The inventory lives in the app at Inventory (/app/inventory).

Asset types

TypeWhat it is
HostA hostname under one of your verified domains: the apex, saved subdomains, discovered subdomains.
IP addressAn address your hosts resolve to, with its network owner (ASN) and, where it matches published ranges, the cloud provider or CDN it belongs to.
DependencyThird-party infrastructure your hosts rely on: a CNAME into a SaaS platform, a CDN, a hosted mail provider. Known vendors are classified here automatically. Listed so you know it exists; never scanned.
CandidateAnother registrable domain that looks related. Candidates are never scanned until you add and verify them.

States

StateMeaning
ApprovedYours and monitored. Hosts count toward your plan's hosts per domain.
CandidateFound by discovery, awaiting your decision. For related domains this means verification.
DependencyThird-party infrastructure you rely on but do not run.
Monitor-onlyTracked for inventory and change history without full scanning.
DismissedNot yours or not relevant. Discovery will not re-add it.

A state you set by hand is never overridden by the system, and assets you have classified are never pruned.

Discovery sources

Discovery only runs for registrable domains you have verified, and only resolves names or reads public datasets. It never connects to a name outside a verified domain.

  • Certificate transparency, read every 15 minutes: every certificate issued for your domain names hosts.
  • Your own DNS records: MX, NS, SPF includes, the www CNAME and 34 common SRV services under the domain.
  • DNSSEC zone walking, where the zone uses plain NSEC (not NSEC3), through public DNS-over-HTTPS resolvers (dns.google and cloudflare-dns.com).
  • Web archives: the Internet Archive's Wayback Machine CDX index and the Common Crawl index, for hostnames that were public at some point. Queried weekly per domain, and always on a manual run.
  • Links on your own pages, collected by the page crawl.
  • A 150-name wordlist of common names (such as vpn, staging, mail) resolved against public DNS. Wildcard DNS is detected, so a zone that answers every name does not flood the inventory.

Only names that resolve and sit under the verified domain are kept; they join the monitored set automatically, subject to your plan's hosts per domain and the domain's exclusion list. Discovery runs nightly as a background job per domain, with a time limit per source so one slow source never blocks the others. Run discovery now starts it on demand, up to twice per domain per hour.

Related domains need verification

Other registrable domains found in your certificates' names always become candidates. Ones found in NS, MX, SPF or CNAME records, or in links on your pages, become candidates only when the name looks related to yours; known vendors become dependencies instead. A candidate (say example-payments.com in a certificate for example.com) is observed through public data only. The inventory offers Add and verify, which starts the normal ownership proof. This is the same boundary that keeps us from scanning anything you do not own.

Where your hosts run

Every IP is attributed to its network (ASN and organisation, from iptoasn.com) and, when it falls inside a provider's published ranges, to the cloud or CDN: AWS, Google Cloud, Microsoft Azure, Cloudflare, Fastly, Oracle Cloud, DigitalOcean and GitHub Pages. Akamai and some others are recognised by ASN. The inventory summarises hosts by provider and network, which answers "what runs where" for asset registers and vendor reviews.

Change history and pruning

Assets record when they were first and last seen. Additions and removals appear in the change feed (asset.added, asset.removed, candidate.found) and in the inventory's history, marked as made by a person or by the system. On plans with scheduled scans, a discovered asset that has not been seen for 45 days is removed by the system. Hosts you exclude are recorded as removed by a person, and discovery will not add them back.

Export and API

The inventory exports to CSV from the Inventory page (see CSV exports) and is available through the REST API as GET /v1/assets on Growth and above. The inventory's other endpoints are used by the app only and are not part of the public API.