Intelligence and priority

Sources and provenance

Advisories come from OSV (including GitHub Security Advisories); exploitation signals from CISA KEV and advisory references; EPSS from FIRST. Every source is stored with its facts (severity, CVSS, fixed versions) and a confidence level. Conflicting facts are never collapsed silently — the vulnerability page shows a "Sources disagree" panel.

EPSS

The Exploit Prediction Scoring System estimates the probability of exploitation activity in the next 30 days. Vellaci shows probability, percentile and last update. It is a prioritisation signal, not a deterministic statement.

Exploitation evidence

Instead of a boolean, a vulnerability carries signals: CISA KEV (authoritative), vendor advisory, public exploit, threat intelligence, in-the-wild reports and manual evidence recorded by your team with source, confidence and observed time. The summary (none / possible / evidence / confirmed) feeds the priority model and the CRA review.

Priority model

An explainable 0–100 score from CVSS, EPSS, exploitation, internet exposure, product criticality, affected versions, customer exposure and fix availability. Weights are normalised and configurable (Settings → Policies). It is not legal severity and never decides CRA reportability.

Last updated . This page describes the current release.