ExposureX Documentation
Welcome to the ExposureX Platform documentation - a Continuous Threat Exposure Management (CTEM) platform that runs the full five-stage loop: Scoping (attack surface + business context), Discovery (assets & exposures), Prioritization (transparent scoring with EPSS, KEV, reachability and business context), Validation (safe checks and re-verification), and Mobilization (remediation campaigns, SLA tracking, workflows, and scope refinement).
This site is the public ExposureX documentation hub. It is derived from the repository documentation and rebranded for the ExposureX deployment.
Getting Started
New to ExposureX? Start here:
| Guide | Description |
|---|---|
| Quick Start | Access the platform and validate the core services. |
| First Scan Tutorial | Register a runner and ingest your first scan result. |
Documentation by Audience
For Users
| Topic | Description |
|---|---|
| CTEM User Guide | Feature-by-feature guide across Scoping, Discovery, Prioritization, Validation, and Mobilization. |
| End-to-End Workflow | Complete scan workflow walkthrough. |
| Scan Management | Configure, run, and monitor discovery runs. |
| Notification Integrations | Slack, Teams, email, webhook, SIEM and ticketing alerts. |
| Authentication | Login, tenant selection, local auth, SSO and SAML setup. |
For Developers
| Topic | Description |
|---|---|
| Runner Quick Start | Run tools and push results with tenant runners. |
| API Reference | Agent and ingest REST endpoints. |
| Custom Tools | Build scanner, parser, collector and CTIS integrations. |
| CTIS Schema | Native ExposureX ingest model for assets and findings. |
For Operators
| Topic | Description |
|---|---|
| Production Operations | Docker Compose, Caddy, Cloudflare Tunnel and service health. |
| Configuration Reference | Domains, app URLs, CORS, CSRF, cookies and secrets. |
| Monitoring Guide | Container health, disk, backups and alerting. |
| Troubleshooting | Common operational issues. |
For Architects
| Topic | Description |
|---|---|
| System Overview | High-level architecture. |
| Scan Pipeline Design | Scan orchestration and workflow execution. |
| Access Control | RBAC, groups, permission sets and data scoping. |
| Agent Command Model | Server-agent communication and command lifecycle. |
Documentation Sections
Getting Started
Quick start guides and first-run procedures.
Platform Guides
Comprehensive guides for platform features:
- Authentication and tenant selection
- Multi-tenancy and RBAC
- Scanning and findings
- Runner configuration
- Integrations and notifications
Architecture
System design and technical architecture:
- Component interactions
- Data flows
- Security design
- Integration patterns
Operations
Deployment and operational guides:
- Production deployment
- Monitoring and alerting
- Backups and restore
- Rollback
Features
Feature-specific documentation:
- Runners
- Scan profiles
- Scanner templates
- Capabilities registry
- Asset modules
Backend
API service documentation:
- API reference
- JWT/session behavior
- Agent ingest
- Command lifecycle
Web Console
The Next.js authenticated application:
- Dashboard and command center
- Assets, findings and exposures
- Settings and administration
- Account and notifications
Component Documentation
| Component | Documentation |
|---|---|
| Platform (API + web) | Architecture and Backend |
| Runner | Runner documentation |
| SDK / Tools | Developer guide |
| Schemas | CTIS schema reference |
External Links
| Link | Description |
|---|---|
| Platform | Live ExposureX application. |
| Website | Public product site. |
| PT-BR Docs | Portuguese documentation. |
Roadmap
See Roadmap for planned CTEM phase coverage and production hardening work.
Contributing
This deployment is currently maintained as the ExposureX monorepo. Public contribution workflow will be documented when a public remote is published.