Use cases

PRIVATE EQUITY CYBERSECURITY

One KEV alert. Every portfolio company that may need to act.

PatchWindow gives operating and security teams an outside-in view across the portfolio. When CISA adds an actively exploited vulnerability, see which public properties use related technology and where confirmation should begin.

THE ACCESS GAP

Portfolio risk is distributed. Your response cannot be.

Each company has different tools, asset records, and security maturity. A time-critical KEV can trigger dozens of emails before anyone knows which companies are even plausible candidates for exposure.

PatchWindow creates a common passive inventory layer. It does not replace each company’s security program; it tells the operating team where to ask for confirmation and where a broad portfolio-wide escalation would waste time.

WHAT YOU GET

A practical first pass, built for action.

01

Watch the whole portfolio

Organize up to 500 public properties in one monitoring workspace, including brands and internet properties outside a single parent domain.

02

Route the right alert

Map new CISA KEV entries to observed technology so outreach begins with the companies most likely to need confirmation.

03

Keep evidence attached

Show why a property matched, when the technology was observed, and which uncertainty the asset owner must resolve.

HONEST BY DESIGN

Potential exposure is not confirmed vulnerability.

Public technology evidence can identify where investigation is likely to pay off. It cannot reliably prove the affected version, configuration, reachability, or remediation state.

Every PatchWindow result keeps that boundary visible and tells the asset owner what must be confirmed through authorized testing.

COMMON QUESTIONS

What buyers need to know.

Does every portfolio company need to install an agent?

No. PatchWindow uses passive public technology observations, so the operating team can establish an initial portfolio view without local deployment.

Can it find every asset or vulnerability?

No. Outside-in evidence is necessarily incomplete, and many vulnerabilities are version- or configuration-specific. The product prioritizes confirmation; it is not a replacement for authenticated asset and vulnerability management.

Why not send every KEV to every company?

Blanket alerts create fatigue and consume security time. Technology matching narrows the initial outreach while keeping the limitations visible.

What is included in the monitoring plan?

The plan covers up to 500 public properties, daily KEV change monitoring, new-match alerts, a portfolio dashboard, and API access.

FREE DOMAIN PREVIEW

See what the worklist looks like.

No agent, credentials, or active scan. Upgrade when you need continuous portfolio coverage.