Compliance evidence
Audit evidence as a side effect of monitoring.
Auditors don't just ask whether you monitor your external infrastructure; they ask you to prove it operated all year. Attack Surface Scan produces that proof by running: scheduled scans with full history, an alert trail, and dated PDF reports you hand over as-is instead of reconstructing the past the week before fieldwork.
No card required to start. Plans from $25/month; first scan in about a minute.
Where the evidence lands
SOC 2
The Common Criteria expect you to monitor infrastructure for vulnerabilities and configuration change (CC7.1) and to evaluate that monitoring (CC4.1). A year of scheduled scans, alerts and resolved findings is that control operating, across the whole period, not just the week before fieldwork.
ISO 27001
Annex A 8.8 asks how you manage technical vulnerabilities; A.5.7 asks where threat intelligence comes from. Scan history plus CT-log discovery and lookalike-domain watching answer both with dated records instead of a described process.
Security questionnaires
"Do you perform external vulnerability scanning?" Attach last week's PDF, with scope, findings, severities and date on the first page, instead of a paragraph the assessor takes on faith.
Point-in-time proof
Every scan is kept, and any of them exports as a branded, dated PDF. When an auditor asks what your posture was in March, you send March's report.
Why continuous beats point-in-time
The audit question is never "were you secure on scan day"; it's "does the control operate". A scanner you run before the audit produces one data point; a schedule produces a record.
History is the control
Scheduled scans, the changes they caught, and the findings that got resolved form a timeline. That timeline is what "monitoring operated effectively" looks like as evidence.
Alerts prove response, not just detection
The alert trail shows issues were surfaced when they happened, and the findings you accepted with a review date show risk decisions being made deliberately.
Honest scoping
Attack Surface Scan is monitoring evidence for a handful of controls, not a compliance program. It does not replace a penetration test and is not a PCI ASV scan. It covers the "continuous external monitoring" row of the controls matrix, and covers it well. Control-by-control mapping →
The gap most programs have
Plenty of stacks have internal scanning and no external eye at all: the gap assessors increasingly ask about. Why external scanning is the missing row →
Common questions
Is Attack Surface Scan itself SOC 2 certified?
Attack Surface Scan produces evidence for your audit; it does not confer certification, and we don't claim its reports are a compliance program. For questions about Attack Surface Scan's own security posture, ask us directly; support reaches a person.
Will auditors accept these reports?
Auditors accept evidence that a control operated: dated, scoped, and covering the period. The scan history and PDF exports in Attack Surface Scan are exactly that shape for external monitoring controls. Your auditor decides sufficiency, but most treat continuous scanning with an alert trail as stronger evidence than an annual one-off.
Does this replace a penetration test?
No. A pentest is humans attempting exploitation at a point in time; Attack Surface Scan is continuous passive observation. SOC 2 and ISO 27001 programs typically want both; they answer different questions.
Start the record now.
Evidence for the audit period starts accumulating with your first scheduled scan.
Start your 7-day trialNo card required to start. Cancel any time.