Documentation

Documentation

Practical guidance for taking ThreatCanary from approved scope through discovery, validation, evidence review and remediation workflows.

Explore the library

From authorised scope to reproducible evidence.

Documentation is organised around the work customers and partners perform: define boundaries, connect context, operate validation safely, review evidence and move remediation into existing systems.

01

Get started safely

  • Define approved organisations, domains, assets, APIs, environments, exclusions and testing windows.
  • Establish roles, approval requirements, execution limits and escalation paths before offensive validation begins.
  • Start with a bounded deployment and expand coverage as ownership and operating controls mature.
02

Operate the platform

  • Understand how discovery, ExposureGraph, methodology, hypothesis generation and deterministic validation work together.
  • Review exposure changes, attack paths, findings, evidence and retest state without losing provenance.
  • Tune workflow depth and approval gates to match the sensitivity of each environment.
03

Connect your ecosystem

  • Bring in ownership and environment context from cloud, gateway, repository and telemetry systems.
  • Route validated findings into ticketing, chat, SIEM and webhook workflows with their evidence attached.
  • Use least-privilege integration access and document what data enters and leaves each connection.
04

Review and remediate

  • Reproduce validated outcomes from recorded requests, responses, observations and execution context.
  • Assign findings to the teams that own the affected asset, API, identity or workflow.
  • Retest after remediation and preserve evidence of what changed.