NIST Stopped. So I Kept Going.
In April 2026 the US government quietly stopped doing a job most of the security industry didn't know it depended on. Here is what that broke, and why I built a record that can show its own past.
In April 2026, the US government quietly stopped doing a job most of the security industry didn’t know it depended on.
NIST stopped enriching every new entry in the National Vulnerability Database. The feed kept flowing. New CVE numbers kept arriving. Nothing broke loudly.
Things that break quietly are my least favorite kind.
What enrichment is, for people with lives
A raw CVE record is a number and one sentence. Buffer overflow in product X allows remote code execution. That is a smoke alarm going off somewhere in the city.
Enrichment tells you whether it is your building. Which products and versions are affected, how bad it is, what kind of flaw it is, whether anyone is actively exploiting it. For years the industry built its triage on NIST doing that for every record: scanners, dashboards, ticket rules, compliance reports. A whole industry resting on one shared dependency, most of which never wrote it down as a dependency.
When NIST stepped back, the alarms kept ringing. They just stopped telling you which building.
The architect’s twitch
I spent thirty years as an enterprise architect. The job mostly trains you to notice when a load-bearing wall has been labeled “decorative.”
This was that, at national scale. And the people standing closest to the wall were the analyst on call, the vulnerability manager, and whoever has to sign the remediation report. The ones who would feel it first and could fix it least.
So I started building.
What I built
VCIY takes the public record, the CVE list, CISA’s Known Exploited Vulnerabilities catalog and FIRST’s exploit prediction scores, and gives every vulnerability its own page. Useful, and not unique. Other people do versions of that.
The part I care about is one line at the top of every page:
No source can show you its own past. This one can.
Most vulnerability sources overwrite themselves. When an assessment changes, the old one is gone. Which is fine right up until someone asks the one question that always arrives eventually, usually from an auditor, sometimes from a lawyer, occasionally from a boss who has just read something alarming: What did we know on March 3, and why did we decide what we decided?
Most tools answer that with a shrug and a screenshot somebody hopefully took.
VCIY keeps two clocks for every fact: when it became true in the world, and when the record learned it. Ask about March 3 and you get March 3. Nothing from after that date can leak in. Print the page and you keep the view exactly as it stood that day, which is a sentence I never expected to be proud of.
Then I trained a model on it
Once the record existed, I trained a model on it. A sovereign one, meaning it runs entirely on the customer’s own hardware with no connection out. The list of what a company runs is the most sensitive thing a security team holds, and I did not want anyone to have to mail it to a stranger’s data center to get an answer. Even a friendly one.
Then I tested it against the best general models available, on vulnerabilities published after their training ended.
Ours scored 90.86. Claude Opus 5 scored 0.0. Gemini scored 0.2.
Not lower. Zero. They cannot know what happened after they stopped reading. Nobody could. That is rather the point. The full numbers and why it happens are on the Voxell blog: The Frontier Models Score Zero.
Why I am telling you
Because I built it alone, and the honest truth about building something alone is that the code is the easy part. The hard part is getting anyone to look.
So here is the ask, with all the subtlety of a solo founder. Go to vciy.com and open a CVE you already know. Log4Shell is a good one; everyone has a Log4Shell story and most of them are not happy. Read the page as if your job depended on it, because for some people it does. Then tell me what is missing, what is wrong, or what would make you come back.
Every score is published at app.vciy.com/validation. Check my work. I would.
Jonathan Corners · Founder, Voxell, Inc. vciy.com · voxell.ai