Credentialed Access · Supervisory Bodies Only

For the people with authority to act.

Securities regulators, privacy commissioners, financial supervisory authorities, and law enforcement agencies receive unrestricted access to the silent patch intelligence feed. No charge. No commercial gating.

WBL · Regulator Access Open Intake
EligibilityVerified Supervisory Bodies
CostComplimentary
VettingLetter of authority required
Turnaround5 business days
Data ScopeFull unredacted feed
RenewableAnnual review
TestimonyAvailable on request
Restricted access. Credentials issued only to verified supervisory authorities.

Market transparency should not be gated from the people responsible for it.

Operating Principle, Whitenbaker Labs
Operational Telemetry · Whitenbaker Labs
Year to date · Updated monthly
Patches Detected
4,121
Across 9 ecosystems
Cumulative YTD +12 this week
Currently Undisclosed
4,103
No CVE · No advisory · No notification
0.44% disclosure rate 99.56% gap
CVEs Filed by Whitenbaker
162
MITRE filings · Cumulative
Embargoed pending Updated monthly
Capital At Risk
$7.16B
Public market cap · Affected infrastructure
Quarterly assessment Last review Q4

The data exists. The authority to act on it exists. The only thing missing is the connection between them.

Whitenbaker’s silent patch intelligence feed catalogs vulnerabilities that vendors fixed without public disclosure – fixes that should have triggered material risk disclosures, breach notifications, or downstream operator warnings, and did not. We commercialize this data to commercial subscribers because the work requires funding. We do not commercialize it to the regulators whose statutory mandates the underlying conduct implicates.

If your office has the authority to compel disclosure, impose fines, conduct enforcement, or initiate investigations against entities whose silent patching conceals material risk from market participants, your credentialed access is already paid for. The funding model is intentional: the entities that benefit from concealment underwrite the cost of exposing it.

Eligible Bodies · Three Categories

Who qualifies.

Credentialed access is restricted to verified supervisory authorities with statutory or regulatory mandates implicated by undisclosed software vulnerabilities. Three broad categories cover the typical mandate.

Category I · Securities

Financial Markets Supervision

Material risk · Disclosure failure · Investor protection

Authorities whose mandate covers public company disclosure obligations, material risk reporting, market manipulation, or fraud against investors when undisclosed software vulnerabilities affect publicly traded entities or instruments.

  • Securities and exchange commissions
  • Financial markets regulators
  • Commodity futures supervisory bodies
  • Capital markets enforcement divisions
  • Self-regulatory organizations (with authority)
Category II · Data & Privacy

Data Protection Authorities

Privacy · Breach notification · Personal data exposure

Privacy commissioners and data protection regulators whose mandate covers statutory breach notification, personal data exposure, or the duty of care owed by data controllers and processors when silent patching affects systems handling personal information.

  • Privacy commissioners (national, provincial, state)
  • Data protection authorities
  • Information commissioners
  • Consumer protection agencies (privacy mandate)
  • Cross-border data flow regulators
Category III · Cyber & Law Enforcement

Critical Infrastructure & Investigations

Critical infrastructure · Active investigations · Evidentiary support

National cybersecurity agencies, sector regulators, and law enforcement agencies with active investigations involving software vulnerabilities, exploit incidents, or operators whose patch concealment timelines bear on the elements of an offense.

  • National cybersecurity centers
  • Critical infrastructure protection agencies
  • Sector-specific cyber regulators
  • Law enforcement investigative units
  • Prosecutorial offices with cyber mandate
What Credentials Unlock

The full record.

Public-facing entries on the taxonomy page are redacted to protect ongoing investigations and downstream users still exposed. Credentialed access removes the redactions and adds investigative tooling.

Access I · Unredacted Database

Full record.

Every embargoed entry in the public taxonomy with vendor names, exploit timelines, and disclosure decisions restored. Search, filter, and export the complete dataset. Live updates as new findings are detected.

37 public · 100+ embargoed · Live feed
Access II · Exposure Maps

Downstream impact.

Per-finding maps identifying every affected operator, fork, or dependent system. Includes user counts, market capitalization exposure, jurisdiction of incorporation, and observed exploit attempts where applicable.

