saascode

Kevreckon

A KEV-to-POA&M workbench for small defense-industrial-base contractors that joins authoritative vulnerability entries to authorized asset evidence, prioritization signals, contract and boundary context, reviewed control mappings, remediation ownership, retest evidence, and machine-readable export.

Genesis score6.92/10
Make Kevreckon real.0/500
500 more votes and Kevreckon is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
3Cross-references
6Inbound connections
0Direct connections
The case

Small defense contractors can consume the Known Exploited Vulnerabilities catalog yet still struggle to determine whether a listed product and version exists inside the assessed boundary, who owns it, which obligation applies, what compensating control exists, and how remediation evidence reaches a Plan of Action and Milestones. Kevreckon creates a candidate queue rather than an automatic compliance record. Catalog presence is not asset exposure, a software match is not exploitability, a prioritization score is not a contractual deadline, a generated control citation is not an accepted mapping, and a POA&M row is not remediation. Catalog entry, asset evidence, boundary, applicability, finding, owner, deadline authority, plan, change approval, deployment, retest, closure decision, assessor observation, and correction remain distinct.

Who pays — and why

A security, compliance, information-systems, operations, or managed-service leader at a small defense contractor preparing and maintaining evidence for an assessed environment.

What it unlocks
An assessed-boundary asset graph preserving legal entity, contract, enclave, system, component, product, version, software evidence, owner, criticality, exposure, last observed time, source coverage, exception, and correction
A vulnerability finding record linking authoritative catalog item, affected-product criteria, asset match confidence, exploit-prioritization signal, applicability review, false-positive reason, compensating control, risk owner, deadline source, and supersession
A POA&M lifecycle separating finding, reviewed control mapping, milestone, resource, dependency, target date, authority, change approval, deployment, provider acknowledgment, asset readback, retest, residual risk, closure approval, assessment evidence, and correction
How Genesis scored it
6.92across seven criteria
tension 7temporal 8blindspot 5buyer 7leverage 8convergence 5why-not 7
8
Temporal window

The KEV catalog updates continuously and the source identifies current assessment pressure, creating a recurring rather than one-time window.

8
Asymmetric leverage

Public feeds, reusable matching, control maps, and machine-readable export can serve many customers after each boundary and inventory is configured.

5
Convergence

Three cross-references and six inbound connections show repeated adjacency, but there are no direct connections and grounded convergence remains five.

Why it scored well

Three cross-references, six inbound links, free authoritative vulnerability and prioritization feeds, an active open asset source, and no identified low-cost hosted KEV-to-POA&M product with machine-readable export support a software-leveraged niche.

What's holding it back

There are no direct connections, the role-budget-current-alternative quartet is incomplete, asset inventories are often partial, product matching is noisy, deadline and control applicability are contractual and boundary-specific, assessor acceptance is unproven, and structural incumbent conflict is weak.

Signals detected5 sources crossed
SignalCISA KEV feed research

SignalOSV.dev service research

SignalFIRST EPSS API research

SignalFleet project research

SignalSource-run market scan

Direction briefkevreckon.md
kevreckon.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.