Deployment Options
XPosture runs where your constraints require — from SaaS to fully offline. All on-premise forms are Docker-based and ship as a self-contained package.
SaaS
The XPosture engine is hosted by us, and a lightweight collector is installed inside your network. The collector connects to your devices (for example firewalls) and tools, collects and analyzes their configuration locally, and sends the results up to the XPosture SaaS engine. Your device configurations and credentials stay inside your network — the collector connects outbound-only, so no inbound access to your network is required. This is how SaaS keeps your sensitive data local while still giving you a hosted, centrally-managed posture view. Talk to us about collector sizing and setup for your environment.
On-premise (standard)
A Docker Compose deployment: the XPosture application, PostgreSQL, and Redis. Suitable for evaluations and smaller environments — plan for a host with at least 16 GB RAM and 8 vCPU. The host needs outbound access to each source you configure, on that source's documented protocol and port.
On-premise (enterprise)
A production profile with a scaled database, multiple scan workers, and higher resource allocations for large environments; the reference sizing targets a 64 GB / 32 vCPU class host. Ask us for the sizing guide matched to your asset count.
Air-gapped / isolated networks
For regulated and isolated environments, XPosture can be deployed as an offline installation package. The exact offline process (including how updates are delivered) depends on your environment — talk to us about the air-gap option for your case.
The collector
The collector is the piece that runs inside your network and does the local collection and analysis for the SaaS deployment (see above): it reaches your devices and tools, holds their credentials locally, analyzes configurations on the spot, and sends only the results outbound to the XPosture engine. This keeps credentials and raw configuration inside your network. Ask us about collector sizing, supported sources, and setup for your environment.
AI features and data boundaries
AI in XPosture explains and summarizes assessment results. AI access is governed per tenant: it can be restricted to a specific provider configuration or disabled entirely. If your requirements include keeping AI processing inside your own environment, talk to us about the deployment forms we can support for your case.