For CIOs, CTOs, and cyber-aware founders

Know when a zero-day hits your stack — not the internet’s.

Add the SaaS tools that hold your data. ZeroDayTracker watches those vendors, and the suppliers behind them, as AI-speed exploits shrink the time you have to respond.

criticaldirectPalo Alto NetworksCVE-2024-3400

Palo Alto Networks PAN-OS command injection

Unauthenticated attackers can execute code with root privileges on GlobalProtect. This is already in CISA’s Known Exploited catalog.

CISA: Apply vendor mitigations or discontinue use until patched.

Apr 12, 2024

Three steps. No scanners. No agents.

You already know which tools hold customer data, source code, and identity. Name them. We do the watching.

01

Name your stack

Pick from a curated catalog — Okta, Slack, Salesforce, M365, GitHub, and eighty more. Not a blank text box.

02

We watch the blast radius

Direct hits on those vendors, plus the cloud, identity, and parent companies behind them. Signal from CISA KEV and critical NVD CVEs — not every CVE on the internet.

03

A briefing you can act on

Severity, the CVE, which of your tools is exposed, and CISA’s required action. Daily or weekly digest on Keep Track.

Built for the person who owns the risk, not the SIEM.

Recorded Future and Mandiant are six figures. This is a watchtower for companies that live in SaaS and do not have a threat-intel desk.

We do not scan you

No network access, no SSO dump, no endpoint agent. You type the tools. That is the whole integration.

Exploited first, not theoretical

CISA’s Known Exploited Vulnerabilities catalog is the primary feed. If it is being used in the wild, it shows up here.

Suppliers, not just logos

Slack runs on AWS. GitHub is Microsoft. Auth0 is Okta. When the vendor behind your vendor is hit, Keep Track says so.

Simple pricing

Start free. Upgrade when the blast radius matters.

Free

$0 / forever
  • 3 SaaS tools
  • Direct vendor matches only
  • Last 7 days on the dashboard
  • No email digest

Create a free watchlist

Questions we hear from CIOs

Do you need access to our network or identity provider?

No. You name the tools. We never connect to your environment.

Where does the intelligence come from?

CISA’s Known Exploited Vulnerabilities catalog and the National Vulnerability Database, matched against a curated SaaS catalog and a hand-built supplier graph. We do not scrape Twitter.

What does “supplier blast-radius” mean?

If you track Slack and AWS is exploited, you see it as a supplier match. Free accounts only see incidents that name a tool you listed.

Can I cancel anytime?

Yes. Stripe Customer Portal handles cards, invoices, and cancellation. Access stays through the paid period.

ZeroDayTracker — Know when a zero-day hits your stack