Ribbon Icon Celebrating 27 Years – Announcing the new GeoTrust Horizon® platform. Learn More
Home Icon > Resources > Articles > Knowledgebase > How Does Vulnerability Manager Handle Data?

How Does Vulnerability Manager Handle Data?

Overview

GeoTrust Vulnerability Manager needs access to certain system information so it can identify vulnerabilities, missing patches, insecure configurations and other security risks. Because this can include security-sensitive details about a server, the scanner is designed to collect only the information needed for vulnerability detection, assessments, and reporting.

What Data Is Accessed During a Scan?

The exact data accessed depends on the type of scan being performed (i.e., GeoTrust Vulnerability Manager use cases).

For an external scan, the scanner assesses the public-facing IP address from the outside. This may include checking exposed services, open ports, software banners, SSL/TLS configuration, web server responses and other externally visible security signals.

For an internal agent-based scan, the installed agent collects system and security metadata from the server. This can include details such as:

  • IP address, hostname and operating system
  • Installed software and software versions
  • Open ports and network posture
  • Running services and processes
  • Patch and update status
  • Registry or package information, depending on the operating system
  • Security-relevant configuration settings
  • Environment and file metadata required to support vulnerability detection

This information is used to determine whether known vulnerabilities or insecure configurations are present on the server.

How Scan Data Is Protected

Scan data is transmitted securely to the vulnerability management platform for processing and reporting. Where an internal agent is used, the agent connects outbound over HTTPS, so customers do not need to open inbound firewall access for scan data to be reported.

Scan data is protected using security controls designed to keep customer environments separate and secure. This includes encryption, audit logging and monitoring.

Some scan information may be stored temporarily while a scan is running or while results are being processed. This data is handled securely and is only used to complete the scan, generate results and support vulnerability reporting.

What the Scanner Does Not Access

GeoTrust Vulnerability Manager is not designed to collect customer business data, application records, documents, emails, database contents or personal files.

The scanner focuses on technical and security-relevant information needed to assess the server. This may include system metadata such as usernames, hostnames, file paths, environment values or configuration names where they are relevant to vulnerability detection.

Summary

Vulnerability Manager, as part of the GeoTrust Horizon platform, collects the technical information needed to check a server for vulnerabilities and help customers understand what needs to be fixed. The data collected is limited to security assessment and reporting, and is protected during transmission and processing.