About cvechain
cvechain explains how a vulnerability travels from a CVE identifier to a CVSS score, an EPSS probability and the CISA KEV catalog – and how to use those signals to decide what to patch first. This page says who is behind that advice.
Who publishes this site
cvechain is published by SEQ SIA (registration No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq. OffSeq is an offensive-security company doing penetration testing, security assessments and continuous threat monitoring. Contact: support@offseq.com.
This is a vendor-run resource. It is not a government, standards body or independent publication, and it does not present itself as one.
Who writes the content
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles are published under the OffSeq security team rather than individual bylines, and the operator named above answers for every one of them. Sources are listed so readers can check the basis for the guidance.
How the content is made
- Every scoring and cataloguing claim is traced to the body that defines it – FIRST for CVSS and EPSS, MITRE for CVE, CISA for KEV – and the sources are listed at the end of each article.
- Figures we cannot trace to a primary source are not published, even when they are widely repeated.
- We describe how to prioritise vulnerabilities. We do not publish exploit code or steps that make exploitation easier.
- The “Updated” date moves only when the text actually changes; an automated content-hash ledger reverts unearned date bumps.
- Everything is readable without an account, a cookie banner or an email address.
Conflict of interest, stated plainly
The company that publishes this site sells vulnerability monitoring and penetration testing. That is a direct commercial interest in you concluding that vulnerability management is hard, and you should read every recommendation here with that in mind.
- Links to OffSeq products and services are our own links, not an independent recommendation.
- No vendor pays to be mentioned here. There is no sponsored content, no advertising and no affiliate links.
- The core workflow this site teaches – CVE plus KEV plus EPSS plus your own exposure – can be run entirely with free public data, and we say so.
What this site is not
This is not a vulnerability feed, not a scanner and not a substitute for your own asset inventory. Prioritisation guidance is generic; the exposure that matters is specific to your environment.
Corrections
If something here is wrong or out of date, write to support@offseq.com. We correct substantive errors and move the update date visibly rather than quietly.