Skip to content
Products

Empirical Security is building the first domain and enterprise specific models in cybersecurity.

Not all security programs look alike — we’ve seen hundreds and are ready to meet you where you are.

Features

Enterprise EPSS

Global

Local

Predictive Vulnerability Scoring

Hourly Score Updates & Enterprise Support

Legacy Model Support (EPSS v3, v4)

UI and API for Data Discovery & Model Performance

Data on over 16,000 exploited in the wild CVEs

Near-Real Time Exploitation Telemetry & Model

ML model for discovering new exploit code on GitHub

All Underlying data contributing to the model exposed

Custom Vulnerability Model based on your enterprise data (Attack telemetry, asset data, vuln data, threat intelligence)

Model Performance Measured against your attack telemetry

Our public model, EPSS, can augment a security program with any budget and we’re here to help. Our global model is the highest efficiency prioritization model ever built in security, and it exposes all the data underneath so you can have confidence in your decisions. If you’re a large enterprise struggling with unique threats or datasets, we’re ready to build your own custom model as well.

  • 01EPSS Models

    Empirical Security builds and maintains the world’s only public machine learning model in cybersecurity, EPSS. We offer enterprise support, hourly updates, and legacy version support as a service.

  • 02Global Models

    Our global models leverage datasets we buy, curate, and data mine with machine learning to build sophisticated solutions that are constantly updated and refined. Stop spending time cleaning data and get to efficient decisions.

    Our global model includes access to data on over 16,000 known exploited in the wild CVEs, and uses that data in the model. This is 12x DHS CISA’s KEV, and far more than any other vendor out there.

    The global model’s current Area Under the Curve (AUC) is over .87. This ensures the best precision and coverage in the industry.

  • 03Local Models

    Your enterprise has environmental and telemetry data that should be used in decision making. Empirical Security unlocks the value of these datasets by training a local model, specific to you and only accessible by you, to support your enterprise’s decision making.

    Traditional Measures of Vulnerability Management miss the boat when they don’t include all the data you have at your disposal, and even our global model shows absolute, not residual risk. Depending on your compensating controls, data about your attack telemetry, assets, vulns, and threat intel, the best model for you can be different and should include all the data you have at your disposal.