What Data XPosture Accesses — and Why
XPosture reads from your connected tools; it never changes them. Everything collected serves one purpose: assessing your compliance and risk posture, with evidence you can audit. This page lists the categories.
| Data category | What it is | Why XPosture needs it |
|---|---|---|
| Findings & check results | Pass/fail/warning results of compliance checks, with the evidence that produced them | The core of posture assessment and audit trails |
| Asset inventory | Hostnames, IPs, OS, device type as reported by your connected tools | Findings and posture are shown against real assets |
| Vulnerabilities | CVEs reported by your EDR/VA tools, with severity and known-exploitation status | Surfacing what is dangerous, not just what is present |
| Device configurations | Firewall policies, ACLs, interface and logging settings from uploaded configuration files | Benchmark checks against hardening guidance |
| Identity & access | Users, groups, MFA enrollment, sign-on policies from your identity providers | Identity-related compliance checks |
| Threat & incident context | Alert and incident status from your SIEM/EDR/XDR | Context for posture assessment |
Points worth stating plainly:
- Read-only, least privilege. Every connector is designed to work with read-only credentials; the prerequisites page lists what each needs.
- Credentials are stored encrypted at rest.
- History is kept honestly. Superseded findings are retained as history rather than overwritten, so trends and audits reflect what was actually true at the time.
- Gaps are visible. If a source fails or is unlicensed, that absence is shown — missing data is never presented as "low risk".