Security Trust Center

OpenTrojan is an open cybersecurity intelligence platform. This page documents how we source, verify, and present security intelligence.

Data Sources

  • NVD (CVE) — Official CVE vulnerability data
  • CISA KEV — Known Exploited Vulnerabilities catalog
  • MITRE ATT&CK — Adversary tactics/techniques STIX data
  • Editorial Content — Human-reviewed security knowledge

Update Frequency

  • CVE / KEV / ATT&CK: synchronized daily via automated pipeline.
  • Editorial content: reviewed before publishing.

Editorial Policy

YMYL (Your Money or Your Life) safety domain: content is defense-oriented, educational, and cites sources. Offensive/weaponization content is excluded.

AI Usage Policy

AI assists research and drafting. AI-generated content is tagged (origin=ai_generated / ai_reviewed) and REQUIRES human review before publication. AI answers are citation-based and never present ungrounded claims as fact.

Review Process

Content flows through draft → review → published. Provenance metadata (source, reviewer, verifiedAt, confidence) is shown on pages for transparency.

Methodology

Evidence comes from authoritative sources (CISA > MITRE > NVD > vendor advisories) and is ranked accordingly. Confidence labels communicate verification level.