# Empirical Security

**Canonical:** https://apis.io/providers/empirical-security/  
**Website:** https://www.empiricalsecurity.com  
**APIs profiled:** 1

Empirical Security builds data-driven models that predict which vulnerabilities will actually be exploited, so security teams can prioritize remediation by real-world risk instead of raw CVSS severity. It operates the Foundation (global) model, which combines real-time internet exploitation telemetry with EPSS and monitors 18,000+ exploited CVEs; hourly-updated EPSS models (epss_v3, epss_v4, epss_v5); and Radiant, an organization-specific model that layers your local assets, configurations and internal telemetry on top of the Foundation data. The read-only REST API exposes CVE detail, per-model scores and percentiles, malware hashes, critical indicators, score history, change history, full dataset export, search, and saved CVE groups, secured with OAuth 2.0 client credentials (JWT bearer). Empirical Security is backed by Costanoa Ventures.

## Kin Score — 29.4 / 100 (thin)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (-0.6 from 30.0).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 14.5 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 0.0 |
| Developer Ergonomics | 54.2 |
| Commercial Clarity | 34.2 |
| Access Clarity | 34.2 |

## Agent readiness — 34.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | na |
| MCP Server | no |
| Auth Clarity | served |
| Idempotency | na |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | na |
| Delegated Identity | served |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (3)

- **Empirical Security CVE Groups API** — Saved CVE queries and their execution.
- **Empirical Security CVEs API** — Retrieve CVE detail, scores, malware hashes and history.
- **Empirical Security Search API** — Query CVEs using Empirical search syntax.

## MCP servers (1)

- **Empirical Security MCP Server**

## Agentic access (1)

- **Empirical Security Agentic Access** — 9 operations

## Security (2)

- **Empirical Security Authentication** — oauth2 · 1 scheme
- **Empirical Security Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Security, Cybersecurity, Vulnerability Management, Vulnerability Prioritization, CVE, EPSS, Exploit Prediction, Threat Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/empirical-security/). Scores are computed from the provider's own public artifacts under a published rubric.
