Questions and answers

What OmenPoint is, who it suits, how it differs from the tools you already use, and where the writing comes from. Last updated 18 August 2026.

What OmenPoint is

What is OmenPoint?

OmenPoint is a subscription security news service that collects from 570 public sources on a 30-minute cycle and files each story under one or both of two lenses. The technical lens covers what is affected and what to do about it. The commercial lens covers the conversation a story opens with a customer. It costs A$5 per month. You can switch on a daily brief at 7am in your own timezone, a Monday weekly wrap, or both, and email stays off until you turn it on in Settings.

Who is OmenPoint for?

It is built for people who have to talk about security news to someone else: pre-sales engineers, solutions architects, reseller and MSP account teams, and consultants. It suits a reader who carries several vendors at once and needs both the technical facts of a story and a reason to call a customer about it. It is not built for SOC analysts running detection and response, or for CTI teams producing finished intelligence, and those readers will find it thin.

What are the Technical and Commercial lenses in OmenPoint?

Each story is shown through two lenses over one shared feed: Technical and Commercial. The Technical lens states what is affected, whether exploitation is live, and the sensible first action. The Commercial lens states the angle for a seller and the conversation the story opens with an account, with CVE ids and EPSS percentages left out. A third view, Mixed, shows both reads on one card. Many stories carry both lenses, some carry only one. The chosen lens is carried in the URL, so a filtered view can be linked or bookmarked.

How many sources does OmenPoint actually cover?

The list holds 570 public sources: vendor research blogs, national CERTs, channel and trade press, CVE and known-exploited feeds, podcasts and YouTube channels. Of those, 399 are native feeds and APIs. The other 171 are scoped news queries used to cover vendors, countries and regions that publish no feed of their own, which is how all 111 named vendors and 194 countries stay filterable by name. Two entries are hand-picked evergreen reference lists rather than live feeds. Every source is public, with no paywalled inputs and no API keys, and every source appears by name in the product's own source filter.

Can I see a real note before I pay?

Yes, on the front page of omenpoint.com, with no account and no card. The cards there are real stories from the live feed carrying the notes actually written for them, on both lenses, refreshed as the feed moves. Read them as a showcase rather than a random sample: the selection prefers one story per vendor for variety, and only stories that carry a written note on that lens are eligible, so it shows the product at its best rather than its average. The email mock-up further down that page is deliberately synthetic, with invented vendors and a CVE id that cannot exist, so no real company has an invented vulnerability printed against its name in marketing. The /trending page is also public and lists the most opened stories of the last seven days. The daily brief itself you only see from inside an account.

How is OmenPoint collected, and how fresh is it?

Collection runs on a 30-minute cycle. An active source is polled every 30 minutes. A source that returns nothing four cycles running backs off, doubling its interval up to a maximum of four hours, and snaps back to 30 minutes the moment it publishes again. Stories covering the same incident are grouped onto one card by fixed rules: the same CVE within seven days, or near-identical headlines within three days. Reference-style entries such as the CISA catalogue are excluded from that grouping.

How OmenPoint compares with other tools

Is OmenPoint just an RSS reader with extra steps?

It is an aggregator with a sales lens on top, so a feed reader with a well curated source list reproduces a good part of the reading experience. What a feed reader does not add: a separate written read for engineers and for sellers, one card where several outlets covered the same incident, a one-click filter down to stories carrying a CISA known-exploited CVE, a sort by EPSS exploit-prediction score, and an email when a vendor on your alert list turns up in that catalogue. If your feed reader already handles the reading, the written read and the vendor alert are the parts you would be paying for.

Is a curated security newsletter enough on its own?

A good security newsletter is one editor's selection for a general security audience, arriving on their schedule, and several free ones are excellent enough that they are worth subscribing to before paying for anything. What a newsletter cannot do is know which vendors you carry. It covers what the editor judged most important that week, not what matters to your accounts, and there is no way to ask it for the last month of stories about one vendor. OmenPoint is the filtered alternative: the same news restricted to the vendors, categories and regions you pick, with a commercial read attached to the stories that carry one.

Do I need a threat intelligence platform, or is this enough?

They solve different problems, and the honest answer depends on whether you have a threat intelligence function. Enterprise threat intelligence platforms are built for CTI teams: dark web collection, finished intelligence products, analyst access, and integration into a security stack, priced accordingly. A reseller, MSP or vendor sales team without a CTI function usually needs three narrower things: the free CISA known-exploited catalogue, the security advisories of the vendors they carry, and a filtered news source. OmenPoint is the third of those at A$5 per month. It is not a threat intelligence platform and does not try to be one.

Can I just use ChatGPT to summarise security news for customer meetings?

An AI assistant with web search will summarise the week's security news and suggest talking points on demand, and for many meetings that is enough. OmenPoint differs in three ways you can check: a standing corpus of 570 sources that is collected whether or not anyone thinks to ask, stories grouped when several outlets cover one incident, and CISA's known-exploited catalogue checked against your chosen vendors after every collection cycle, with the alert emailed when one of them lands.

