Security teams are buried in CVE alerts, and most of them don't apply to what they actually run. StackWatch takes a target, maps its attack surface and software stack, and tells you which advisories really affect you, with proof.
You give it a repo, a deployment or a domain. It runs recon (DNS, certificate transparency, RDAP, TLS), finds dependencies and live endpoints, and matches them against OSV advisories. Then it checks each match: Semgrep looks for the vulnerable code pattern in source, and runtime probes test the live app. Every finding gets a status (verified, present, inconclusive or not present). Risk is scored as severity times proof, so a verified high ranks above an unconfirmed critical, and an exposure graph moves internet-facing issues to the top. An authorization gate keeps it scanning only targets you're allowed to touch.
Built with FastAPI and asyncio, OSV, Semgrep, a Ministral research agent for plain-English explanations, ClickHouse and SQLite, and a Senso.ai knowledgebase integration.