Core objects
Vulnerability terms
Time fields
Common fields includetimestamp, date_added, first_seen, last_seen, created_at, updated_at, and completed_at. Their presence and format vary by endpoint. Some are Unix timestamps; date filters on Enterprise routes often use DD/MM/YYYY, while OEM audit filters use YYYY-MM-DD.
Normalize times to UTC in your application, but retain the original field and value for auditability.
Ownership and attribution
DNS, certificates, shared hosting, historical records, and organization profiles are evidence, not definitive ownership proof. Keepobserved, inferred, and verified relationships separate in your internal model.