patchletter vs. SecAlerts
SecAlerts is a commercial CVE alerting service: you register your software stack and receive matching vulnerability alerts from many sources — via email, Slack, Teams, Jira or API.
patchletter takes a different angle. We follow the vendors' own release sources, pull in the demonstrably exploited flaws from CISA's KEV catalogue and record the end-of-support dates from endoflife.date. Whether you hear about it instantly, once a day or once a week is yours to set. The update radar costs nothing.
Side by side
| Feature | patchletter | SecAlerts |
|---|---|---|
| Release tracking for vendor products (Proxmox, FortiOS, Veeam …) | ✓ curated vendor sources: APIs, feeds, release-notes pages | ✗ |
| Actively exploited vulnerabilities (CISA KEV) | ✓ curated & low-noise — only demonstrably exploited CVEs; free to read, alert email with Pro | ✓ |
| End-of-life / support dates | ✓ endoflife.date data on every product page; warning email 90/30/7 days ahead with Pro | ✗ |
| Hardware / firmware (firewalls, NAS, switches) | ✓ | ✗ |
| Email instantly / daily / weekly | ✓ | ✓ |
| Slack / Teams / webhooks | partly Slack, Teams, webhook with Pro | ✓ |
| API | ✓ read-only REST API v1, free and without an account; plus an RSS feed per product | ✓ |
| Free to use | partly update emails free; security and EOL alerts with Pro | ✗ paid — free only as a time-limited trial |
When SecAlerts is the better choice
- A broad source base beyond CVEs (advisories, researcher reports) and integrations up to Jira.
- Team features and an API for larger security organizations.
Nothing wrong with running both: SecAlerts for its strengths, patchletter for the vendor gear it can’t see.
Tick off what you run
Confirm your address once, and after that an email arrives as soon as one of your vendors ships a new version. That is all we need.
Browse the catalogFacts about SecAlerts verified: 2026-08. Spotted something outdated? Let us know via the legal-notice contact. All product names are trademarks of their respective owners.