ADX by Dajota App Factory

Data catalog

Start with software security.

A focused first product for agents that build, maintain, and evaluate software. Broader data collections are part of the roadmap, not an expanded claim of API availability.

Dependency-security query

Exact package names and versions in npm, PyPI, and NuGet.

01

OSV

Package advisories and affected-version evidence.

02

CISA KEV

Known-exploited vulnerability context, joined by CVE.

03

FIRST EPSS

Source-reported exploitation probability and percentile.

04

NVD

CVE details, severity metrics and weakness context.

What the query does

  • Matches retained OSV advisories against supplied package versions.
  • Adds CISA KEV, EPSS, and NVD context where a CVE join is available.
  • Returns explicit match states and evidence with timestamps.
  • Uses bounded candidate-advisory pagination.

What it does not establish

  • No match in a page does not mean the package is safe.
  • Unsupported version rules remain unknown.
  • No automatic dependency-tree or transitive-dependency discovery.
  • No promise of complete ecosystem or vulnerability coverage.
  • No independent certification of source accuracy.

A broader exchange, built in stages.

We are retaining and evaluating other public datasets. Downloaded bytes alone do not make a supported customer product.

PLANNED API

Weather & earth events

Weather observations, alerts, and earthquake context for operational agents.

PLANNED API

Research & knowledge

Publication metadata, knowledge sources, and research-integrity signals.

PLANNED API

Geospatial context

Structured place and geographic data for location-aware workflows.

No purchase or delivery date is offered for these planned products. Agent galleries, sponsored discovery, and marketplace services are also not publicly available.