How it works
Nothing Is Touched Until It Is Proven Yours
Coverage reaches an asset in three steps, and the score reached in the second decides what happens in the third.
Nothing is installed anywhere, and no credential is ever held.
Find It. Prove It. Secure It.

Find it before they do
Discovery runs continuously against the root domains the customer authorizes, querying many independent sources rather than one scanner: Certificate Transparency logs watched live, cloud object storage enumerated across the public providers, and passive DNS, registration records and internet-wide scan data checked against each other. An asset enters inventory only once more than one source agrees it is real.

Prove it is yours
Several independent signals are scored in parallel and combined into one confidence score from 0 to 100, so no single signal pushes an asset into scope on its own. They fail differently: certificate lineage, WHOIS and RDAP data, DNS and SOA relationships, favicon hashes, JARM fingerprints, and address and domain reputation. Every score carries its reasoning, so an analyst can defend it when an owner disputes it.

Then look for the way in
Only assets in the confirmed band are actively probed, which keeps the platform away from infrastructure that may belong to somebody else. Within the confirmed inventory the assessment covers known vulnerabilities and the misconfigurations that carry no CVE at all: exposed management interfaces, default or missing authentication, open cloud storage, weak or expiring TLS, and missing SPF, DKIM and DMARC records, which are frequently the actual way in.
Confidence That Determines What Happens Next
A false positive in exposure management is almost never a detection error. It is an attribution error: a shared address, a parked domain or a hosting range swept into scope by resemblance. That failure costs more than a missed finding, because it reaches a report. So the decision is made deterministically, recorded with its evidence, and it governs the platform’s behavior from that point on.
| Confidence band | Score | What the platform does |
|---|---|---|
| Confirmed | 70 and above | Automatically in scope. Active assessment permitted. Alerts may fire. Findings are eligible for board and client reporting. |
| Likely | 40 to 69 | Automatically in scope with elevated review priority, and surfaced for analyst confirmation before it carries the same weight as a confirmed finding. |
| Suspicious | 10 to 39 | Held in the shadow-IT queue. Observed passively, never actively probed. An analyst decision is required to promote or discard it. |
| Unknown | Below 10 | Discarded from inventory. Logged for traceability so the decision is auditable, but not surfaced in any queue or report. |
A platform that promotes everything it finds will eventually probe infrastructure that is not the customer’s, and a platform that promotes nothing is a scanner with an inbox.
The four bands make the decision explicit, evidenced and reviewable, so the line between what is monitored and what is touched is a matter of record rather than of configuration drift.
Analyst decisions feed back into the engine. A contested asset resolved by an analyst seeds the auto-learning model, a false-positive mark stops the finding recurring as noise, and favicon and JARM baselines retrain on each tenant’s own confirmed assets, so accuracy improves with every scan rather than through manual tuning.
Every Change Tracked. Every Finding Driven to Resolution.
An attack surface is a timeline rather than a list, so every asset is versioned and alerting fires on what moved. Findings also end somewhere: each runs through an explicit state machine from new to resolved, risk acceptance carries a mandatory expiry date, and the work happens in Jira, Slack, Teams and email rather than in a portal nobody opens.

Nothing to Install. Nothing to Hand Over. No Blind Spots.
See Your Own Surface for Fifteen Days
Discovery and assessment run against your own root domains before any commitment, so the first thing you see is your own inventory rather than a demonstration environment.
Start a 15-day trial
