← Software & GRC projects
PUBLIC VULNERABILITY INTELLIGENCE + GRC

Third-Party Risk
& Vulnerability Monitor

Built a review workspace that connects real public vulnerability records to a fictional organization's vendor inventory. Focus on High and Critical CISA KEV findings, understand their potential technical and business impact, then document applicability, ownership, and treatment decisions.

PythonAPI integrationCISA KEVNVDEPSSThird-party risk
Open the risk monitor ↗

Five curated vendor/product profiles and up to ten KEV candidates. Published snapshot plus on-demand public-feed refresh. Business context and reviews are fictional; no private company data is used.

EVIDENCE → CONTEXT → DECISION
  1. 01 / COLLECTPublic vulnerability signals

    Source links, retrieval dates, and explicit unavailable data

  2. 02 / VALIDATEConfirm applicability

    Product matches begin as candidates, not confirmed exposures

  3. 03 / DOCUMENTRecord the response

    Owner, target date, evidence, acceptance review, and export

PROJECT APPROACH

Risk needs context.

The Python collector builds a dated snapshot using CISA's catalog, the NVD CVE API, and FIRST EPSS. A browser refresh can request new public data; unavailable feeds remain clearly labeled. There is no continuous background monitoring.

A small curated inventory samples two recent KEV entries per product, then shows only entries with CVSS scores of 7.0 or higher. Lower scores and unavailable severity are counted but excluded from the review queue. This is not exhaustive vulnerability discovery, automatic version matching, or a vendor security rating. Analyst review connects the technical signal with the fictional deployment.

Vendor profiles include four due-diligence areas: data handling, access controls, incident notification, and business continuity. Review decisions and evidence can be exported as a Markdown assessment. Optional browser-local saving retains fictional reviews, due-diligence notes, and history after reload. Storage is unencrypted and is not an independent audit trail.

Try it: open a finding, record version evidence, confirm applicability, assign an owner and date, then export the assessment. Risk acceptance requires a reviewer and justification and does not reduce the finding's priority.