Collections are the organizational backbone of SpartanX. They group assets logically — by exposure type, technology, compliance scope, or team ownership — giving you meaningful structure for your engagements, vulnerability management, and reporting.
What Is a Collection?
A collection is a named group of assets. It defines a scope — a set of targets that belong together for operational or compliance reasons. SpartanX ships with several default system collections representing common organizational structures:
Perimeter Network — public-facing network assets
Public Web Applications — externally accessible web apps
Public APIs — externally exposed API endpoints
Cloud Infrastructure — GCP, Azure, AWS, or Oracle Cloud assets
AI Services — chatbots, AI agents, and AI-powered systems
Internal Infrastructure — intranet applications and internal services
You are not limited to these defaults. Collections are fully customizable to match how your organization is structured.
Creating a New Collection
To create a collection, click "New Collection" and fill in the following fields:
Name — a descriptive label for the collection (e.g., "PCI Cardholder Environment" or "EU Branch Infrastructure")
Description — optional context about what this collection contains
Exposure Type — select one of three options: Externally Facing (internet-connected), Internally Facing (not exposed externally), or Air-Gapped (isolated from the IP network layer)
Asset Types — optional classification such as web applications, APIs, cloud systems, or AI services. This is for organizational clarity, not enforcement.
Compliance Framework — flag if the collection is in scope for a specific regulation, such as PCI DSS, HIPAA, or SOC 2.
Once created, the collection appears in your list. A freshly created collection will show no vulnerabilities or security metrics — those populate after you run an engagement against its assets.
Managing Collections
Collections are flexible. You can:
Search for collections by name
Rearrange and reorganize them as your environment evolves
Delete collections that are no longer needed
Move assets between collections
When you open a collection, you can view its compliance framework, creator, and security metrics — once engagement data is available.
What's Next
With a collection created, the next step is adding assets to it. The following section walks through how to associate assets — IP addresses, domains, APIs, web apps, and mobile app binaries — with a specific collection.




