Skip to content
Self-hosted ASPM

Xposure360

Self-hosted · $0

One prioritized, deduplicated view of every scanner's findings — self-hosted on your own infrastructure, at no licence cost.

Xposure360 is a self-hosted Application Security Posture Management (ASPM) platform. Security teams run several scanners — SAST, SCA, container, and IaC — and each reports the same vulnerabilities in its own format, with its own severity opinion. Xposure360 ingests that output, merges duplicate findings across tools into one, and ranks what's left by exploit-aware risk, so you triage a single prioritized list instead of chasing every scanner separately. It runs entirely on your own machine at $0 — no cloud infrastructure, no SaaS dependency, and your findings never leave your environment.

What it does

  • Ingest every scanner
  • Deduplicate & corroborate
  • Exploit-aware prioritization
  • Explainable risk score
  • Tunable weights & SSVC
  • + 4 more below

What it does

Ingest every scanner

Upload SARIF (Semgrep, Trivy, Grype), AWS Security Hub ASFF, or CSV — or connect tools directly: GitHub Dependabot, GitHub Code Scanning, AWS Security Hub (pull), and a CI SARIF push endpoint all flow through the same engine.

Deduplicate & corroborate

A deterministic fingerprint merges the same real-world issue reported by different tools into one finding — so “confirmed by N of M scanners” is visible instead of buried, including GHSA↔CVE alias resolution across tools. In a real nine-scanner test corpus this collapsed 682 raw findings into about 325 unique — roughly 2.1x fewer to triage.

Exploit-aware prioritization

Ranks findings by real-world exploitability using EPSS probabilities and the CISA KEV catalog — not CVSS alone — so the threats actually being exploited rise to the top.

Explainable risk score

Every score breaks down as severity x asset criticality x internet exposure, computed live — tag an asset as a crown jewel or internet-facing and every dependent score updates immediately. No bare numbers.

Tunable weights & SSVC

Org-tunable weight profiles let you encode your own risk appetite (every change versioned for audit), and an SSVC decision layer labels each finding Act / Attend / Track alongside the score.

CVSS-vs-Xposure360 proof

A side-by-side view contrasts the CVSS-only “critical” queue against the exploit-aware queue — showing the bloat it drops and the lower-CVSS-but-actively-exploited threats it floats up.

Fix workflow to retest

An OPEN -> IN PROGRESS -> FIXED -> RETEST -> CLOSED workflow with assignment, full history, SLA tracking, and optional Jira ticket creation.

Team-ready & auditable

App-native login with role-based access (Admin / Analyst / Viewer), an append-only audit log, and a login rate limit that combines per-username and per-IP signals. Connector credentials are encrypted at rest.

Runs on your infrastructure

A single self-hosted app backed by SQLite — no cloud spend, no SaaS account, no data egress. Demo-data seeding, backup and restore, and honest empty states are built in.

How it works

From connect to result

01

Find

Ingest scanner reports by upload, or pull them in automatically from connected tools and CI.

02

Correlate

Duplicate findings across tools collapse into one, with corroboration and GHSA↔CVE alias resolution made visible.

03

Prioritize

Findings rank by exploit-aware, explainable risk — EPSS, KEV, asset criticality, and exposure — under weights you control.

04

Assign

Route each finding to an owner, with autocomplete from names you've used before.

05

Fix

Move findings through the status workflow, with full history and optional Jira tickets.

06

Retest

Re-ingest a scan; fixed issues that reappear auto-reopen, and issues a scan stops reporting are flagged as evidence to close — never auto-closed.

Who it's for

Best fit

  • AppSec and security teams running multiple scanners with no single, deduplicated view
  • Teams without a commercial ASPM/CNAPP (Wiz, Prisma, PlexTrac) — the $0, self-hosted alternative
  • Security teams that need an on-premise tool where findings never leave their infrastructure
  • GRC- and audit-conscious teams that need explainable, reproducible, versioned prioritization

How it fits

What it is — and what it isn't

We'd rather be clear up front than have you find the edges later.

  • A focused, self-hosted tool — not enterprise SaaS. SSO (SAML/SCIM), true multi-tenant isolation, and external secret vaulting are deliberately out of scope for now.
  • One shared project pool: roles gate actions, not separate data partitions.
  • SQLite-backed and single-writer — sized for team scale, not thousands of concurrent analysts.

Xposure360 — FAQs

What does 'self-hosted at $0' actually mean?

Xposure360 runs as a single app on your own machine or server, backed by a local SQLite database. There's no cloud infrastructure to pay for and no SaaS subscription — and because it runs on your side, your findings never leave your environment.

Which scanners and tools does it support?

It ingests SARIF (Semgrep, Trivy, Grype), AWS Security Hub ASFF, and CSV by upload, and connects directly to GitHub Dependabot, GitHub Code Scanning, and AWS Security Hub (pull), plus a CI SARIF push endpoint.

How does it decide what's actually important?

It combines exploitability signals (EPSS probability and the CISA KEV catalog) with your asset context (criticality and internet exposure) into an explainable score you can tune — and adds an SSVC Act / Attend / Track decision label.

How does it avoid double-counting the same vulnerability?

A deterministic fingerprint merges the same issue reported by different tools into a single finding — including resolving GHSA and CVE identifiers for the same advisory — and shows how many scanners corroborated it.

Is it a Wiz or Prisma replacement?

No. Xposure360 is aimed at teams that don't have a commercial ASPM/CNAPP and want a free, self-hosted way to unify and prioritize their existing scanner output.

See Xposure360 for yourself

Book a call and we'll walk you through it against a sample environment, and talk through access for your team.