Skip to content

Security stewardship for your public estate

We map everything you expose to the internet and check it every day against what attackers can do now, so you don't have to wonder.

One flat monthly fee. A map of every public asset you own, re-checked as attack techniques change, and a record of what was verified and when. Security decisions, kept in order.

The problem

Your attack surface grew while nobody was watching.

Nobody has the list
Public estates grow by accretion. Most organizations cannot produce a current inventory of the hostnames they own.
Annual tests go stale
A penetration test is a snapshot. The report is out of date the week after it is delivered.
Scanners produce noise
Thousands of undifferentiated findings, no narrative, no owner, and no sense of what to fix first.

Method

Four stages, in this order, every time.

  1. Stage 01

    Authorize

    You provide a written asset inventory and a scoped engagement. We configure it as a code-enforced allowlist before anything runs.

  2. Stage 02

    Assess

    A fixed probe plan collects evidence across HTTP, TLS, DNS, WAF, and a focused port profile. Coverage is tracked, so nothing silently narrows.

  3. Stage 03

    Report

    You get a reviewed report with severity, stable finding IDs you can track across scans, and clear remediation ownership.

  4. Stage 04

    Watch

    DNS drift is checked every 30 minutes and the full control catalog runs every day. Checks are added as attacker techniques change, each one dated and explained. You are paged only on actionable change: a new dangling CNAME, an opened zone transfer, a dead nameserver.

Coverage

What we check

Every probe returns structured evidence. Each report carries a manifest of exactly which of these ran.

http_probe
Security headers, redirect chains, cookie flags, technology fingerprinting, certificate verification.
tls_check
Certificate validity and expiry, weak protocol support, and known protocol-level flaws.
dns_check
SPF, DMARC, and DKIM across common provider selectors, plus MX, NS, and TXT records.
dns_health
Dangling CNAMEs and subdomain takeover signals, lame nameservers, zone transfer exposure, CAA, DNSSEC.
waf_detect
Web application firewall presence and vendor identification.
port_scan
Open ports and service versions across a focused, approved port profile. No broad, UDP, or stealth scanning.

Guarantees

Built to refuse work you did not authorize.

An assessment tool that can be talked into scanning the wrong target is a liability. These guardrails are structural, not advisory.

  • Scope is enforced in code, not by prompt

    Every target is checked against your written inventory before a socket opens. An empty scope denies everything. Subdomains are never assumed from a parent domain.

  • The model only exercises judgement

    Deterministic probes collect the evidence and code assigns severity. The language model prioritizes and narrates what has already been found and graded.

  • It fails loud

    A scan that did not complete is never delivered as a finished assessment. A failed required probe blocks the report rather than quietly narrowing coverage.

  • The boundary is written down

    No exploitation, credential attacks, phishing, denial of service, or persistence. Higher-risk actions require a separate, signed, single-use approval.

Boundary

What is and is not in scope

Stated plainly, because a vendor who overstates coverage is the more expensive problem.

Covered today

  • External attack-surface inventory and monitoring
  • Public web and network recon and validation
  • DNS and domain security, including takeover signals
  • TLS and certificate posture
  • Client-ready reporting and alert delivery

Not covered

  • Cloud and SaaS configuration posture
  • API authorization testing and schema fuzzing
  • Internal network and authenticated testing
  • Red teaming and adversary emulation
  • Social engineering and phishing
  • Malware analysis and source code review

Start here

Two questions we will answer for free.

  1. Can any certificate authority issue a certificate for your domain? A missing CAA record means yes.
  2. Can your DNS responses be forged? Without DNSSEC, an on-path or cache-poisoning attacker can.

Both are publicly observable, take minutes to check, and require no access to your systems. We will tell you either way.

We assess only estates you authorize in writing. No probing happens before a signed engagement.