OurCVEs
Register
How it works

Security posture for teams without a security team.

If you ship software at a small company or an agency, "security" and "DevOps" are probably hats you put on between features — not a team down the hall. Nobody hired you to read CVE feeds, chase Dependabot PRs, or wonder whether that staging box is three Ubuntu versions out of date.

OurCVEs is built to carry that weight for you. The whole product is three moves working together:

01

We see every repo and server you run.

You can't secure what you can't see — so the first job is a complete, always-current picture of your stack.

  • Install the GitHub App on the repositories you ship from. We read your lockfiles — composer.lock, package-lock.json, pnpm-lock.yaml, yarn.lock — so we know the exact versions you actually run.
  • Install the read-only sensor on your servers. It reports the OS packages your machine already knows about, whether a reboot is pending, and whether unattended upgrades are even on.
  • From then on, "what are we running?" has a real answer instead of a guess.
02

The routine handles itself.

Hundreds of CVEs are published every week. The vast majority that touch you are routine: a patch exists, and applying it is safe and mechanical. Those should not cost you an afternoon.

  • We match every advisory feed against your actual inventory, so you only ever look at vulnerabilities that affect something you really run.
  • The durable automation is native and deterministic — Dependabot auto-merge gated by your own CI on your repos, and unattended OS patching tuned to the downtime you can tolerate on your servers.
  • Your coding agent, connected through our MCP server, does the one-time work of switching that automation on safely — repo by repo, server by server. From then on it runs without anyone in the loop, including us.
  • We never reach into your servers and change them ourselves. The sensor is read-only; what actually ships stays under your control.
03

A human steps in only when it matters.

The dangerous cases aren't the routine ones — they're the critical CVE with no fix yet, the server drifting toward end-of-life, the reboot that's been pending for six weeks. Those need judgment.

  • You declare your posture once — your downtime tolerance, your maintenance window, your auto-merge policy — and we watch for drift away from it.
  • When something genuinely needs a person, we pull you in with the context already assembled, instead of burying it in a feed of noise.
  • Want the whole thing off your plate? Our managed service runs it for you — the people behind the agent do the work.
What setup honestly looks like

We'll be straight with you: getting fully set up is not a 30-second affair. You connect a GitHub App, install a sensor on each server, and tell us how your team likes to operate. Most teams are seeing their first real findings within an afternoon, and fully dialed in within a week.

We don't think that's a reason to wait. The work is finite and front-loaded — once it's running, the point of OurCVEs is that you go back to shipping and let it watch your back.

Two shortcuts make it easier: you can onboard without leaving your AI agent, or you can hand the whole thing to us.