50+ networks · Cross-jurisdictional
Access III · Evidentiary Documentation

Chain-of-custody records.

Commit-level evidence preserved with timestamps, hash verification, and detection methodology for findings cited in enforcement proceedings. Reproducible by your own technical staff.

Court-admissible · Reproducible
Access IV · Expert Consultation

Technical liaison.

Direct access to the research team for clarifying questions, supplementary analysis on specific findings, and where appropriate, expert testimony in enforcement proceedings or congressional inquiries.

By appointment · No retainer
The Intake Process

From request to credentials.

The intake is designed to verify authority, not to gate it. Most credentialed requests complete in under five business days.

01

Initial Request

Email from an official domain stating the requesting authority, your role, and the general scope of interest. No specific findings need to be named at this stage.

02

Authority Verification

Letter of authority on official letterhead confirming your office’s jurisdiction and your designation to receive sensitive research material. Standard for inter-agency cooperation.

03

Credentials Issued

Secure credentialed access provisioned. Initial briefing scheduled if the requesting body would benefit from an overview of the research methodology before reviewing findings.

04

Ongoing Liaison

Direct point of contact for follow-up questions, supplementary filings, or expert consultation on specific findings as your investigations develop.

Frequently Asked

Questions we anticipate.

Why is access free for regulators when commercial subscribers pay?

+

The funding model is intentional. Commercial subscribers – auditors, underwriters, protocol maintainers – pay us to use silent patch intelligence in their own work. Regulators and law enforcement agencies need the same data to perform statutory duties that those commercial entities benefit from. Charging the people whose mandate covers the underlying conduct would create the wrong incentive structure.

Put plainly: commercial subscribers underwrite the work that enables regulators to act. Charging regulators on top of that would mean charging twice for the same outcome.

What’s the verification process actually like?

+

A letter of authority on official letterhead from the requesting agency, signed by someone with appropriate signing authority, confirming that the named individual is designated to receive sensitive third-party research material on behalf of the agency. We do not run our own background checks – the verification is that the agency confirms you.

This is the standard documentation used for inter-agency cooperation and third-party intelligence sharing. Most agencies have an existing template.

Can findings be shared with other agencies once received?

+

Yes, within your agency’s existing inter-agency cooperation framework. Whitenbaker findings are not classified material and carry no clearance requirement. They are private research with embargo conditions in place to protect ongoing investigations and downstream users still exposed to the underlying vulnerability.

If your matter involves multiple agencies, we can extend credentials to coordinating offices without restarting the verification process.

Will Whitenbaker testify in enforcement proceedings?

+

Yes. The research methodology is designed for evidentiary use – every finding has commit-level chain-of-custody documentation, hash verification of the underlying code states, and reproducible detection logic. Expert testimony on the methodology, the specific finding, or the downstream impact analysis is available on request.

Testimony scheduling is coordinated through the requesting agency. No retainer is charged.

Are findings shared with other regulators before our request?

+

Where a finding clearly implicates a specific jurisdiction’s mandate and no investigation is known to be underway, we may route the finding to the relevant supervisory body proactively. This is the same disclosure model used for coordinated vulnerability disclosure to vendors – it’s how the research becomes actionable.

If your agency would prefer to receive findings in your jurisdiction proactively rather than reactively, that arrangement can be made standing.

How does this differ from commercial threat intelligence feeds?

+

Commercial threat intelligence catalogs disclosed vulnerabilities – CVEs, public advisories, known exploits. The data is downstream of the vendor’s decision to disclose.

Whitenbaker catalogs the opposite: security patches that were applied without disclosure. By definition, none of these appear in commercial threat feeds. The disclosure rate measured across the ecosystems we monitor is 0.44%. Commercial feeds see less than half a percent of the actual vulnerability surface.

The two are complementary, not competing. Commercial feeds cover what’s been disclosed. We cover what hasn’t.

Begin Intake

If you have the authority, we have the evidence.

Email from an official domain. Letter of authority. Credentials in five days.

drew@whitenbaker.com