← Back to VulnScope

Legal & Terms of Use

VulnScope — last updated 20 July 2026

Copyright © 2026 Yashesh D. Shah. All rights reserved.
VulnScope is proprietary software. It is not open source, and no licence to reuse its source code is granted by the fact that your browser downloads it.

1. What you may do

2. What you may not do

Without prior written permission:

3. What this copyright does and does not cover

The claim covers this particular expression: the source code, interface design, wording, the business-risk scoring model and its weightings, the curated vulnerability catalogue, and the framework crosswalk mappings.

It does not claim ownership of the public standards and data VulnScope builds on, which remain the work of their respective owners and are used here as published — CVE records (CVE Program / MITRE), NVD analysis and CPE data (NIST), the Known Exploited Vulnerabilities catalogue and the SSVC decision model (CISA, with Carnegie Mellon SEI), EPSS scores (FIRST.org), product lifecycle data (endoflife.date), the OWASP Top 10 (OWASP Foundation), PCI DSS (PCI SSC), and the HIPAA Security Rule (U.S. HHS).

Nothing here prevents anyone from independently building their own tool on those same public standards. Copyright protects an implementation, not an idea.

4. Your data

Asset inventories you upload are processed entirely in your browser. CSV or text you paste or upload is parsed, matched and scored locally in the page. It is not transmitted to the VulnScope backend and is not stored anywhere. Closing the tab discards it.

The backend proxy sees only what is needed to fetch public vulnerability data — CVE identifiers, product keywords and CPE strings — which it forwards to NVD, the CVE Program, FIRST.org and endoflife.date, caching responses briefly to stay within upstream rate limits. It does not receive your asset names, business-context selections, or any other inventory field.

No accounts, no advertising, no analytics or tracking cookies are set by VulnScope.

5. No warranty, and how to treat the output

VulnScope is provided “as is”, without warranty of any kind, express or implied. It is a decision-support aid: its scoring, SSVC decisions and compliance mappings are advisory and must not be relied upon as the sole basis for a security decision.

Some mappings are documented approximations rather than authoritative crosswalks. The CWE→OWASP and OWASP→PCI/HIPAA tables are best-fit; the business-risk weights are transparent hand-tuned heuristics, itemised in the interface so you can judge them; the SSVC decision table is CISA's published v1.0 reproduced verbatim, while the derivation of its four inputs is VulnScope's own automation. Upstream data may be incomplete — a CVE awaiting NVD analysis carries no CPE or CVSS data, which VulnScope labels rather than hides.

Always verify against the vendor advisory before acting.

6. Availability

VulnScope is offered free of charge with no service-level commitment. It may be changed, rate-limited or withdrawn at any time. Upstream sources impose their own rate limits, which can cause searches to fail temporarily.

7. Contact

Permission requests, licensing enquiries and infringement reports: yasheshdshah@gmail.com