Privacy
whattopatch publishes data about software flaws, not about people. This page says what little personal data the site handles and why. Updated .
Who is responsible
The operator of https://whattopatch.com decides how the site's data is used and is responsible for it (the controller). Write to hello@whattopatch.com about anything on this page.
What the pages hold
The pages hold public data about vulnerabilities from CISA, FIRST, the CVE Program, CWE, Metasploit and Exploit-DB. We do not take the names of the people credited in CVE records or exploit catalogues into our pages.
When you visit this site
This site sets no cookies and runs no tracking or advertising scripts.
We count visits without your IP address or any identifier. For a sample of ordinary visits we note only which kind of page was asked for, the answer given and how long it took. For the crawlers of search engines, checked against their published addresses, we also note the page.
Cloudflare serves the site for us. To deliver pages and to block floods of requests, it handles your IP address and your request. We do not keep your IP address.
Email you send us
If you write to hello@whattopatch.com, we receive your address and what you write. We use it only to answer you and to make the change you asked for, and we keep it as long as that takes. Cloudflare forwards the mail to our mailbox.
Why we may use it
Our lawful basis is legitimate interests (article 6(1)(f) of the UK GDPR and of the GDPR): to run the site, keep it working and answer the people who write to us.
Your rights
You can ask us what we hold about you, to correct it, to delete it or to stop using it, by writing to hello@whattopatch.com. You can also complain to the data protection authority where you live.