Terms and professional disclaimer

Terms and Disclaimer

This page explains the intended use, limitations and responsibility boundaries for the RiskRank. It is written for security teams, business owners, auditors and technical stakeholders who need clear expectations before using the output in remediation or risk discussions.

These terms reflect the current operational scope of RiskRank. They should be reviewed by qualified legal counsel before any significant changes to data handling, paid features, user accounts or advertising are introduced.

Prioritization aid

The tool supports vulnerability triage and remediation planning. It does not replace expert review, formal risk ownership or vendor guidance.

Source-aware, not source-perfect

Public intelligence sources can be delayed, incomplete or temporarily unavailable. Results must be validated before operational action.

No blind automation

The Business Risk Score should support decisions, not automatically approve, delay or execute remediation work.

Detailed terms and limitations

Last updated: 2026-06-26

1. Purpose of the tool

RiskRank is designed to help security teams, IT operations, risk owners and business stakeholders translate vulnerability intelligence into business-aware remediation priority. The tool combines technical severity with contextual inputs such as exposure, asset importance, data sensitivity, exploit likelihood, CISA KEV status, remediation complexity and compensating controls.

2. Prioritization aid only

The output is intended to support vulnerability management conversations, remediation planning, CAB/change discussions, management reporting and risk acceptance workflows. It should be treated as supporting evidence, not as the sole authority for accepting risk, delaying remediation, executing emergency changes or declaring a vulnerability non-impacting.

3. Not an official CVSS replacement

CVSS remains the technical severity baseline. The Business Risk Score is a contextual prioritization model that adds business and threat context on top of source metrics. A change in business context can change the Business Risk Score, but it does not modify the original CVSS score, CVSS vector, NVD data, EPSS probability or CISA KEV status.

4. Source data limitations

The tool may use public vulnerability intelligence sources such as NVD, FIRST EPSS and CISA KEV. These sources may be delayed, revised, incomplete, unavailable or interpreted differently by vendors and scanners. Users should validate findings against vendor advisories, scanner evidence, asset inventory, change records and internal threat intelligence before taking operational decisions.

5. Affected product hints

Affected product information is treated as source-derived intelligence, usually based on public vulnerability data and CPE-style configuration hints. These hints do not prove that a user's environment contains the product or vulnerable version. Applicability must be confirmed through asset inventory, software discovery, configuration evidence, scanner results or owner validation.

6. Remediation and mitigation disclaimer

The tool may recommend remediation urgency, compensating-control options and validation steps. These recommendations are general prioritization guidance. Exact remediation steps must be validated through official vendor documentation, security advisories, internal change processes and compatibility testing. Users are responsible for assessing outage risk, rollback plans, dependencies and business approval before applying changes.

7. No vulnerability scanner replacement

The tool does not perform authenticated scanning, exploit validation, asset discovery, software inventory or configuration assessment. It does not prove whether a vulnerability exists in a specific environment. It is designed to prioritize and explain findings after CVE intelligence, scanner evidence or manual validation is available.

8. No incident response guarantee

A high Business Risk Score, KEV listing or high EPSS value may indicate urgency, but this tool does not determine whether an environment is compromised. If exploitation is suspected, users should follow their incident response process, preserve evidence, review logs, isolate affected systems where appropriate and engage qualified responders.

9. User responsibility

Users are responsible for the accuracy of business-context inputs such as asset exposure, criticality, data sensitivity, authentication requirements, patch complexity and compensating controls. Incorrect inputs can produce misleading prioritization. When in doubt, users should document assumptions and validate them with asset owners, system administrators and security engineers.

10. Session-only report behavior

Reports are session-only in the current version and are not stored as user records in the application database. Users should download or print the current report before generating a new one, refreshing the page or closing the browser session. No account registration is required to use the tool.

11. Data handling

The tool caches public CVE intelligence from NVD, FIRST EPSS and CISA KEV for performance. This cache contains public vulnerability identifiers and scores, not private user reports or sensitive business data. Users should not enter passwords, secrets, private keys, confidential incident details or personally identifiable information into any input field.

12. No warranty

The tool is provided as-is and without warranty of any kind, express or implied. No guarantee is made that results are complete, error-free, suitable for every environment or sufficient for compliance, insurance, audit, legal, regulatory or contractual obligations. Users should apply professional judgement and independent validation before taking action based on results.

13. Governing law

These terms are provided as a plain-language statement of intended use and limitation. They do not constitute a formal legal agreement and should be reviewed by qualified legal counsel before any commercial deployment, paid-tier launch or material change to the application's data handling or audience.

14. Contact

For questions about these terms, data handling or use of RiskRank, contact: igorberner89@gmail.com.

Recommended use

Use the report to structure remediation conversations, document why a vulnerability is urgent, explain risk to business owners and preserve decision context for CAB meetings, audit evidence and vulnerability management reviews.

Do not use it as

Do not use the score as the only basis for accepting risk, proving exploitability, confirming asset exposure, bypassing change control, ignoring vendor guidance or replacing incident response, scanner validation or professional engineering judgement.

Data handling boundary

RiskRank caches public CVE intelligence from NVD, EPSS and CISA KEV for performance. Generated reports remain session-only and are not stored as user records. Users should not enter secrets, passwords, private keys, confidential incident details or sensitive internal architecture information into any input field.

Plain-language summary

This tool helps answer: "What should we fix first and why?" It does not answer every security, legal, compliance or operational question by itself. Use it as a structured, transparent decision-support layer and validate the final decision through your normal security and business process.