EASM
Attack Surface
Everything you expose on the Internet, mapped and monitored continuously.
Discovery starts from a seed, one domain name, and widens in waves: what Certificate Transparency logs have published, what DNS answers in both directions, what WHOIS ties to the same registrant, then what open ports confirm. This page details that mechanism: the sources queried, the refresh cadence, and what happens to false positives.
- in, the whole surface out
- 1 domain
- of multi-source discovery
- 14 plugins
- continuous monitoring, not a yearly audit
- 24/7
Features
What continuous mapping sees of your exposure.
Automatic discovery from a single domain
You enter your root domain, the engine unrolls the rest. 14 discovery plugins cross Certificate Transparency, six public subdomain sources, DNS, WHOIS and reverse WHOIS, port scanning and service fingerprinting to surface the shadow IT nobody ever declared. No agent to install, no IP range to provide.
A live inventory of every exposed asset
Subdomains, IPs and ASNs, ports and services, TLS certificates, detected technologies, cloud buckets and storage: every asset reachable from the Internet and tied to your domain surfaces in the inventory, with its history. It is the real perimeter your CMDB doesn't have.
CyberScore and attack-path graph
A CyberScore from A to F sums up the state of your surface and tracks its trajectory over time. Assets and findings are linked together (shared certificates, DNS, cloud relationships) to reconstruct exploitation chains, each path ranked by severity with a blast radius.
Continuous refresh, and the delta only
Periodic scans scheduled via cron or launched on demand from the interface and the API. At every pass the inventory is compared with the previous one: what surfaces is the delta (new subdomain, port that opens, service whose version changes, finding resolved), not 800 lines to re-read. The alert goes out the same day to Slack, Teams, Jira, GitHub, GitLab, PagerDuty or an HMAC-signed webhook.
Attack surface monitoring pricing.
Discovery
€0
- Attack Surface module included in the EASM offering
- In plain terms: the perimeter of a single domain name, 25 exposed assets at most.
- 10 scans / mo
- Multi-source discovery + more than 240 detection modules
- CVE correlation and prioritisation by real exploitability
- 2 AI-native validations / mo
- Email alerts, 1 user
- Free, no time limit and no credit card
Pro
€99 / mo
- In plain terms: 5 domain names, 250 tracked exposed assets, 5 people on the account.
- 100 scans / mo
- 30 AI-native validations / mo
- HMAC-signed webhooks (Slack, Teams, Discord, PagerDuty)
- Jira, GitHub, GitLab, Slack integrations
- PDF and CSV exports, API access (5 keys)
For businesses only, a company identifier is asked at the next step.
Business
€299 / mo
- In plain terms: 15 domain names, 1,000 tracked exposed assets, no cap on scans.
- 100 AI-native validations / mo
- SSO, RBAC and role management
- SIEM connector, custom integrations
- Email support, prioritised handling
For businesses only, a company identifier is asked at the next step.
Enterprise
On request
- In plain terms: the perimeter you set in the contract, no cap on domains or validations.
- SSO / SAML, SCIM provisioning
- Enhanced AI validation (extended reasoning)
- GDPR-compliant DPA, master agreement and NIS2 guidance
- A single point of contact: the pentester who runs it
VAT not applicable (art. 293 B of the French tax code)
How it works
From setup to the first alert.
- 01
The seed, and the boundary
The only mandatory input is a root domain name. It plays two roles at once: the starting point of discovery, and the boundary of what we allow ourselves to attribute to you. Before the first pass you also set the maximum rate per host and the headers or cookies to attach to requests, enough to get through a WAF without waking it or to lift a geographic restriction.
- 02
Passive sources, before touching anything
The first wave generates no traffic towards you. Certificate Transparency first: every issued certificate publishes the names it covers, which gives away internal subdomains as soon as they get TLS. Then six public enumeration sources, DNS records, WHOIS and reverse WHOIS to tie other domains to the same registrant, and ASN data. By that point we already know what an attacker can learn about you without sending a single packet.
- 03
Active confirmation, non-intrusive
The second wave verifies what the first one assumed: name resolution, port scanning, service and version fingerprinting, vhost enumeration, web crawling, cloud storage detection across S3, Azure and GCP. No exploitation is replayed, no destructive payload is sent, redirects are disabled and a three-layer anti-SSRF guard stops the scanner from wandering into an internal network. A confirmed asset can open a new wave through its certificate or its ASN, until nothing new surfaces.
