How Exposentra works

Outside-in visibility.
Inside your control.

The Exposentra mobile app and full web platform take you from authorised asset onboarding to clear external-security evidence—without placing an agent inside your network.

VIEWPOINTThe public internet

01

Create your organisation workspace

Self-enrolment creates a separated workspace for your organisation. Workspace roles help control who can view results, run assessments and administer users.

  • Business account and organisation profile
  • Role-based workspace access
  • Mobile app and full web platform
02

Add the assets you are authorised to assess

Add business domains and public IP addresses. Every asset remains tied to your organisation, with ownership and verification state visible to the team.

  • Domain assets
  • Public IP assets
  • Ownership and verification status
03

Verify ownership before active assessment

Verification is a safety boundary. It helps demonstrate that the organisation controls the asset before an authorised user runs a new assessment.

  • Verification challenge
  • Visible verified or pending state
  • Assessment actions restricted by role
04

Assess from an external point of view

Exposentra checks publicly observable controls and reachable services. It does not need credentials to your internal network, cloud tenant or endpoint fleet.

  • Email and DNS controls
  • Web and TLS posture
  • Publicly reachable services
05

Review score, evidence and findings

The result is organised into an overall posture, per-asset technical evidence and findings ranked by severity, category and recommended action.

  • 0–100 posture score
  • Prioritised findings
  • Technical evidence and observations
06

Track improvement and stay informed

Reassess after changes, compare results over time and use mobile notifications, web reports and support conversations to keep progress moving.

  • Assessment history and trends
  • Mobile push notifications
  • Web reports and Request Center

What an external view means

Useful evidence, with honest boundaries.

What it does

Reviews controls and services that can be observed from the public internet, organises results and helps track change.

×

What it does not do

It does not authenticate into internal systems, exploit vulnerabilities, guarantee security or certify regulatory compliance.

When to go further

Use professional assessment, penetration testing or architecture review when deeper assurance or regulatory evidence is required.

Reading your result

A score is a signal—not a verdict.

Scores make change easier to understand, but no single number can represent every business context. Prioritise the underlying findings, affected assets and recommended action, and consider how each issue relates to your organisation.

Read assessment FAQs
CriticalImmediate attention
PoorMaterial gaps
FairImprovement needed
GoodMaintain and improve

Controlled early access

See your first external baseline.

Tell us about your organisation and the assets you want to understand. We’ll explain the controlled early-access process.

Choose your access path