ExposeGuard
An infrastructure exposure validation platform: it checks whether each service is reachable from where it should be — and only from there.
Most scanners stop at "this port is open". ExposeGuard answers the question that actually matters to a security team: is this service reachable from this location, should it be reachable from there, and does it behave the way the organization says it does?
The same asset is checked from several scanner nodes placed in different network segments — the internet, the office, the VPN, a production VPC or a DMZ. Wherever what the network actually allows differs from what policy expects, ExposeGuard records a finding with evidence, history and a lifecycle, so drift such as an admin panel accidentally reachable from the internet is caught and tracked until it is fixed.
It is a defensive, authorized-use product. During setup an organization defines the networks and domains it owns, and nothing outside them is ever scanned. ExposeGuard performs no exploitation and only observes and validates exposure. Scanner nodes always connect outbound to the controller, so they can run inside a private network or behind office NAT without opening any inbound firewall rule.
Key features
- Exposure checked from multiple network vantage points: internet, office, VPN, VPC and DMZ
- Expected-versus-actual reachability turned into findings with evidence, history and a lifecycle
- Scanning limited to the networks and domains the organization has authorized
- Remote scanner nodes that connect outbound only, with no inbound firewall changes
- Live scan progress in the web console
- Published status pages for a public-facing view
- Defensive by design: observation and validation only, no exploitation
Architecture
A TypeScript controller serves the API, the web console and a gateway that remote scanner nodes connect to over outbound WebSocket connections, with PostgreSQL for storage. The scanning tools run inside a dedicated container image, so nothing extra is installed on the host, and the stack is deployed with Docker behind nginx.