment maintains its own stack, pressure scores, and threat list
- Multi-environment switching
- Environment lifecycle management: archive, reactivate, set primary
Prices exclude VAT where applicable. Billed monthly or annually through PayFast.
EARLY ACCESS
You won’t be customer #10,000.
You deal directly with the team that builds Signal, and your feedback shapes what gets built next.
QUESTIONS
Common questions before you sign up.
Yes. Enterprise plans support up to 3 independently managed environments, each with its own technology stack, pressure scores and threat list.
Those feeds tell you what’s been published, globally. Signal tells you which of those apply to what you actually run, with the evidence behind each verdict.
New CVEs come from NVD, which Signal checks every 15 minutes. Most reach Signal within about 15 minutes of NVD publishing them. Because NVD no longer adds product data to most new CVEs, Signal also takes product and version data from CVE.org records written by the organisations that assign CVEs, and from Red Hat, Microsoft and Cisco advisories. CISA’s list of actively exploited vulnerabilities is checked on every run, and FIRST EPSS exploitation scores are updated daily.
No. A scanner tells you what’s installed. Signal tells you which of the world’s disclosed vulnerabilities matter for what you run, and how urgently.
No agents, no scanners. You describe your environment, and Signal matches it against new vulnerabilities as they’re published.
No. You describe your technology stack (vendor, product and version) directly in Signal. We never request infrastructure credentials, network access or scanning permissions.
Isolation is enforced by the database itself, using row-level security, so it doesn’t depend on application code alone. No customer can see another customer’s environment, findings or settings.
A small Signal operations team can view environment data to run and support the service. We never share it, and we never ask for access to your infrastructure.
Your technology stack and environment data is stored with Supabase in the European Union. Vercel serves the web application, and Resend sends alert emails, which contain environment names and matched CVE lists. Payment data is handled separately, within South Africa, by PayFast. See our Privacy Policy for details.
Yes. You can acknowledge or suppress any finding. Your decision is stored separately and never changes Signal’s own verdict. If Signal’s priority for that finding changes later, it comes back to you for review.
Signal recognises more than 1,500 products and flags new ones as they appear in CVE records. If something you run isn’t covered yet, you can request it from inside the app on Pro and Enterprise. Every request is reviewed by our team.
Stop searching feeds.
Start knowing what’s actually exposed.
Free to start. Matching against your own stack is on Pro and Enterprise.
No agent. No network access. No infrastructure credentials.