ExposureGraphGraph Intelligence
Graph Intelligence is ThreatCanary’s relationship layer: assets, APIs, identities, vulnerabilities, owners, data and trust boundaries connected into one attack-path model.
Evidence traceApproved scopeTarget-aware testing
Connected contextOne graph. Every decision retains its source.
ThreatCanary connects exposure, APIs, identities, evidence and remediation so analysts can inspect why a path matters.
Open the sample evidence pack → - 01
EntitiesAssets, APIs, identities and data
- 02
RelationshipsOwnership, trust and reachability
- 03
ObservationsDiscovery and behavioural signals
- 04
PathsTarget-relevant compromise hypotheses
- 05
OutcomesEvidence, remediation and retest
Representative product workflow. This diagram explains the evidence model; it is not presented as a customer result or live product capture.
Capability architecture
Turn disconnected findings into compromise paths.
The graph is the platform memory that lets ThreatCanary reason over relationships instead of evaluating each signal in isolation.
01Why it matters
- Most tools produce lists: assets, APIs, CVEs, alerts and tickets.
- Attackers exploit relationships: a service connected to an API, an API connected to sensitive data, an identity connected to a trust boundary.
- Without relationship modelling, teams over-prioritise noisy findings and miss quiet paths to compromise.
02ThreatCanary approach
- Models assets, APIs, cloud services, identities, owners, data sensitivity, observations, hypotheses, tests and findings as connected entities.
- Weights relationships using exploitability, exposure, confidence, trust, data sensitivity and business context.
- Feeds offensive reasoning, blast-radius views, reporting, ownership routing and remediation prioritisation.
03Questions it answers
- What can this exposed system reach?
- Which APIs or identities make this finding more serious?
- Which assets form a realistic path to crown-jewel data?
- Which teams own the path and what evidence supports action?
04Outputs
- Interactive attack-path and blast-radius views.
- Relationship-aware risk scoring and prioritisation.
- Graph-backed context for AI advisors, reports and validation workflows.
- Evidence chains that explain why a finding matters beyond its isolated severity.
Common questions
Questions teams ask before they commit.
Direct answers on scope, evidence, safety controls and how ThreatCanary differs from tools you already run.
01What is ExposureGraph?
ExposureGraph is the ThreatCanary relationship layer. It connects assets, APIs, identities, vulnerabilities, owners, sensitive data and trust boundaries into a single attack-path model that every other capability reads from and writes to. It is what allows a finding to carry context about what it connects to rather than existing as a standalone record.
02Why does a graph model matter for security findings?
Because attackers do not respect product boundaries. Exposure, identity, API behaviour and exploitability have to be understood together to see that a low-severity issue on one asset becomes serious once it connects to an API handling sensitive data. A graph makes those relationships queryable, which is what turns a list of findings into a set of attack paths.
03What can teams do with the graph directly?
Threat hunting queries the graph for attacker-relevant patterns, exposure clusters and suspicious relationships. The same relationships drive remediation prioritisation — ranking fixes by exploitability, chainability, sensitive data exposure, ownership and business impact — and ownership mapping, which routes each finding to the team responsible for fixing it.