Exposure & reachability/v1/exposure
Tells you which CVEs are actually running and network-reachable — not a raw CVSS list of everything installed — so you fix what an attacker can really reach first.
Risk scoring/v1/risk/asset/:id
Explainable, Tenable-VPR-style scoring that blends CVSS + EPSS + CISA KEV with asset context (in-memory, internet-facing, criticality) to produce a 0–100 score, band and a PATCH_NOW / STAGED / DEFER decision with the factors that drove it.
Device posture/v1/device-posture/scan
Grades each host on hardening — Secure Boot, TPM, BitLocker, ASR rules, Credential Guard — so you can drive measurable improvement across the fleet.