Map the public estate
Build a passive technology inventory with first- and last-seen evidence.
Turn a domain into a prioritized worklist of technologies potentially exposed to CISA-known exploited vulnerabilities. No access. No agents. No guess disguised as certainty.
THE ACCESS GAP
Traditional vulnerability tools are excellent after you own the asset. PatchWindow is for the awkward weeks before that—when the deal committee needs a risk worklist and you have no right to scan or install anything.
We join passive BuiltWith technology history with CISA’s official KEV catalog, then show exactly what your security team should confirm first.
FROM DOMAIN TO DECISION
Build a passive technology inventory with first- and last-seen evidence.
Match detected products to vulnerabilities CISA says are actively exploited.
Export a ranked confirmation list with evidence, caveats, and required actions.
LIVE SOURCE-OF-RECORD
A DEAL DEADLINE IS NOT A DEPLOYMENT WINDOW
Start with one public domain. Upgrade when you need a portfolio-wide decision package.