Empirical Security
Empirical Security builds data-driven models that predict which vulnerabilities will actually be exploited, so security teams can prioritize remediation by real-world risk instead of raw CVSS severity. It operates the Foundation (global) model, which combines real-time internet exploitation telemetry with EPSS and monitors 18,000+ exploited CVEs; hourly-updated EPSS models (epss_v3, epss_v4, epss_v5); and Radiant, an organization-specific model that layers your local assets, configurations and internal telemetry on top of the Foundation data. The read-only REST API exposes CVE detail, per-model scores and percentiles, malware hashes, critical indicators, score history, change history, full dataset export, search, and saved CVE groups, secured with OAuth 2.0 client credentials (JWT bearer). Empirical Security is backed by Costanoa Ventures.
Empirical Security publishes 1 API on the APIs.io network. Tagged areas include Company, Security, Cybersecurity, Vulnerability Management, and Vulnerability Prioritization.
Empirical Security’s developer surface includes documentation, API reference, getting-started guide, engineering blog, signup flow, authentication, and 17 more developer resources.
API Rating
APIs
Empirical Security API
Read-only REST API for real-time CVE exploitation-probability scores (Foundation/global and EPSS models), CVE detail, malware hashes, critical indicators, score history, search,...
MCP Servers
empirical-security-mcp.yml
MCP SERVERResources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Access & Security 3
Authentication, authorization, and security posture
Commercial 2
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API