| CVE | CVSS | EPSS | KEV | Exploit | VEX | Description | Published |
|---|
| CVE | Vendor / product | Vulnerability | CVSS | EPSS | Added | Due | Ransomware |
|---|
| Rule | STIG ID | CAT | Finding | 800-53 | CCIs | Host |
|---|
| STIG | Version | Released | Category |
|---|
| Status | Source | Sector | Category | Items | Last OK | Last error | Actions |
|---|
We collect nothing about you. Prairie Watch has no accounts for visitors, no analytics, no trackers, and no advertising. Visiting and using the dashboard does not create any profile of you.
The only data recorded is the standard web-server access log that serving any website necessarily produces: your IP address, the time of the request, the URL requested, the response status, and your browser's user-agent string. This is inherent to delivering the page over the internet and is used solely to operate, troubleshoot, and secure the site. It is not combined with anything else, sold, or shared.
Your work stays in your browser. Your personal watchlist, your VEX determinations, any STIG checklists you import and the findings from them, and interface preferences such as theme and active tab are all stored only in this browser's local storage. None of it is transmitted to or stored on the server. Clearing your browser data removes it; exporting to a file (OpenVEX, a POA&M CSV, or a STIG POA&M) is the only way it leaves your machine, and only when you choose to. POA&M and VEX documents are generated in your browser, not on the server.
Cookies. No cookie is set unless you sign in as an administrator, in which case a single session cookie identifies that admin session and nothing more. It is removed when you log out.
On the server we store only public reference data: security feed metadata, CVE and CISA KEV records, exploit/PoC availability, the STIG catalog, and the CWE-to-800-53 and CCI-to-800-53 control mappings. None of it is about you. There is nothing personal to request, correct, or delete, because none is kept.