Skip to main content
Version: 1.0.0

Installation & Setup

Cert-IX is a cloud-hosted platform β€” there is nothing to install to get started. Sign in at app.cert-ix.com, and you can run external scans, track compliance, and use the dashboard immediately. The Quick Start Guide walks you through your first scan.

You only install software when you want deeper reach than a cloud service can have on its own β€” chiefly, visibility inside your private network.

What you might set up​

Your goalWhat to set upInstall required?
Scan internet-facing assets, use the dashboardNothing β€” just sign inNo
Discover & monitor internal / private-network assetsDeploy a scanner agentYes (a lightweight agent)
Automate scanning in scripts or CI/CDCreate a Scan API keyNo
Let your AI coding agent block vulnerable dependenciesAdd the DepCheck MCPNo (config only)

Deploy a scanner agent​

External scanning only sees what's exposed to the internet. To inventory and continuously monitor the assets inside your network, deploy a Cert-IX scanner agent β€” a lightweight, signed binary that registers with the platform and streams telemetry over an encrypted, Kafka-first pipeline.

Cert-IX offers a small family of purpose-built agents:

AgentPurpose
BitcollectorAsset telemetry β€” processes, ports, software inventory, system metrics
BitscannerHost & network vulnerability scanning and CVE detection
BitmapperNetwork topology β€” service discovery and network mapping
BitenforcerHardening policy β€” validates a CIS / STIG / PCI-DSS policy and shows exactly what applying it would change. v1 does not change hosts

Requirements​

  • A Cert-IX account with an active subscription.
  • Your Tenant ID β€” found in Settings β†’ Organization.
  • Root / administrator access on the target host.
  • Outbound HTTPS (port 443) to api.cert-ix.com β€” the agent's gateway and telemetry ingestion endpoints both live there.

Getting the binary​

There is no public download URL

The agent binaries are distributed through your Cert-IX account. There is no anonymous public download endpoint today, so treat any instruction to fetch one from a public host as out of date β€” ask your Cert-IX contact for the release directory for your platform.

Every release directory ships the binary, a CycloneDX SBOM, a cosign signature, a signed SHA256SUMS and the build provenance. Verify them before you run anything β€” those steps need no network access and apply to whatever directory you receive.

Fastest path: the dashboard wizard​

From the dashboard, go to Asset Management β†’ Devices and click Deploy Agent. The wizard generates copy-paste commands pre-filled with your Tenant ID for each platform.

Or install from the command line​

Once you have verified the release directory, a minimal Linux (x86_64) install is:

# From the verified release directory β€” see "Verifying your downloads"
install -m 0755 bitcollector-linux-amd64 /usr/local/bin/bitcollector

# Confirm what you have
bitcollector --version
Where the authoritative instructions live

This page is an overview. Verifying your downloads is the authority on obtaining a release and proving the bytes. The Agent Deployment Guide covers running the agent as a service, per-platform paths and configuration β€” its download commands predate this change and still name a public URL that does not serve the agent, so take the binary from your release directory instead.

Learn more:

  • Bits β€” what bitcollector and bitenforcer each do, and the evidence they produce.
  • Scanner Agents β€” what each agent collects and how they work.
  • Agent Deployment Guide β€” step-by-step deployment for every platform.
  • Agent Configuration β€” tune collection intervals, scopes, and policies.

Connect via the API​

No install needed. Create a scoped API key in the dashboard under Settings β†’ API Keys, then call the Scan API at https://api.cert-ix.com/scan-api/api/v1. See the Scan API β€” Getting Started guide.

Connect your AI coding agent (MCP)​

Point any MCP-capable coding assistant (Claude, Cursor, VS Code) at Cert-IX DepCheck to check dependencies for known vulnerabilities before they enter your codebase β€” no install, just client configuration. See the MCPs overview.

Next steps​

Need a hand? Email [email protected].

Was this page helpful?