Product capability disclosure

See which exposures need action, with the evidence behind each decision.

KMayer Exposure Lens AI brings discovery, correlation, prioritisation, remediation and verified recheck into one licensed platform. This page explains the 29 capability families, what a customer receives and where authorised data or deployment is required.

Buyer-readable coverage

One platform, itemised by operation and outcome.

Search by environment, operation or output. The complete list remains available when JavaScript is unavailable.

01-08

Management and analysis

CapabilityCustomer resultActivation and boundarySubscription
1Exposure Management A governed register from discovery through remediation, closure and recurrence. Uses available evidence and approved organisation scope. Included when active for the authorised scope
2Executive Dashboards / Exposure View Decision-ready views of exposure, ownership, movement and open action. Views are limited to the entitled organisation and available data. Included when active for the authorised scope
3Attack Path Analysis Observed relationships and inferred paths with evidence, confidence and breakpoints. Inferred paths are labelled; deeper validation requires authorisation. Included when active for the authorised scope
4Risk-Based Prioritisation A ranked decision queue with explainable factors and unavailable-data handling. Priorities support decisions; they do not replace customer judgement. Included when active for the authorised scope
5ExposureAI / Agentic AI Evidence-grounded analysis, summaries and next-action support. AI output remains traceable, confidence-scored and reviewable. Included when active for the authorised scope
6Cyber Exposure Score A documented exposure measure with contributing factors and trend context. The score reflects available authorised evidence, not complete protection. Included when active for the authorised scope
7Peer Benchmarking Normalised cohort context with methodology, privacy thresholds and freshness. Shown only when an eligible benchmark dataset and cohort are available. Included when active for the authorised scope
8Custom Exposure Cards Customer-relevant views built from governed exposure measures. Definitions and data requirements are agreed within the licensed scope. Included when active for the authorised scope

09-21

Scanning, mapping and discovery

CapabilityCustomer resultActivation and boundarySubscription
9Vulnerability Management Normalised vulnerability evidence connected to assets, priority and ownership. Requires a supported scanner source, authorised export or approved collection. Included when active for the authorised scope
10IT Asset Inventory Canonical assets, relationships, source provenance and count-once reconciliation. Coverage follows the authorised sources and asset boundary. Included when active for the authorised scope
11External Attack Surface Management Outside-in discovery, evidence, ownership review and change monitoring. Public collection stays passive; active validation requires approval. Included when active for the authorised scope
12Attack Surface Management Known, possible, excluded and newly observed assets in one governed inventory. Potential assets remain unconfirmed until ownership is reconciled. Included when active for the authorised scope
13Cloud Security / CNAPP Cloud asset, configuration, identity and workload context linked to exposure. Requires authorised cloud access or an approved cloud export. Included when active for the authorised scope
14Infrastructure as Code Scanning Repository and pipeline findings linked to deployable assets and owners. Requires approved repository or export scope. Included when active for the authorised scope
15Identity Security Identity relationships, privilege exposure and accountable remediation context. Requires authorised identity evidence; credentials are not exposed in reports. Included when active for the authorised scope
16OT / IoT Security Asset and exposure context for approved operational and connected-device estates. Collection mode and safe operating boundary are environment-specific. Included when active for the authorised scope
17Web Application Scanning Authorised web findings with evidence, scope and recheck state. No unrestricted anonymous scanning; target ownership is required. Included when active for the authorised scope
18Container Security Image, workload and deployment evidence connected to assets and remediation. Requires a supported registry, runtime source or authorised export. Included when active for the authorised scope
19Active Active Directory Monitoring Directory change and privilege evidence with identity relationship context. Requires authorised deployment and an approved directory boundary. Included when active for the authorised scope
20Passive Network Monitoring Network-observed asset and communication evidence without active probing. Requires an approved sensor location and collection boundary. Included when active for the authorised scope
21Credentialed and Non-Credentialed Scanning Reconciled scan evidence with method, coverage and confidence preserved. Credentials remain controlled; scanning requires explicit authorisation. Included when active for the authorised scope

22-29

Infrastructure, compliance and ecosystem

CapabilityCustomer resultActivation and boundarySubscription
22Compliance and Benchmarks Evidence mapped to applicable control and benchmark context. Control mapping supports review and does not itself certify compliance. Included when active for the authorised scope
23Core, Virtual Appliances and Agents Scoped collection options with health, freshness and deployment evidence. Deployment is separately approved for the customer environment. Included when active for the authorised scope
24Third-Party and Vendor Risk Assessment Vendor relationships, exposure evidence, business context and owner decisions. Coverage depends on authorised internal and available external evidence. Included when active for the authorised scope
25Threat Intelligence and Research Threat context connected to affected assets, evidence and priority decisions. Source rights, freshness and confidence remain visible. Included when active for the authorised scope
26Integrations and Open API Ecosystem Validated connections and authorised imports with provenance and lifecycle controls. Each provider is live only after source-specific authorisation and validation. Included when active for the authorised scope
27Role-Based Access Control Organisation-scoped roles, privileged support boundaries and accountable access. Access is enforced server-side and follows the entitled tenant. Included when active for the authorised scope
28SLA Tracking and Remediation Workflows Owner, due date, action, evidence, recheck and escalation context. Workflow state does not replace verified technical closure. Included when active for the authorised scope
29Asset Criticality Rating Business criticality connected to asset identity and prioritisation. Criticality is governed by customer context and recorded rationale. Included when active for the authorised scope

Versioned technical coverage

Know which catalogue and result state supports each conclusion.

The active authorised-host catalogue is versioned and evidence-bound. Framework relationships provide review context; they do not certify the customer or establish legal compliance.

Catalogue

Current verified version

CoverageVersion and relationship
Authorised Linux host baselineKMayer Linux Host Baseline 2026.09-r9
Technical check setsNIST Cybersecurity Framework 2.0; CISA Cross-Sector CPG 2023-1; DISA Ubuntu 24.04 STIG V1R5.
Control relationship overlaysISO/IEC 27001:2022; NIS2 Directive (EU) 2022/2555; Security practices Trust Services Criteria 2017; CIS Controls 8.1; PCI DSS 4.0.1; OWASP ASVS 4.0.3.

Result states

What each result means

ResultMeaningCustomer interpretation
PASSAuthorised evidence met the expected check at collection time.A point-in-time result, not proof of complete compliance.
FAILAuthorised evidence did not meet the expected check.Review the evidence, authorised scope and remediation before recheck or risk acceptance.
NOT CHECKEDAn imported OpenSCAP or XCCDF control was not evaluated, not selected or not applicable.Never treated as passing; the reason and source boundary remain explicit.

Native host checks can also report WARNING when non-required evidence is absent and ERROR when a source cannot be read. Neither is treated as passing.

Purchase-to-value path

Know the scope before an assessment starts.

  1. ReviewInspect capability, security and integration boundaries.
  2. RequestSubmit the organisation, authorised target and provisional asset quantities without payment or assessment.
  3. VerifyConfirm the business recipient, authorised assets and tenant boundary.
  4. ApproveReview the provisional capacity, billing frequency and scope before approving PayPal.
  5. ReceiveA verified webhook activates server-side entitlement; assessment follows, then private outputs.
Start an exposure assessment
EN
KMayer - IT Service Provider
Privacy Policy

Our website is committed to protecting your privacy. We collect and process data to enhance your experience, such as recognizing you when you return and understanding how you interact with our content. Your information is used responsibly to ensure that our services remain valuable, secure, and tailored to your needs. For a detailed explanation of how we handle and protect your data, please refer to our Privacy Policy