A collection is the top-level organizational unit in SpartanX. Collections sit above assets, and assets sit above vulnerabilities. This structure helps you mirror your real environment inside the platform so that testing, reporting, and prioritization all follow a logical business context.
Collections are useful because they let you group related systems together in a way that reflects how your organization actually operates. Instead of working with a flat list of targets, you can organize your environment into meaningful segments.
Common collection examples
Example collection | Typical assets inside it |
Perimeter | Firewalls, API gateways, edge infrastructure |
Internal Systems | Internal applications and supporting systems |
DMZ | Internet-facing systems separated from the internal network |
Cardholder Data Environment | Payment systems and PCI-scoped infrastructure |
Payment Microservices | Services involved in transaction processing |
HIPAA-scoped systems | Systems handling healthcare-related data |
Engagements that you have already run can also appear as collections, making it easier to navigate back to tested scopes and their associated findings.
What you can do inside a collection
Opening a collection gives you a summarized view of everything that belongs to it.
Area | What you can review |
Vulnerability summary | Severity distribution for findings in the collection |
Metadata | Collection details and context |
Assets list | Every asset grouped under the collection |
Top assets by risk | Highest-priority assets within that collection |
This makes collections useful for both navigation and prioritization. You can start at the collection level, understand overall risk, and then drill down into the most important assets.
Understand the hierarchy
Collections follow a simple three-level structure.
Collection β Asset β Vulnerabilities
This hierarchy keeps the platform easy to understand. You can move from a business or environment grouping, into a specific target, and then into the individual findings tied to that target.
Apply compliance at the collection level
One of the most valuable features of collections is bulk compliance tagging. You can assign one or more compliance frameworks to a collection, and that scope is then inherited across the assets and reporting tied to that collection.
For example, if an entire environment is in PCI scope, you can assign PCI DSS once at the collection level instead of manually applying the same context repeatedly later. Multiple frameworks can be applied at the same time, which is useful for environments that fall under several regulatory obligations.
Collections are the foundation of good organization in SpartanX. If you structure them thoughtfully, every later step, including testing, prioritization, and reporting, becomes easier.
