Every CVE says it matters. Signal tells you if it actually does.
Signal turns the global vulnerability feed into environment-specific, evidence-backed intelligence, so you know exactly what's exposed and why.
CH.00 · THE PROBLEM
The feed doesn't know what you run.
Thousands of CVEs publish every month. Almost none apply to your specific stack. Nothing in the raw feed tells you which ones do. Most teams end up drowning in noise, or trusting a shortcut that quietly gets it wrong.
You get the whole feed
Traditional CVE dashboards show you everything published, everywhere. Working out what's actually relevant is still your job, CVE by CVE, every day.
Matching by hand doesn't scale
CVE records don't name vendors and products the way people do. Lexical matching alone has, in practice, compared one product's version range against a completely different one. Nobody confirmed the two were the same thing first.
Uncertainty quietly becomes "safe"
Most tools collapse "we don't know" into "not affected." That's the single worst failure mode in vulnerability management. Signal is built so unknown never silently becomes no.
of sysadmins say timely security patch implementation takes up too much time. 2026 State of Sysadmin Report
CH.01 · UNKNOWN NEVER BECOMES NO
Most tools have two answers. Signal has four.
"Affected" or "not affected" is easy to compute and easy to get wrong. When the evidence doesn't support a clean answer, Signal says so instead of guessing.
Confirmed
We have evidence it affects you.
Potential
Evidence suggests it may affect you, without full certainty yet.
Insufficient coverage
We don't have enough information to say either way, and we say so rather than guess.
Not applicable
We have evidence it does not affect you. Never a default assumption under uncertainty.
If Signal doesn't know, it tells you it doesn't know.
CH.02 · LIVE ENVIRONMENT
See which vulnerabilities actually match your environment.
Environment Intelligence takes your technology stack and turns the global feed into a prioritised list of what actually needs your attention.
Signal doesn't hide uncertainty to make the dashboard look cleaner. What's confirmed is confirmed. What isn't, says so.
A probable match isn't treated the same as a confirmed one. This finding surfaces with its own confidence trail, made up of a version verdict, resolution path, and evidence basis, not folded into a generic severity score.
CH.03 · ONE VULNERABILITY, END TO END
CVE-2026-24858, from global feed to instruction.
Here's every step between a CVE being published and knowing exactly what to do about it.
Critical
An authentication bypass affecting a wide range of FortiOS-family products, published to the global CVE corpus.
Fortinet FortiGate
Authoritative identity match. Both vendor and product resolved via canonical CPE strings, at the highest confidence level.
Confirmed
Evidence this version is actually affected, not just named in the advisory.
Production, internet-facing
Deployment context that raises operational exposure, not just a severity label.
Act Now
Severity and real-world exploitation combine into one number that tells you how urgently to act.
Patch to the confirmed fix version
Signal also flags when a newer fix already exists in the same branch, so the minimum patch doesn't read as the finish line.
CH.04 · HOW SIGNAL WORKS
Every finding goes through the same five steps.
Signal checks every finding in the same order. It identifies the product, checks whether the vulnerability applies to how you've deployed it, evaluates the installed version, and determines how urgently you need to act.
Ingest
Continuously ingested from multiple independent vulnerability sources, not just one feed, since no single source enriches every CVE. CISA KEV (confirmed active exploitation) and FIRST.org EPSS (exploitation probability) are layered on top.
Identify
Is this CVE even about a product you run? Signal resolves that with graded confidence, not a single yes/no guess. A probable match is never presented as a confirmed one.
Applicability
Does it apply to how you've actually deployed it? Signal returns one of four outcomes: confirmed, potential, insufficient coverage, or not applicable.
Version analysis
Is your installed version inside the affected range? The verdict is confirmed, not affected, or indeterminate. Indeterminate gets reported, never hidden.
Score & recommend
CVSS, active exploitation, exploitation probability, asset criticality, deployment scope, and internet-facing exposure combine into a single score, paired with one specific instruction.
CH.05 · EXPLAINABLE BY DESIGN
You can see why Signal gave a finding its priority.
Signal doesn't hand you a bare CVSS number and call it prioritization. Every finding carries a scored, versioned priority, along with a plain-language trail showing exactly which evidence produced it.
- CVSS base score, CISA KEV status, and EPSS probability combined into a single formula, not just listed side by side
- Asset criticality, deployment scope, and internet-facing exposure weighted into the same formula
- Fixed, change-controlled tier thresholds. Critical means the same thing every time
- No black box, no silent formula drift, no "trust the vendor score"
Patch to 7.6.6 to remediate this KEV vulnerability. That's the CVE's own fix. Signal also tells you a later fix (7.6.7) already exists in this branch, so you're not left thinking the minimum patch is the latest one.
CH.06 · WHAT SETS IT APART
The registry keeps itself current.
Your coverage keeps growing
Signal notices new vendor/product pairs appearing in the vulnerability corpus and proposes them for governed admission. It's a self-growing registry, not a manual onboarding queue.
Drift correction
When a known product's naming or aliases shift, Signal notices and corrects coverage automatically, before it can silently drop findings.
