
TechWatchAlert is a CVE monitoring and vulnerability intelligence platform that filters security alerts to match only the specific software versions a company actually runs. The service continuously scans seven threat feeds, including CISA's KEV catalog, and prioritizes remediation based on real-world exploitation and risk probability. It also tracks end-of-life dates for software components to prevent support gaps.
Funding
Funding not disclosed
Founders
Product
Problem
Security teams are overwhelmed by the volume of CVE alerts, most of which are irrelevant to their specific technology stack. Generic vulnerability feeds generate excessive noise, making it difficult to identify which vulnerabilities actually affect their systems and require immediate attention. This leads to alert fatigue and delayed remediation of genuinely critical threats.
Solution
TechWatchAlert provides a targeted CVE monitoring service that filters vulnerability intelligence against a company's declared technology stack, matching by CPE identifiers to ensure only relevant alerts are delivered. The platform continuously re-reads seven security feeds, including CISA's KEV catalog and FIRST.org's EPSS data, and automatically prioritizes remediation based on observed exploitation first, probability over 30 days second, and severity last. Users declare their components once—manually, via SBOM import, or from a URL—and receive real-time alerts through Slack, Teams, Discord, email, or webhooks. The service also tracks end-of-life dates for all declared components, sending alerts at D-90, D-30, and D-7 before support ends, and provides a daily brief each morning summarizing critical findings and recommended actions.
Target Audience
Primary customers are IT security teams, DevOps engineers, and independent developers who need to track vulnerabilities in their specific technology stack without noise. The service serves small teams through enterprise organizations, including public sector entities and educational institutions.
Features
- CPE-based matching against 360,000+ indexed CVE records, including reserved and rejected identifiers, to filter only relevant vulnerabilities
- Continuous monitoring of seven data feeds including CISA's KEV catalogue, CVE List v5, and FIRST.org's EPSS with 15-second sync cycles
- Automated remediation prioritization using observed exploitation status, 30-day probability scores, and CVSS severity ratings
- End-of-life tracking with automated alerts at D-90, D-30, and D-7 for every declared component
- Daily brief delivered at 8:00 AM summarizing critical CVEs, active campaigns, and available patches
- REST API v1 with 20 endpoints, Bearer authentication, and plan-based quotas for programmatic access
- Role-based access control with organizations, projects, and case management workflow (PENDING → RESOLVED)
- SBOM import support for CycloneDX format and custom watchlists for unlimited components