Your dataset, fresh every day, with what changed
The files you already load from CyberMax's free Hugging Face datasets, refreshed daily, with daily history and a "what changed since yesterday" diff. Same schema, same paths: switch your pipeline with one line. Feeds from $19/month.



Who it's for
Anyone whose notebook, ETL job or app already pulls a CyberMax dataset and needs it current every morning, with history and the changes.
Point the job at the feed URL instead of the Hugging Face file; read only the diff files to update incrementally.
Kevscope feed: the CISA KEV catalog with EPSS and CVSS, rebuilt every day, with the new KEV entries and EPSS moves as rows.
Form 4 and 10-K/10-Q feeds: every new filing every business day, with the history kept since the feed started.
Domain-ranks feed: Majestic Million ranks refreshed daily across 10M domains, with every rank change listed.
Try it
Pick a feed and see what changed in the newest daily build.
Raw JSON response
Real sample output
Shape of /api/changes (counts from a real build of the Form 4 feed on its first day).
{
"feed": "form4",
"title": "SEC Form 4 insider transactions",
"date": "2026-10-09",
"since": null,
"data_date": "2026-10-09",
"files": {
"data/transactions.parquet": {
"key": "whole row",
"rows": 1305,
"added": 1305,
"removed": 0,
"changed": 0
}
},
"rows": "https://deltawren.cybermaxtools.com/v1/form4/diff/2026-10-09/<file> (key needed)"
}Limits, plainly
Free and rate limited so it stays fast for everyone. A bulk and scheduled version for big lists is coming to the Apify Store.
- Free: the feed list, each feed's manifest.json and the daily change counts (diff/<date>.json), 200 requests a day per IP.
- Paid keys open the files: today's files, daily history and the changed rows, for the feed you buy (or every feed with All feeds). Plans from $19/month.
- History starts on the feed start date (9 Oct 2026) and grows every day; full daily snapshots are kept 90 days (domain ranks: daily diffs plus a monthly snapshot).
- Data comes from public sources (CISA, FIRST, NIST NVD, SEC EDGAR, Majestic, Common Crawl) under their own licences, listed in each dataset card.
Need answers, not files?
The Kevscope, Insidewell and Linkheft APIs answer per CVE, ticker or domain, with free daily calls.
Get an API key
Daily data feeds as files: the same layout and schema as the free CyberMax Hugging Face datasets, refreshed every day, with daily history and a what-changed diff per file. One key per feed, or All feeds.
14-day money-back promise: if it doesn't work as described, email us within 14 days and we fix it or refund you in full. Refund terms.
20,000 file requests a month · 60 per minute
Get Open Domain Ranks feed keyor $190/year, 2 months free20,000 file requests a month · 60 per minute
Get Kevscope CVE + KEV + EPSS feed keyor $190/year, 2 months free20,000 file requests a month · 60 per minute
Get Riskroll SEC 10-K/10-Q sections feed keyor $290/year, 2 months free20,000 file requests a month · 60 per minute
Get SEC Form 4 insider transactions feed keyor $290/year, 2 months free60,000 file requests a month · 120 per minute · + every Deltawren feed
Get All feeds keyor $650/year, 2 months freePay with card, Apple Pay, Google Pay or Link through Stripe Checkout. Prices are in USD; where your country charges VAT or sales tax, Stripe adds it at checkout and shows it before you pay. Your key appears on the page you return to right after checkout: save it. Manage or cancel any time at deltawren.cybermaxtools.com/manage. Send it as x-api-key: YOUR_KEY (or Authorization: Bearer YOUR_KEY, which MCP clients support). Check usage at /key. Failed calls are not counted. Priced at or under the entry tier of each category's rivals. Open Domain Ranks: Moz API, DataForSEO, Ahrefs, OpenPageRank. Kevscope CVE + KEV + EPSS: OpenCVE (EUR 19/49 a month), Vulners ($600). Riskroll SEC 10-K/10-Q sections: sec-api.io ($49-55/mo), EODHD ($59.99/mo), Financial Modeling Prep ($19-99/mo). SEC Form 4 insider transactions: sec-api.io ($55/mo), FMP ($19/mo), EODHD ($59.99/mo).
