For security teams
Attack surface management without the enterprise contract.
The enterprise attack surface platforms do continuous discovery well, usually priced per asset and sold through a sales cycle. Attack Surface Scan covers what a lean security team needs: continuous discovery of what you expose, known vulnerabilities ranked by active exploitation, lookalike-domain watching, a change feed with the evidence inline, and API and AI-assistant access so your own tooling can drive it. Self-serve, from $25/month.
No card required to start. Plans from $25/month, flat; first report in minutes.
Built around how security teams actually work
Discovery you didn't have to seed
Systems under your domains are found continuously from several public sources and join monitoring on their own, so the inventory grows as the estate does, not when someone updates a list. Related domains are flagged for you to confirm, never assumed. Discovery in detail →
Exploited-first prioritisation
Known vulnerabilities in the software your systems reveal are ranked by whether attackers are using them now, with a dedicated view of everything on the U.S. government's list of actively exploited vulnerabilities. How matching works →
A change feed, not a snapshot
Every check is compared with the last: a new system, a service that started answering the internet, email protection that weakened, a safeguard that disappeared. The evidence is inline, so triage doesn't start with re-running the check.
Triage that sticks
Findings carry severity and evidence; accepted risk gets a reason and a review date, noise gets muted. What's left is a digest short enough that people keep reading it, which is the actual failure mode of most scanners.
Automation-first by design
The whole product for your AI assistant
A hosted MCP server gives Claude, ChatGPT, Codex, Cursor and other assistants the same scans, findings, change feed, triage and reports as the app, under the same ownership rules. You sign in with your normal account; there are no keys to manage. Setup guide →
Into your existing pipeline
Urgent changes reach Slack, Teams, PagerDuty, Jira or any tool that accepts a webhook the moment they are found. Findings and inventory export to CSV on every plan, and a REST API is included on Growth and above. Integrations · API reference
Hand-off prompts for remediation
Any report exports as a severity-ordered prompt for a coding agent, with the evidence and how to confirm each fix, plus a separate checklist for fixes that live with a registrar or in a vendor console instead of a code repository.
Scope you can defend
Checks run only against domains with proven ownership, and that proof is re-confirmed regularly. Deliberately: the platform cannot be pointed at infrastructure you don't control. How scanning works →
What you can show leadership
Coverage without a budget fight
One flat monthly price per plan and no per-asset metering, so discovering more of your estate never produces a bigger bill or a mid-year budget request.
Proof the program operates
Scan history, the alert trail, recorded risk decisions and a dated evidence pack mapped to common frameworks: what a board, auditor or insurer asks for. Compliance evidence →
Common questions
How does Attack Surface Scan compare to enterprise EASM platforms?
The discovery core is the same idea: continuous external discovery and change detection. What Attack Surface Scan doesn't have: per-asset pricing, onboarding projects or a sales cycle. What the big suites have that it doesn't: years of internet-wide scan history, discovery that starts from a company name, and deep ties into their own security suites. The side-by-side comparison and the articles go further.
Is the check depth enough for a security team?
The checks cover inventory and discovery, known vulnerabilities, exposed services, certificates and encryption, email and domain hygiene, website privacy and blocklist reputation. It is read-only by design, so it complements your penetration testing and internal scanning rather than replacing them. Every check, with its severity and fix, is in the checks reference.
Can we drive it entirely from our own tooling?
Close to it: the MCP server covers the workflow end to end (start checks, read findings and changes, triage, generate reports), webhooks push changes outward, and the REST API on Growth and above feeds your own reporting. The console is still there for the parts you want eyes on.
Stand up external monitoring this afternoon.
Verify a domain, connect your alert channel, and the change feed starts filling itself.
Start your 7-day trialNo card required to start. Cancel any time.