Skip to main content

Collections in SpartanX: Organize Your Assets Like a Pro

Learn what collections are and how to create them with exposure type, asset types, and compliance frameworks like PCI and HIPAA. Group and manage your assets your way.

Written by SpartanX CS

Collections are the organizational backbone of SpartanX. They group assets logically — by exposure type, technology, compliance scope, or team ownership — giving you meaningful structure for your engagements, vulnerability management, and reporting.


What Is a Collection?

A collection is a named group of assets. It defines a scope — a set of targets that belong together for operational or compliance reasons. SpartanX ships with several default system collections representing common organizational structures:

  • Perimeter Network — public-facing network assets

  • Public Web Applications — externally accessible web apps

  • Public APIs — externally exposed API endpoints

  • Cloud Infrastructure — GCP, Azure, AWS, or Oracle Cloud assets

  • AI Services — chatbots, AI agents, and AI-powered systems

  • Internal Infrastructure — intranet applications and internal services

You are not limited to these defaults. Collections are fully customizable to match how your organization is structured.


Creating a New Collection

To create a collection, click "New Collection" and fill in the following fields:

  • Name — a descriptive label for the collection (e.g., "PCI Cardholder Environment" or "EU Branch Infrastructure")

  • Description — optional context about what this collection contains

  • Exposure Type — select one of three options: Externally Facing (internet-connected), Internally Facing (not exposed externally), or Air-Gapped (isolated from the IP network layer)

  • Asset Types — optional classification such as web applications, APIs, cloud systems, or AI services. This is for organizational clarity, not enforcement.

  • Compliance Framework — flag if the collection is in scope for a specific regulation, such as PCI DSS, HIPAA, or SOC 2.

Once created, the collection appears in your list. A freshly created collection will show no vulnerabilities or security metrics — those populate after you run an engagement against its assets.


Managing Collections

Collections are flexible. You can:

  • Search for collections by name

  • Rearrange and reorganize them as your environment evolves

  • Delete collections that are no longer needed

  • Move assets between collections

When you open a collection, you can view its compliance framework, creator, and security metrics — once engagement data is available.


What's Next

With a collection created, the next step is adding assets to it. The following section walks through how to associate assets — IP addresses, domains, APIs, web apps, and mobile app binaries — with a specific collection.

Did this answer your question?