For IT & ops teams

The outside of your estate, watched around the clock.

Your team already runs the systems. What slips is the outside view: the certificate nobody tracked, the change nobody ticketed, the server someone set up and forgot. Attack Surface Scan watches everything your organization exposes to the internet and routes each alert to the channel your team already watches.

No card required to start. Plans from $25/month, flat; first report in minutes.

What slips through when everything is manual

Certificate renewals on a spreadsheet

Automatic renewal fails silently, and the one certificate tracked nowhere is the one that expires on a Saturday. The cost is an outage your customers see first.

Changes with no paper trail

A change to where your domain's website or email points is what an account takeover looks like from outside. Weakened email spoofing protection is how invoice fraud starts. Neither raises a ticket on its own.

Systems nobody registered with you

Departments sign up for vendors, vendors get pointed at your domain, and the estate grows entries that point at services someone else could claim.

Services that opened overnight

A database or remote-access tool answering the internet is worth knowing about today, not at the next quarterly review.

What changes with Attack Surface Scan

Expiry warnings that escalate

Warnings from a month out that escalate as the date approaches, an early alert when automatic renewal has quietly stopped, an alert for any certificate issued for your name by a provider you have not approved, and a watch on the domain registration itself. Certificate monitoring in detail →

Every change, with the before and after

Each scheduled check is compared with the last. The change feed shows exactly what moved, old and new side by side, so triage starts with evidence instead of investigation.

Forgotten systems found for you

New systems under your domains are found from public records, usually within the quarter hour, and join monitoring on their own up to your plan's limit. The inventory shows where each one is hosted. How discovery works →

Alerts where your team already looks

Email, Slack, Microsoft Teams, PagerDuty, Jira, or a webhook into your own tools. Urgent changes go out immediately; the rest arrive as one weekly digest. Risks you accept are recorded with a reason and a review date, so the digest stays short. Integration setup →

What you can show management and auditors

An inventory you can hand over

Every internet-facing system, where it runs and when it appeared, exportable to a spreadsheet for your asset register, a vendor review or an insurance application.

A trend leadership can read

A single 0 to 100 posture score and a dated PDF report show whether things got better or worse, without a briefing deck. The change history shows what was fixed and when.

Common questions

Is scanning safe to run against production?

Yes. Every check is read-only and behaves like an ordinary visitor: no logins, no attack traffic, no load testing, nothing installed. It only checks systems under domains you have proven you own. The full list of what it does and never does is in the documentation.

Can we monitor multiple domains and route alerts differently?

Yes. Every plan covers at least one verified domain, higher plans cover more, and alert channels can be scoped so the right subset of alerts reaches the right inbox, chat channel or ticket queue. See pricing for per-plan domain limits.

Does this replace our internal vulnerability scanner?

No. It covers the other side. Internal scanners see your network from inside; Attack Surface Scan sees what an outsider sees: the public surface where certificate expiry, unexpected changes and forgotten systems actually live. Most teams run both.

Put the estate under watch.

Verify your domains and let the schedule do the checking from tonight.

Start your 7-day trial

No card required to start. Cancel any time.