01 One card per vulnerability
Every card describes a single publicly known vulnerability — a CVE —
in the same shape: what the flaw is, how severe it is, whether it is
exploited in the wild, what an attacker needs, and the one action to take.
The shape is the Common Risk Definition Set (CRDS), an open JSON schema.
02 Built from public, authoritative feeds
The facts on a card come from the sources security teams already trust:
the NIST National Vulnerability Database (NVD) for scores and weakness
classes, the CISA Known Exploited Vulnerabilities (KEV) catalog for
in-the-wild exploitation, and FIRST's Exploit Prediction Scoring System
(EPSS) for exploitation probability. Every card cites its sources.
03 Written by a pipeline, reviewed by a person
An automated pipeline fetches the feeds, fills in the looked-up fields,
and drafts the plain-language text. A validator rejects anything that
contradicts its sources. A human reviews the judgement calls — severity,
the attack technique, the recommended action — before a card is published.
Cards are revised, never deleted.
04 A reference, not a service
This site is static files. There are no accounts, no cookies, no
analytics and no tracking. The cards are published under the Creative
Commons Attribution 4.0 (CC BY 4.0) licence, and the data, the schema and
the code that builds the site live in a public repository on GitHub. Use
the cards in your own tooling, or build a deck for your software from an
SBOM in the Deck Builder — in your browser, without uploading anything.
Who runs this
SCRTY is a product of Kaiari Labs, an independent research
practice founded by Rachid El Khayari. Kaiari Labs works at the intersection
of software engineering, cyber security and AI-assisted development; its
background in security research — including mobile security work at the
Fraunhofer Institute for Secure Information Technology — is where the idea
of a card came from: the facts about a risk, in a shape you can hold.
Read more about the practice at
kaiari.com/about,
or visit kaiari.com.
Contact
Questions, corrections and collaboration proposals:
hello@kaiari.com. Found an error on a
card? Every card links to its sources, and the data lives in a public
repository — an issue or pull request at
github.com/scrty-projects/crds
is the fastest route to a corrected reprint.
Licence
The cards — the JSON behind every page here — are published under the
Creative Commons Attribution 4.0 International
licence (CC BY 4.0). You may copy, redistribute and build on them for any
purpose, including commercially, as long as you credit SCRTY:CRDS and link
to the licence. The facts on a card come from public sources with terms of
their own, recorded in each card's provenance; the licence covers the card
as an editorial work — the selection, the plain-language text, the
classification and the recommended action.
Sources and trademarks
CVE is a registered trademark of The MITRE Corporation; the CVE records
themselves are published by the CVE Program. NVD data is provided by the
U.S. National Institute of Standards and Technology. The KEV catalog is
published by the U.S. Cybersecurity and Infrastructure Security Agency.
EPSS scores are provided by the Forum of Incident Response and Security
Teams (FIRST). ATT&CK is a registered trademark of The MITRE Corporation.
SCRTY:CRDS is not affiliated with or endorsed by any of these
organizations; it cites them.