Exposure Alerts

How to choose which risk exposures and port categories notify you, from Settings → Notifications.

The Exposure Alerts card on Settings → Notifications controls which exposures Guard reports and which ones notify you. The card reads Get notified when exposures are detected.

Edit the settings

  1. Click Edit on the card. The button appears only for users who can manage settings.
  2. In Exposure Alert Settings, set each row:
    • Enabled turns detection on for that exposure or category.
    • Notify sends a notification when it is detected. It is available only while Enabled is on.
    • Severity sets the severity of the resulting risk: Exposure, Info, Low, Medium, High, or Critical. The default is Exposure.
  3. Click Apply. Guard shows Exposure alerts updated.

If the modal shows Failed to load exposure settings., click Retry before changing anything, so you don't overwrite your existing configuration.

Risk exposures

Name

Detects

Web Logins (SSO)

Login pages with an SSO provider detected (Okta, Azure AD, and similar)

Web Logins (Generic)

Login forms without SSO, such as admin panels and basic auth pages

LLM Chatbots

Exposed AI/LLM endpoints (Ollama, OpenAI-compatible, and similar)

MCP Servers

Exposed Model Context Protocol servers (tool and resource endpoints for LLM clients)

Port categories

Each category shows a risk badge. Critical categories are listed first.

Category

Risk

Services

Remote Access Services

Critical

SSH, RDP, VNC, Telnet

Databases Exposed to Internet

Critical

MySQL, PostgreSQL, MongoDB, Redis, MSSQL, Oracle, Elasticsearch, Cassandra, CouchDB, Memcached

File Sharing & SMB Services

High

SMB, NetBIOS, FTP, NFS, TFTP

Management Interfaces

High

SSH, RDP, Telnet, SNMP, VNC, WinRM, IPMI

Telecom Protocols

High

RADIUS, SIP, GTP, Diameter, SIGTRAN, H.323

Custom ports and protocols

Under Custom Ports and Custom Protocols, search for or type a port or protocol to add it. Each added item has its own Notify switch and Severity setting. Remove an item with its remove control.

Card summary

Line

Shows

Risk Exposures

The enabled risk exposures, or None

Port Categories

The first enabled categories, then +N more, or None

Custom

Your custom ports and protocols. Shown only when you have added any.

Severity Overrides

Exposures whose severity you changed. Shown only when there are any.