See the outside-in estate
Start from public domains and observed web technologies, including historical first- and last-seen evidence.
M&A CYBER DUE DILIGENCE
When access to the target is limited, PatchWindow turns public technology evidence into a ranked CISA KEV confirmation list. Your security team gets a defensible place to start without waiting for agents, credentials, or another questionnaire.
THE ACCESS GAP
A questionnaire tells you what the target remembers to disclose. It rarely reveals old brands, regional sites, or acquired web properties that still sit on the public internet.
Traditional vulnerability tools become useful after credentials and deployment rights arrive. During diligence, the practical question is narrower: which observed technologies should the target prove are patched first?
WHAT YOU GET
Start from public domains and observed web technologies, including historical first- and last-seen evidence.
Join the observed inventory to the CISA Known Exploited Vulnerabilities catalog instead of handing analysts an undifferentiated CVE backlog.
Give the target a prioritized confirmation list: product, evidence, exploitation status, and the checks needed to establish actual exposure.
WHY TEAMS PAY
The free preview answers one domain. A paid monitoring workspace earns its place when the deal or integration team must coordinate a larger estate and keep the evidence current.
Compare plans →Track hundreds of public properties in one workspace instead of repeating manual lookups domain by domain.
Know when a newly exploited vulnerability maps to technology already observed across the estate.
Preserve dates, source facts, match rationale, and required confirmation steps for the diligence record.
Start expert review with a ranked shortlist, not days of inventory collection and CVE correlation.
HONEST BY DESIGN
Public technology evidence can identify where investigation is likely to pay off. It cannot reliably prove the affected version, configuration, reachability, or remediation state.
Every PatchWindow result keeps that boundary visible and tells the asset owner what must be confirmed through authorized testing.
COMMON QUESTIONS
No. Passive technology detection usually cannot establish affected version, configuration, or reachability. PatchWindow identifies potential exposure and states what an authorized team should confirm.
No. The public workflow uses passive outside-in evidence. Active scanning requires proof of control and written authorization and is not part of this product.
PatchWindow does not reduce a company to a score. It produces an evidence-backed worklist tied to specific known exploited vulnerabilities and observed technologies.
It is useful when you need portfolio-scale inventory, recurring KEV monitoring, new-match alerts, saved worklists, and API access rather than a one-domain preview.
FREE DOMAIN PREVIEW
No agent, credentials, or active scan. Upgrade when you need continuous portfolio coverage.