FAQ
Is RPS a replacement for CVSS?
No. CVSS measures potential severity. RPS combines severity with exploitation likelihood, confirmed exploitation, public exploit evidence, and patch signals to help rank remediation work.
Does DevSecure decide my SLA?
No. DevSecure is SLA-neutral and policy-neutral. Use priority_band, sla_guidance, and recommended_next_step as inputs to your internal policy.
Can I use the API without a key?
Yes, public endpoints such as KEV, status, stats, and trends do not need a key. Authenticated enrichment and prioritization endpoints require a bearer key.
Where are full schemas?
All endpoint schemas, examples, code samples, and try-it controls live in the API Reference.
Why is a CVE missing?
A CVE may exist upstream before it enters the DevSecure corpus. Use the source_record_url field from not-found responses to inspect upstream records.