Skip to content

What Data XPosture Accesses — and Why

XPosture reads from your connected tools; it never changes them. Everything collected serves one purpose: assessing your compliance and risk posture, with evidence you can audit. This page lists the categories.

Data category What it is Why XPosture needs it
Findings & check results Pass/fail/warning results of compliance checks, with the evidence that produced them The core of posture assessment and audit trails
Asset inventory Hostnames, IPs, OS, device type as reported by your connected tools Findings and posture are shown against real assets
Vulnerabilities CVEs reported by your EDR/VA tools, with severity and known-exploitation status Surfacing what is dangerous, not just what is present
Device configurations Firewall policies, ACLs, interface and logging settings from uploaded configuration files Benchmark checks against hardening guidance
Identity & access Users, groups, MFA enrollment, sign-on policies from your identity providers Identity-related compliance checks
Threat & incident context Alert and incident status from your SIEM/EDR/XDR Context for posture assessment

Points worth stating plainly:

  • Read-only, least privilege. Every connector is designed to work with read-only credentials; the prerequisites page lists what each needs.
  • Credentials are stored encrypted at rest.
  • History is kept honestly. Superseded findings are retained as history rather than overwritten, so trends and audits reflect what was actually true at the time.
  • Gaps are visible. If a source fails or is unlicensed, that absence is shown — missing data is never presented as "low risk".