For the people with authority to act.
Securities regulators, privacy commissioners, financial supervisory authorities, and law enforcement agencies receive unrestricted access to the silent patch intelligence feed. No charge. No commercial gating.
Market transparency should not be gated from the people responsible for it.
The data exists. The authority to act on it exists. The only thing missing is the connection between them.
Whitenbaker’s silent patch intelligence feed catalogs vulnerabilities that vendors fixed without public disclosure – fixes that should have triggered material risk disclosures, breach notifications, or downstream operator warnings, and did not. We commercialize this data to commercial subscribers because the work requires funding. We do not commercialize it to the regulators whose statutory mandates the underlying conduct implicates.
If your office has the authority to compel disclosure, impose fines, conduct enforcement, or initiate investigations against entities whose silent patching conceals material risk from market participants, your credentialed access is already paid for. The funding model is intentional: the entities that benefit from concealment underwrite the cost of exposing it.
Who qualifies.
Credentialed access is restricted to verified supervisory authorities with statutory or regulatory mandates implicated by undisclosed software vulnerabilities. Three broad categories cover the typical mandate.
Financial Markets Supervision
Authorities whose mandate covers public company disclosure obligations, material risk reporting, market manipulation, or fraud against investors when undisclosed software vulnerabilities affect publicly traded entities or instruments.
- Securities and exchange commissions
- Financial markets regulators
- Commodity futures supervisory bodies
- Capital markets enforcement divisions
- Self-regulatory organizations (with authority)
Data Protection Authorities
Privacy commissioners and data protection regulators whose mandate covers statutory breach notification, personal data exposure, or the duty of care owed by data controllers and processors when silent patching affects systems handling personal information.
- Privacy commissioners (national, provincial, state)
- Data protection authorities
- Information commissioners
- Consumer protection agencies (privacy mandate)
- Cross-border data flow regulators
Critical Infrastructure & Investigations
National cybersecurity agencies, sector regulators, and law enforcement agencies with active investigations involving software vulnerabilities, exploit incidents, or operators whose patch concealment timelines bear on the elements of an offense.
- National cybersecurity centers
- Critical infrastructure protection agencies
- Sector-specific cyber regulators
- Law enforcement investigative units
- Prosecutorial offices with cyber mandate
The full record.
Public-facing entries on the taxonomy page are redacted to protect ongoing investigations and downstream users still exposed. Credentialed access removes the redactions and adds investigative tooling.
Full record.
Every embargoed entry in the public taxonomy with vendor names, exploit timelines, and disclosure decisions restored. Search, filter, and export the complete dataset. Live updates as new findings are detected.
Downstream impact.
Per-finding maps identifying every affected operator, fork, or dependent system. Includes user counts, market capitalization exposure, jurisdiction of incorporation, and observed exploit attempts where applicable.
Chain-of-custody records.
Commit-level evidence preserved with timestamps, hash verification, and detection methodology for findings cited in enforcement proceedings. Reproducible by your own technical staff.
Technical liaison.
Direct access to the research team for clarifying questions, supplementary analysis on specific findings, and where appropriate, expert testimony in enforcement proceedings or congressional inquiries.
From request to credentials.
The intake is designed to verify authority, not to gate it. Most credentialed requests complete in under five business days.
Initial Request
Email from an official domain stating the requesting authority, your role, and the general scope of interest. No specific findings need to be named at this stage.
Authority Verification
Letter of authority on official letterhead confirming your office’s jurisdiction and your designation to receive sensitive research material. Standard for inter-agency cooperation.
Credentials Issued
Secure credentialed access provisioned. Initial briefing scheduled if the requesting body would benefit from an overview of the research methodology before reviewing findings.
Ongoing Liaison
Direct point of contact for follow-up questions, supplementary filings, or expert consultation on specific findings as your investigations develop.
Questions we anticipate.
Why is access free for regulators when commercial subscribers pay?
+The funding model is intentional. Commercial subscribers – auditors, underwriters, protocol maintainers – pay us to use silent patch intelligence in their own work. Regulators and law enforcement agencies need the same data to perform statutory duties that those commercial entities benefit from. Charging the people whose mandate covers the underlying conduct would create the wrong incentive structure.
Put plainly: commercial subscribers underwrite the work that enables regulators to act. Charging regulators on top of that would mean charging twice for the same outcome.
What’s the verification process actually like?
+A letter of authority on official letterhead from the requesting agency, signed by someone with appropriate signing authority, confirming that the named individual is designated to receive sensitive third-party research material on behalf of the agency. We do not run our own background checks – the verification is that the agency confirms you.
This is the standard documentation used for inter-agency cooperation and third-party intelligence sharing. Most agencies have an existing template.
Can findings be shared with other agencies once received?
+Yes, within your agency’s existing inter-agency cooperation framework. Whitenbaker findings are not classified material and carry no clearance requirement. They are private research with embargo conditions in place to protect ongoing investigations and downstream users still exposed to the underlying vulnerability.
If your matter involves multiple agencies, we can extend credentials to coordinating offices without restarting the verification process.
Will Whitenbaker testify in enforcement proceedings?
+Yes. The research methodology is designed for evidentiary use – every finding has commit-level chain-of-custody documentation, hash verification of the underlying code states, and reproducible detection logic. Expert testimony on the methodology, the specific finding, or the downstream impact analysis is available on request.
Testimony scheduling is coordinated through the requesting agency. No retainer is charged.
Are findings shared with other regulators before our request?
+Where a finding clearly implicates a specific jurisdiction’s mandate and no investigation is known to be underway, we may route the finding to the relevant supervisory body proactively. This is the same disclosure model used for coordinated vulnerability disclosure to vendors – it’s how the research becomes actionable.
If your agency would prefer to receive findings in your jurisdiction proactively rather than reactively, that arrangement can be made standing.
How does this differ from commercial threat intelligence feeds?
+Commercial threat intelligence catalogs disclosed vulnerabilities – CVEs, public advisories, known exploits. The data is downstream of the vendor’s decision to disclose.
Whitenbaker catalogs the opposite: security patches that were applied without disclosure. By definition, none of these appear in commercial threat feeds. The disclosure rate measured across the ecosystems we monitor is 0.44%. Commercial feeds see less than half a percent of the actual vulnerability surface.
The two are complementary, not competing. Commercial feeds cover what’s been disclosed. We cover what hasn’t.
If you have the authority, we have the evidence.
Email from an official domain. Letter of authority. Credentials in five days.
