Terminology Reference¶
SBOM (Software Bill of Materials) — A structured inventory of the components, libraries, and dependencies that make up a piece of software, submitted in CycloneDX or SPDX format.
VEX (Vulnerability Exploitability eXchange) — A formal statement declaring whether a known vulnerability actually affects a specific product, and if so, what action is being taken.
CVE (Common Vulnerabilities and Exposures) — A unique identifier assigned to a publicly known cybersecurity vulnerability.
CVSS (Common Vulnerability Scoring System) — A standardized numeric score (0–10) representing the severity of a vulnerability.
EPSS (Exploit Prediction Scoring System) — A probability score estimating the likelihood that a vulnerability will be exploited in the wild.
KEV (Known Exploited Vulnerabilities) — The CISA-maintained catalogue of vulnerabilities confirmed to have been exploited in real-world attacks.
Organization — A user managing products, vendors, customers, and vulnerability triage on the platform.
Vendor / Supplier — A company supplying software components or products to an organization, responsible for submitting SBOMs and responding to alerts.
Customer — A user who has deployed an organization's product and receives vulnerability notifications relevant to that deployment.
Deployment — A specific installation of a product, recorded by a customer with a version, environment, and status.
Triage Status — The internal review state of a vulnerability within an organization — Unreviewed, Reviewed, or Escalated.
Notification — A vulnerability alert sent by an organization to a customer or vendor, tracked from sent through to acknowledgment.
VEX Request — A customer's formal ask for an official exploitability assessment of a specific CVE against their deployment.
OpenVEX — The open, machine-readable document format used to exchange VEX statements between systems and scanners.