- 04
The next pass, and what changed
Every new pass is compared with the previous one. Assets and findings are deduplicated and reconciled: what already existed keeps its history and its first-detection date, what is no longer reproduced flips to resolved, and you only get what moved. The cadence is yours (cron or manual launch) within the plan limits: 10 passes a month on the free tier, 100 on Pro, no cap on Business.
Benefits
What a living inventory changes in your daily work.
Discovery that widens on its own
Discovery works in waves. The first one never touches your infrastructure: it queries Certificate Transparency logs, where every certification authority publishes the names covered by a certificate it issues, including the staging subdomain nobody declared. Add six public enumeration sources, DNS in both directions, WHOIS and reverse WHOIS to tie other domains to the same registrant. The next wave confirms what was found: name resolution, port scanning, service fingerprinting, vhost enumeration, web crawling. A confirmed asset becomes a seed again through its certificate or its ASN, and the wave after that starts from there. That loop is why the result always overflows the official inventory: nobody remembers to declare an asset, but a certification authority publishes it automatically.
Track a trajectory, not a snapshot
A yearly audit gives you a snapshot that is already stale the next day. Here the inventory stays alive: periodic or on-demand scans, history per asset, change detection, and a CyberScore from A to F to see whether your surface is improving or drifting. You don't discover a forgotten asset six months after it opened; the alert lands the day it appears, where your team already works.
A timestamped trail, not a screenshot
What an auditor asks for is not an inventory, it is proof the inventory is kept. So every asset carries its first and last detection date, every scan leaves its delta, and the CyberScore keeps its history: enough to show a six-month trajectory rather than a state as of the meeting date. PDF and CSV exports are done by section, which saves attaching 40 pages to justify one point. This is the raw material for the mapping part of Article 21 of NIS2, not the whole of compliance: governance, incident response and supply chain remain yours.
Overview
The platform in pictures.




Why own2pwn
Why this mapping is not one more scan.
What we refuse to attribute to your perimeter
A map is worth what its attribution is worth. An asset wrongly tied to you is an alert that does not concern you, and after three of those, a console nobody opens. So an asset only enters your inventory through a verifiable chain from a domain you declared: a certificate covering the name, a DNS record pointing to it, a shared WHOIS registrant, a cloud relationship. No attribution by name resemblance, no whole IP block added because the neighbour looks like you.
A closed false positive does not come back next pass
Detection is automated: nobody re-reads findings by hand before they reach you, so we do not promise zero false positives (human verification is the pentest, a separate offering). What we do hold is that noise does not pile back up. Findings are deduplicated from one pass to the next and reconciled with the previous state: a known finding does not fire another notification, and a finding no longer reproduced flips to resolved instead of sitting in the pile.
You set the cadence and the footprint
A scan scheduled via cron, a scan launched by hand from the interface or the API, or both. Between two passes nothing runs against your infrastructure. During a pass the per-host rate is capped and adjustable from 1 to 1000 requests per second: you arbitrate between a fast map and a near-zero footprint on a sensitive environment, without negotiating a maintenance window with the ops team.
Your exposure data stays under European law
The inventory of an attack surface is exactly the document you do not want leaving the building: it says where to hit. So it stays hosted in the EU, under European law, GDPR compliant, with strict per-customer isolation at the database level. Handing it to a US vendor exposes it to extraterritorial access requests, which is hard to defend in front of a NIS2 auditor.
Frequently asked questions
Your questions about attack surface monitoring.
What is the external attack surface, concretely?
How do you discover my assets from a single domain?
Do you detect cloud assets (AWS, Azure, GCP)?
How often is my surface re-scanned?
What is the CyberScore?
What is the attack-path graph for?
Could the scan disrupt my production?
How does this module help my NIS2 compliance?
Is there a minimum term, and how do I cancel?
Do I need a credit card for the free plan?
How long between payment and actual access?
Can I change plan mid-subscription?
Go further
EASM: the complete guide
Definition, step-by-step workings, and the difference with a scanner or a pentest.
Read →Asset discovery in practice
Subdomain enumeration, ASN, ports and cloud assets to map your surface.
Read →Recon via Certificate Transparency
Tying unknown assets to your perimeter through shared certificates.
Read →Subdomain takeover explained
How a forgotten subdomain turns into a takeover, and how to detect it.
Read →EASM and NIS2 compliance
Mapping your external attack surface to meet NIS2 Article 21.
Read →Want to see your attack surface?
One root domain is enough to start the mapping. To talk it through first, a reply lands within 24 hours.