Transparent derivation

Methodology

CASCA packages evidence for decisions while keeping source assertions, normalized restatements, deterministic derivations, curated analysis, and forward observations visibly distinct.

Priority is an evidence range, not a risk oracle.

The visible lower–upper interval reflects what eligible evidence supports and what remains unknown. It is not an exploitation prediction or a replacement for asset context.

Four bounded factors

  1. A · observed exploitation (0–40). Direct CISA KEV membership supports the factor. Non-membership is 0 / 0 / 40 unknown.
  2. B · dated FIRST EPSS (0–20). The exact probability, model, and score date stay attached.
  3. C · CVSS assessments (0–25). Distinct eligible assessments remain side by side by role, version, and origin; CASCA never averages CVSS.
  4. D · cited applicability reach (0–15). Accepted source-scope obligations and mappings drive the range. It is not recall over an unknowable product universe.

Time and replay

observed_at records when CASCA first registered an artifact; provider event time records what the source said; applicability validity is a separate interval. The active and immediately prior generation can be replayed exactly by as_known. Broader retrospective valid_at and 180-day reconstruction are deferred.

Changed-since cohorts

The default board includes forward evidence only and stops at 50 rows before pagination. Historical reconstruction, provider backfill, model transitions, mapping transitions, and curation transitions remain separately labeled so bootstrap work cannot masquerade as today’s change.

Conflicts and corrections

CASCA does not majority-vote sources or count derivative mirrors as corroboration. Conflicting eligible assertions remain visible. Corrections append a successor and preserve the earlier as-known state.