The picture a security or procurement reviewer needs: how the service runs, what data it uses, what it collects from you, and how to report a problem. ESIP's posture follows the same principle as its signals: verify, don't trust. Everything here is checkable.
This website is a static site served from Cloudflare's edge (Workers and Static Assets). It
renders no customer data and holds no database. ESIP's signal data is served by a separate API:
the free tier at public.exposuresignal.io and the commercial tier at
api.exposuresignal.io.
Every signal is derived from publicly observable evidence: exploitation catalogs, prediction scores, exploit repositories, advisories, and patch sources. Producing a signal requires no access to your environment, your assets, or your scan data.
X-API-Key header.The services ESIP relies on to operate this site and its access flows:
Every signal is deterministic and evidence-backed: the same evidence under the same rules always produces the same verdict, and each one traces to the public source behind it. The method is defined in the published reference and explained on how it works.
Report security issues in the site or the API responsibly to security@exposuresignal.io. Disclosure details follow RFC 9116 at /.well-known/security.txt.