SecNote is a public-source briefing dashboard. Personal triage state is kept in your browser unless a separate deployment adds account or server-side persistence.
Saved items: article IDs you bookmarked in the browser.
Read items: article IDs you marked as read in the browser.
Exposure configuration: providers, products, vendors, CVEs, and keywords you added to My Exposure.
Vendor selection: selected major vendors and any custom vendor entries.
Sync timeline: recent refresh metadata used to show newly loaded articles.
Server
Public Source Fetching
The server fetches public RSS feeds, public APIs, and structured public vulnerability sources.
Briefing results are cached briefly server-side to avoid repeatedly hammering public feeds.
No API keys are required for the current public-source briefing.
Opening a source link navigates to the external source site, which is governed by that site's policies.
Scope
What SecNote Does Not Store
No SecNote account profile is created by the briefing dashboard.
No private vulnerability data is entered into the default public-source briefing flow.
No saved/read/exposure/vendor state is intentionally sent to the server by the current dashboard UI.
No source credentials, vendor credentials, or SIEM credentials are required by the current dashboard.
Clear browser site data for this domain to remove saved/read state, exposure watchlists, vendor selections, custom vendors, and sync timeline entries from this browser.