curl -s "https://deltawren.cybermaxtools.com/api/changes?..." -H "x-api-key: YOUR_KEY"
# MCP (Claude Desktop, Cursor, VS Code)
{ "mcpServers": { "deltawren": { "type": "http", "url": "https://deltawren.cybermaxtools.com/mcp",
"headers": { "Authorization": "Bearer YOUR_KEY" } } } }
# Usage so far
curl -s https://deltawren.cybermaxtools.com/key -H "x-api-key: YOUR_KEY"Use the API
JSON over HTTPS, CORS enabled, no key. GET for quick calls, POST a JSON body for lists. Spec: openapi.json · llms.txt
curl -s "https://deltawren.cybermaxtools.com/api/changes?feed=kevscope"
# lists: POST a JSON body
curl -s -X POST https://deltawren.cybermaxtools.com/api/changes \
-H "content-type: application/json" \
-d '{"feed":"kevscope"}'import requests
r = requests.post("https://deltawren.cybermaxtools.com/api/changes",
json={"feed":"kevscope"}, timeout=30)
r.raise_for_status()
for row in r.json()["null"]:
print(row)Endpoints: /api/feeds every feed: dataset, cadence, history and plans · /api/changes what changed in a feed since the previous day (counts per file)
Add it to your AI agent (MCP)
A remote MCP server at https://deltawren.cybermaxtools.com/mcp (streamable HTTP, no auth). Read-only tools with JSON schemas, so agents know exactly what to send.
// Claude Desktop, Cursor, VS Code, any MCP client (remote, no key)
{
"mcpServers": {
"deltawren": { "type": "http", "url": "https://deltawren.cybermaxtools.com/mcp" }
}
}
# Claude Code
claude mcp add --transport http deltawren https://deltawren.cybermaxtools.com/mcp
# Tools: feed_list, feed_changes
# e.g. feed_list({"feed":"domain-ranks"})feed_list
Every Deltawren daily data feed: source dataset, refresh cadence, history kept, manifest URL and plans.feed_changes
Rows added, removed and changed per file in one feed since the previous daily build.
FAQ
How do I switch my pipeline?
Change the base URL from https://huggingface.co/datasets/CyberMax-tools/<dataset>/resolve/main/ to https://deltawren.cybermaxtools.com/v1/<feed>/latest/ and send your key as the x-api-key header. File names, formats and columns are the same.
What is in the diff?
For every data file: rows added, removed and changed since the previous build, matched on the file's key (CVE ID, domain) or on the whole row when the file has no unique key. The counts are free; the rows are Parquet files you download with your key.
Why not just re-download the free dataset?
The free snapshot is refreshed on its own schedule and keeps one version. The feed is rebuilt every day, keeps daily history and tells you exactly what changed, so jobs can update incrementally and reproduce any past day.
Is there a key or a cost?
The free tier needs no key: 200 file requests a day per IP. Paid keys: Open Domain Ranks feed $19/month for 20,000 file requests, Kevscope CVE + KEV + EPSS feed $19/month for 20,000 file requests, Riskroll SEC 10-K/10-Q sections feed $29/month for 20,000 file requests, SEC Form 4 insider transactions feed $29/month for 20,000 file requests, All feeds $65/month for 60,000 file requests (plus every Deltawren feed). Yearly billing gives 2 months free. A key opens one feed (or every feed with All feeds). Send the key as the x-api-key header. No surprise overage charges; cancel any time.
Can AI agents use it?
Yes. The MCP server (URL below) has feed_list and feed_changes tools; files are plain HTTPS downloads.
Where does the data come from?
Public sources under their own licences: CISA KEV (CC0), NIST NVD (public domain), FIRST EPSS (attribution requested), SEC EDGAR (public domain), Majestic Million (CC BY 3.0) and the Common Crawl web graph (Common Crawl terms). Not affiliated with any of them. Form 4 and SEC data: information only, not investment advice.