Security Trust Center
OpenTrojan is an open cybersecurity intelligence platform. This page documents how we source, verify, and present security intelligence.
Data Sources
- NVD (CVE) — Official CVE vulnerability data
- CISA KEV — Known Exploited Vulnerabilities catalog
- MITRE ATT&CK — Adversary tactics/techniques STIX data
- Editorial Content — Human-reviewed security knowledge
Update Frequency
- CVE / KEV / ATT&CK: synchronized daily via automated pipeline.
- Editorial content: reviewed before publishing.
Editorial Policy
YMYL (Your Money or Your Life) safety domain: content is defense-oriented, educational, and cites sources. Offensive/weaponization content is excluded.
AI Usage Policy
AI assists research and drafting. AI-generated content is tagged (origin=ai_generated / ai_reviewed) and REQUIRES human review before publication. AI answers are citation-based and never present ungrounded claims as fact.
Review Process
Content flows through draft → review → published. Provenance metadata (source, reviewer, verifiedAt, confidence) is shown on pages for transparency.
Methodology
Evidence comes from authoritative sources (CISA > MITRE > NVD > vendor advisories) and is ranked accordingly. Confidence labels communicate verification level.