← Trust
For your security review

Security & deployment

The picture a security or procurement reviewer needs: how the service runs, what data it uses, what it collects from you, and how to report a problem. ESIP's posture follows the same principle as its signals: verify, don't trust. Everything here is checkable.


How the service runs

This website is a static site served from Cloudflare's edge (Workers and Static Assets). It renders no customer data and holds no database. ESIP's signal data is served by a separate API: the free tier at public.exposuresignal.io and the commercial tier at api.exposuresignal.io.


What data ESIP uses

Every signal is derived from publicly observable evidence: exploitation catalogs, prediction scores, exploit repositories, advisories, and patch sources. Producing a signal requires no access to your environment, your assets, or your scan data.


What we collect from you

Authentication & secrets

Third-party services

The services ESIP relies on to operate this site and its access flows:


Determinism & integrity

Every signal is deterministic and evidence-backed: the same evidence under the same rules always produces the same verdict, and each one traces to the public source behind it. The method is defined in the published reference and explained on how it works.


Reporting a vulnerability

Report security issues in the site or the API responsibly to security@exposuresignal.io. Disclosure details follow RFC 9116 at /.well-known/security.txt.


Assurance artifacts