Passive intelligence for time-critical diligence

Find the patch window
before it closes.

Turn a domain into a prioritized worklist of technologies potentially exposed to CISA-known exploited vulnerabilities. No access. No agents. No guess disguised as certainty.

Passive lookup only · Free preview · No login required

1,653known exploited vulnerabilities tracked
2026-07-22latest catalog addition
0agents or credentials required
Built for the diligence windowPRIVATE EQUITYCORPORATE DEVELOPMENTPORTFOLIO OPERATIONSSECURITY LEADERS

THE ACCESS GAP

You need an answer.
The target cannot give you access.

Traditional vulnerability tools are excellent after you own the asset. PatchWindow is for the awkward weeks before that—when the deal committee needs a risk worklist and you have no right to scan or install anything.

We join passive BuiltWith technology history with CISA’s official KEV catalog, then show exactly what your security team should confirm first.

FROM DOMAIN TO DECISION

A defensible first pass in minutes.

01

Map the public estate

Build a passive technology inventory with first- and last-seen evidence.

02

Join against KEV

Match detected products to vulnerabilities CISA says are actively exploited.

03

Work the shortlist

Export a ranked confirmation list with evidence, caveats, and required actions.

LIVE SOURCE-OF-RECORD

Recent KEV additions

Explore the catalog →

A DEAL DEADLINE IS NOT A DEPLOYMENT WINDOW

Know what to confirm before you sign.

Start with one public domain. Upgrade when you need a portfolio-wide decision package.