Use cases

M&A CYBER DUE DILIGENCE

Find the risks worth confirming before the deal closes.

When access to the target is limited, PatchWindow turns public technology evidence into a ranked CISA KEV confirmation list. Your security team gets a defensible place to start without waiting for agents, credentials, or another questionnaire.

THE ACCESS GAP

The diligence clock starts before access does.

A questionnaire tells you what the target remembers to disclose. It rarely reveals old brands, regional sites, or acquired web properties that still sit on the public internet.

Traditional vulnerability tools become useful after credentials and deployment rights arrive. During diligence, the practical question is narrower: which observed technologies should the target prove are patched first?

WHAT YOU GET

A practical first pass, built for action.

01

See the outside-in estate

Start from public domains and observed web technologies, including historical first- and last-seen evidence.

02

Focus on exploited flaws

Join the observed inventory to the CISA Known Exploited Vulnerabilities catalog instead of handing analysts an undifferentiated CVE backlog.

03

Ask better follow-up questions

Give the target a prioritized confirmation list: product, evidence, exploitation status, and the checks needed to establish actual exposure.

HONEST BY DESIGN

Potential exposure is not confirmed vulnerability.

Public technology evidence can identify where investigation is likely to pay off. It cannot reliably prove the affected version, configuration, reachability, or remediation state.

Every PatchWindow result keeps that boundary visible and tells the asset owner what must be confirmed through authorized testing.

COMMON QUESTIONS

What buyers need to know.

Does PatchWindow prove that a target is vulnerable?

No. Passive technology detection usually cannot establish affected version, configuration, or reachability. PatchWindow identifies potential exposure and states what an authorized team should confirm.

Do you actively scan the acquisition target?

No. The public workflow uses passive outside-in evidence. Active scanning requires proof of control and written authorization and is not part of this product.

How is this different from a security rating?

PatchWindow does not reduce a company to a score. It produces an evidence-backed worklist tied to specific known exploited vulnerabilities and observed technologies.

When is the paid plan useful?

It is useful when you need portfolio-scale inventory, recurring KEV monitoring, new-match alerts, saved worklists, and API access rather than a one-domain preview.

FREE DOMAIN PREVIEW

See what the worklist looks like.

No agent, credentials, or active scan. Upgrade when you need continuous portfolio coverage.