The complete inventory of everything your company exposes to the internet.
Our flagship service. Every domain, subdomain, service and certificate an attacker can see: found, validated and prioritized by someone who did this for global infrastructure.
The problem
Years of growth leave a trail: forgotten subdomains, exposed test environments, services "someone" spun up, expired certificates, shadow IT. Attackers automate the search for exactly that. You can’t defend what you don’t know you have.
What's included
- Exhaustive discovery: domains, subdomains, IPs, exposed services, ports, technologies, certificates, DNS, headers
- Manual validation of every finding, zero false positives in the report
- Prioritization by real exposure and exploitability, not generic severity
- Quick wins: what you can close this very week
- Benchmark against industry good practice
How we work
- Scoping and written authorization
- Discovery: specialized tooling + manual validation
- Analysis and prioritization with enterprise judgment
- Dual report (executive + technical) and walkthrough session
How fast you see value
- Day 1Scoping and written authorization. Nothing gets touched without it.
- Week 1Discovery. By the end of the week you know how many assets were missing from your list.
- Week 2Manual validation and prioritization. If something urgent shows up, you hear it that day, not in the report.
- Week 3Dual report, 30/60/90 roadmap and walkthrough session.
What you get
- Inventory of exposed assets: your new map
- Executive report for leadership
- Technical report with evidence and step-by-step remediation
- 30/60/90 roadmap
- Walkthrough session
What it evidences to an auditor
Everything ships dated and with evidence, mapped to the asset-inventory and external-exposure controls the common frameworks ask for. It is evidence for those controls, not the whole framework: we would rather tell you exactly what it covers.
What this service evidences
- Inventory of exposed assets, dated, with owner and evidenceISO 27001 A.5.9 · CIS Control 1 · PCI DSS 12.5.2 (scope) · DORA Art. 8
- External exposure findings with severity, evidence and step-by-step remediationISO 27001 A.8.8 · SOC 2 CC7.1 · CIS Control 7 · NIS2 Art. 21
- 30/60/90 roadmap as a risk treatment planISO 27001 cl. 6.1.3
- Proof of a periodic external assessment for a customer or an auditorvendor due-diligence questionnaires
What it does not cover
- The quarterly PCI DSS ASV scan (Req. 11.3.2): an approved scanning vendor does that, not us
- Internal controls: access and identity, encryption at rest, policies, HR
- Business continuity and recovery (BCP/DR)
- The certification itself. The auditor certifies; we give you the evidence for the external controls
Pricing
from USD 750
by surface size · typically 2-3 weeks
What this service is NOT
- Not an automated scan that forwards you a tool’s output
- Not an exploitation pentest. If you need one, we work with a specialized partner
Frequently asked questions
How is this different from the Security Snapshot?
The Snapshot is the quick X-ray; this is the complete map, with an inventory and a detailed technical plan.
How often should we repeat it?
Your surface changes with every deploy. Yearly at minimum; quarterly if your infrastructure moves fast, or as part of ongoing advisory.
Want to talk about your case?
A free, no-strings 20-minute intro call. Tell us your context and we’ll tell you honestly whether this service makes sense for you.