The inventory lives in the app at Inventory (/app/inventory).
Asset types
| Type | What it is |
|---|---|
| Host | A hostname under one of your verified domains: the apex, saved subdomains, discovered subdomains. |
| IP address | An address your hosts resolve to, with its network owner (ASN) and, where it matches published ranges, the cloud provider or CDN it belongs to. |
| Dependency | Third-party infrastructure your hosts rely on: a CNAME into a SaaS platform, a CDN, a hosted mail provider. Known vendors are classified here automatically. Listed so you know it exists; never scanned. |
| Candidate | Another registrable domain that looks related. Candidates are never scanned until you add and verify them. |
States
| State | Meaning |
|---|---|
| Approved | Yours and monitored. Hosts count toward your plan's hosts per domain. |
| Candidate | Found by discovery, awaiting your decision. For related domains this means verification. |
| Dependency | Third-party infrastructure you rely on but do not run. |
| Monitor-only | Tracked for inventory and change history without full scanning. |
| Dismissed | Not yours or not relevant. Discovery will not re-add it. |
A state you set by hand is never overridden by the system, and assets you have classified are never pruned.
Discovery sources
Discovery only runs for registrable domains you have verified, and only resolves names or reads public datasets. It never connects to a name outside a verified domain.
- Certificate transparency, read every 15 minutes: every certificate issued for your domain names hosts.
- Your own DNS records: MX, NS, SPF includes, the
wwwCNAME and 34 common SRV services under the domain. - DNSSEC zone walking, where the zone uses plain NSEC (not NSEC3), through
public DNS-over-HTTPS resolvers (
dns.googleandcloudflare-dns.com). - Web archives: the Internet Archive's Wayback Machine CDX index and the Common Crawl index, for hostnames that were public at some point. Queried weekly per domain, and always on a manual run.
- Links on your own pages, collected by the page crawl.
- A 150-name wordlist of common names (such as
vpn,staging,mail) resolved against public DNS. Wildcard DNS is detected, so a zone that answers every name does not flood the inventory.
Only names that resolve and sit under the verified domain are kept; they join the monitored set automatically, subject to your plan's hosts per domain and the domain's exclusion list. Discovery runs nightly as a background job per domain, with a time limit per source so one slow source never blocks the others. Run discovery now starts it on demand, up to twice per domain per hour.
Related domains need verification
Other registrable domains found in your certificates' names always become candidates. Ones found
in NS, MX, SPF or CNAME records, or in links on your pages, become candidates only when the name
looks related to yours; known vendors become dependencies instead. A candidate (say
example-payments.com in a certificate for example.com) is observed through
public data only. The inventory offers Add and verify, which starts the normal
ownership proof. This is the same boundary that keeps us from scanning anything you do not own.
Where your hosts run
Every IP is attributed to its network (ASN and organisation, from iptoasn.com) and, when it falls inside a provider's published ranges, to the cloud or CDN: AWS, Google Cloud, Microsoft Azure, Cloudflare, Fastly, Oracle Cloud, DigitalOcean and GitHub Pages. Akamai and some others are recognised by ASN. The inventory summarises hosts by provider and network, which answers "what runs where" for asset registers and vendor reviews.
Change history and pruning
Assets record when they were first and last seen. Additions and removals appear in the change
feed (asset.added, asset.removed, candidate.found) and in the
inventory's history, marked as made by a person or by the system. On plans with scheduled scans, a
discovered asset that has not been seen for 45 days is removed by the system. Hosts you exclude are
recorded as removed by a person, and discovery will not add them back.
Export and API
The inventory exports to CSV from the Inventory page (see
CSV exports) and is available through the REST API as
GET /v1/assets on Growth and above. The inventory's other endpoints are used by the app
only and are not part of the public API.