Your judgment, kept separate
Acknowledge, dispute, or suppress a finding without it silently overwriting Signal's own verdict. Both stay on record, so you can see what changed and why.
CH.07 · BUILT FOR WHAT YOU ACTUALLY RUN
From the edge to the data center.
Engineered around the stacks security teams actually operate:
CH.08 · BUILT TO BE TRUSTED
The same rigor you'd expect from intelligence you rely on.
Same steps, every time
Every technology Signal supports goes through the identical pipeline, start to finish. Nothing skipped, nothing shortcut.
KEV coverage
CISA KEV status is pulled in as part of Signal's regular ingestion cycle, not tracked separately or imported once. When CISA adds a vulnerability, Signal's coverage catches up on the same cycle as everything else.
Explainability
Every scored threat must show its reasoning. No exceptions, no silent black-box scores.
Database-enforced isolation
Every customer's environment data is isolated at the database layer using row-level security. That protection doesn't depend on application logic alone.
CH.09 · JOIN NOW
You won't be customer #10,000.
Join now and you're talking to the people building Signal, not a support queue. Your environment, your feedback, and your priorities shape what gets built next.
Direct roadmap input
What founding customers ask for is what gets built next. Not a feature-request form that disappears into a backlog.
Early-partner pricing
Pricing that reflects joining while Signal is still being built, not the rate a mature platform charges its ten-thousandth customer.
Real access to the team
You're reaching the people who build Signal directly, not a ticket queue.
CH.10 · PLANS
Free tells you what's happening globally. Paid tells you what matters to you.
Free is real, factually-rigorous intelligence in its own right. Upgrade when you want that same rigor applied to the exact technology you run.
Signal's core threat matching is live, tested, and monitored today. Everything else keeps growing, shaped by the founding customers using it right now.
Converted at an approximate, periodically-updated exchange rate for reference only. All plans are billed in ZAR via PayFast.
Free
Global threat situational awareness
Free during early access. Standard pricing may apply later.
- Global CVE feed with real-time KPI monitoring
- Operational Threat Pressure scoring: global view
- Severity distribution, attack vector analysis, top affected vendors
- Up to 10 threat feed refreshes per day
- Up to 10 CVE intelligence queries per month
- No environment context. Upgrade to Pro for stack-aware intelligence
Pro
Stack-aware vulnerability intelligence for your environment
- Everything in Free
- Full Vulnerability Dashboard: search, filter, and paginate the entire CVE corpus
- Corpus-wide vendor search: find every CVE affecting any vendor, across all time
- Technology stack intelligence: automatically identify which CVEs affect your environment
- Environment Dashboard: threat intelligence scoped to your specific stack
- Exposure Pressure Scoring: CVEs ranked by CVSS, KEV status, and recency
- Automatic prioritisation: Act Now / Prioritise / Investigate / Monitor per CVE
- KEV-Listed tracking within your environment
- Unlimited threat feeds and CVE intelligence queries
Enterprise
Multi-environment operational threat intelligence
- Everything in Pro
- Up to 3 independent managed environments (Production, Staging, Dev)
- Each environment maintains its own stack, pressure scores, and threat list
- Multi-environment switching
- Environment lifecycle management: archive, reactivate, set primary
Prices exclude VAT where applicable. Billed monthly or annually via PayFast (PCI DSS-compliant checkout).
Prefer a walkthrough before you sign up? Request one at info@visionzero.co.za
CH.11 · QUESTIONS
Common questions before you sign up.
Does Signal support multiple environments?
Yes. Enterprise plans support up to 3 independently managed environments, each with its own technology stack, pressure scores, and threat list.
How is this different from raw NVD or KEV feeds?
Those feeds tell you what's been published, globally. Signal tells you which of those apply to what you actually run, with the evidence trail behind that verdict.
Is this a replacement for a vulnerability scanner?
No. A scanner tells you what's installed. Signal tells you which of the world's disclosed vulnerabilities matter for that installed footprint, and how urgently.
Do I need to install anything?
No agents, no scanners. You describe your environment; Signal does the matching against the CVE corpus continuously.
Do you need credentials or access to our infrastructure?
No. You describe your technology stack (vendor, product, and version) directly in Signal. We never request infrastructure credentials, network access, or scanning permissions.
Where does our environment data go?
Your technology stack and environment data is processed via Supabase infrastructure, which operates in the United States and/or European Union. Payment data is handled separately, within South Africa, by PayFast. See our Privacy Policy for details.
Can analysts override a finding?
Yes. You can acknowledge, dispute, or suppress any finding. That action is recorded separately and doesn't overwrite Signal's own verdict. Both stay visible, so you can see what changed and why.
What if Signal doesn't support a technology I use?
Signal's registry grows automatically. Every CVE we ingest is scanned for vendor and product references we don't yet recognize, and likely matches get queued for review. If a technology you use isn't covered yet, you can request it directly from inside the app. Every request is reviewed by our engineering team, not left to an algorithm alone.
Stop searching feeds.
Start knowing what's actually exposed.
No agent. No network access. No infrastructure credentials.