Vulnerabilities and alerts

Is CISA KEV available for free?

CISA's Known Exploited Vulnerabilities catalogue is free and public, needs no account, and the complete JSON feed can be downloaded from cisa.gov by anyone. OmenPoint mirrors the whole catalogue, 1,666 CVEs as at August 2026, so the KEV coverage is the catalogue's own and nothing about it is proprietary. The newest 120 entries also appear as browsable story cards; the full catalogue sits behind them and drives the badges, the filter and the alerts. A subscription pays for the routing: the catalogue watched against your chosen vendors, and each entry joined to the news coverage around it.

How do I get alerted when a vendor I sell has an exploited vulnerability?

Switch on KEV alerts in Settings, which are off until you do, and you get an email when a story lands carrying a CVE that is in CISA's known-exploited catalogue and affects a vendor on your alert list. In practice that is usually within hours. The alert vendor list is its own list: set one and following a vendor's news no longer means being paged about that vendor's entries, and until you set one your feed interests are used instead. Routine alerts are capped at one every six hours and 15 CVEs per email, and the first alert covers the previous seven days. CVEs past the cap are not dropped: the email counts them and they are waiting in your feed. Ransomware-linked entries and CISA deadlines falling inside a week skip the cooldown and send straight away.

What is the cheapest way to get security news alerts by vendor?

Free keyword alerting costs nothing and covers the basics: Google Alerts on the vendor name, plus each vendor's own security advisory mailing list. Free keyword alerts arrive one per matching article, so eleven outlets covering one breach produce eleven emails, and none of them tell you whether the CVE is being exploited. OmenPoint groups outlets covering the same incident into a single card using fixed rules, the same CVE within seven days or near-identical headlines within three days, and flags the ones sitting in CISA's known-exploited catalogue.

The notes and the lenses in practice

How do I prep for a customer security conversation quickly?

Open the commercial lens, filter to the vendors and regions that account cares about, and read the top few cards. Filters are multi-select, server-side and carried in the URL, so a filter set for one account can be saved, re-opened in a click, and set to email when new matches arrive, from the next matching story onward. Stories with a known-exploited CVE are badged and can be filtered to on their own with one toggle, and the feed can be sorted by EPSS exploit-prediction score when you want the likely-to-be-attacked ones first.

Does OmenPoint write a note on every story, or just some of them?

No, and that is deliberate. A story with nothing useful to say to a seller gets no commercial note rather than a manufactured one, and a card with no note is treated as a correct outcome. The technical read is written once, when a story is classified, so a story that arrived without one keeps none. The commercial read works differently and is not locked: older stories have been offered to it again when the prompt improved. Measured on 18 August 2026, 76% of the stories from the previous 30 days carried at least one written read, and 77% of the previous 7 days. Expect that to move as prompts change, and check it yourself rather than trusting it: a card with no note renders as a card with no note, so coverage is visible on screen.

Who writes the OmenPoint notes, and how accurate are they?

The notes are written by an AI model, from a fixed set of facts held for that story, and nothing else. The model is given the headline, the feed summary, the source, the vendor, the category, and the CISA known-exploited and ransomware flags with the catalogue's own name for the vulnerability. It is never given the article text, so a note is a short read of what the story says rather than an analysis of the underlying research. Its instructions forbid inventing versions, CVE ids, mitigations, exploitation status, numbers, names or impact, and a note that comes back carrying anything other than prose is discarded and asked for again. Treat a note as a prompt for your own judgement rather than a citable source, and open the link before you quote a number or a version.

Price, limits and data

What does OmenPoint cost, and is there a trial?

A$5 per month, beginning with a 30-day trial that collects a card up front through Stripe. Cancelling is one click in Stripe's own portal, during the trial or at any point after. Card details go to Stripe and are never held by OmenPoint. One trial is allowed per person, tracked by a one-way hash of the email address, with aliases folded in so plus-tags and Gmail dots count as one identity. Comped invites are the exception: they are free and take no card at all. Billing is monthly and in Australian dollars.

What does OmenPoint do with my data?

Reader data is held on a single server in AWS Sydney, with encrypted nightly database backups in AWS S3 in the same region. Cookies are first-party and functional: an HttpOnly session cookie, short-lived cookies during sign-in, and an optional trusted-device cookie if you turn on two-factor. There is no advertising cookie, no third-party analytics script and no cross-site tracker, and reader data is not sold. At signup your IP address is sent to a geolocation service to record a country code, and both are stored on your account, appear in your export, and go when the account goes. Share-link open details, address, user agent and referrer, are deleted after 90 days. Exporting everything held about an account is one click of self-serve JSON. Deleting an account cancels billing first, then erases the profile, preferences, saved stories, click history and share links. A one-way hash of your email address is kept so a free trial cannot be reused, and any feedback you sent is kept, with the login it was sent from.

Thirty days free, then A$5 a month. Cancel any time from Stripe's own portal, no email required.

Start the trial