Frequently asked questions

What types of scans does Exposia run? Exposia covers several dimensions of your attack surface: discovery of subdomains and DNS records, port scanning and service detection, web vulnerability analysis, TLS verification, remote audits on Linux servers via SSH (Lynis, OpenSCAP), Law 25 compliance analysis (Quebec), ASVS OWASP evaluation, static code analysis (SAST) and threat intel enrichment (Enterprise plan). Multiple specialized engines work together, orchestrated by automated pipelines.
What is the unified inventory?

The inventory groups all detected exposure points (IPs, ports, services, technologies) in a single view, regardless of which scan type discovered them. Each entry keeps its appearance history (first seen / last seen) and a link to the source scan. You can filter by IP, hostname, service or technology and export to CSV or JSON.

Can I scan any target?

You can only scan targets that you have declared and for which you are the owner or responsible. Scans outside the authorized perimeter are not permitted.

Am I allowed to scan this target?

You may only submit targets you own or for which you hold explicit written authorization. By adding a target, you attest to this authorization in accordance with the Terms of Use. Scanning a system without authorization may constitute a criminal offence (s. 342.1 of the Canadian Criminal Code).

How do pipelines work?

A pipeline automatically sequences multiple scanning steps in the order you define: for example, subdomain discovery, then port scanning on the results, then vulnerability scanning. Exposia also provides ready-to-use integrated pipelines — including Daily Watch (daily_watch, short, adapted to daily planning) and Weekly Deep Audit (weekly_deep, more comprehensive). You can create your own custom pipelines.

Does Exposia replace a penetration test?

No. Exposia provides automated continuous monitoring of your attack surface. A penetration test is a thorough manual assessment carried out by a professional. Exposia completes this approach by ensuring permanent monitoring between tests.

How does scan scheduling work?

Scheduled scans (daily, weekly, bi-monthly or monthly) are included from the Pro plan (Pro+). On the Free plan, you launch your scans manually; The Advanced Target option allows one-time heavy scans without a subscription, but not recurring scheduling. The results accumulate in history and the inventory is updated automatically with each scheduled run.

What is Law 25 compliance?

Exposia integrates a compliance analysis with Law 25 (protection of personal information in Quebec) on your declared domains. The results complete your attack surface scans and can feed your pipelines (especially daily monitoring). The analysis focuses on public signals related to your web presence and digital communication practices — support for your compliance approach, not legal advice.

What is ASVS analysis?

ASVS (OWASP Application Security Verification Standard) is a grid of application security controls. Exposia runs an assisted ASVS assessment: automated probes aligned with these requirements, plus a prioritized report. This is not an OWASP certification or a human security audit. Unlimited ASVS is included from the Pro plan; on the Free plan, it is available via the Advanced Target option (manual scans).

What is the local agent?

The local agent is a component installed on your internal network (LAN) that lets you scan assets not exposed on the Internet — workstations, internal servers, private IP ranges. It communicates securely with the Exposia platform. This feature is reserved for the Enterprise plan and, for early customers, deployment is guided by the Exposia team (not fully self-serve).

Can I connect my code repositories?

Yes. Exposia lets you connect your GitHub or GitLab repositories to analyze dependencies and run static analysis (SAST) on your source code. You can also enable webhook monitoring on pull requests: Exposia analyzes modified code and surfaces findings directly in the platform.

How do email notifications work?

Exposia can send you an email when a scan detects new significant findings. Notifications are configurable at the organization level and, for code monitoring, per repository. You can enable or disable email alerts according to your preferences in the settings.

How does the team workspace work?

Each organization has a shared space. You invite colleagues with appropriate roles (owner, administrator, analyst, reader). All members see the same inventory, findings and reports.

Can I export my data?

Yes. The inventory of exposed assets and scan results can be exported in CSV and JSON. A REST API is also available depending on your plan: reading and launching scans on Pro, full access on Enterprise. There is no public OpenAPI documentation portal yet; contact us if you need an integration reference.

Where is my data hosted?

The data is hosted in Canada. We do not transfer your data out of the country.

How do I contact support?

Write to us at support@exposia.ca. We respond as soon as possible.