One-time audits of your public attack surface, brand & email security, and shadow cloud infrastructure. Plain English. Real remediation. Every finding mapped to NIST, MITRE ATT&CK and CISA KEV. No agents, no meetings, no consultants.
Free, full-depth report — no card, no paid tier. Free account required, and you'll only scan domains you're authorized to assess.
Nearly every intrusion starts with something reachable from the public internet. Attackers enumerate that surface continuously — most companies have never enumerated it once. Discovery comes before patching, pen-testing and insurance questionnaires, because all of them assume you already know what you own.
Two focused sections. Every finding is scored, evidenced, and mapped to a fix and to the control frameworks you report against.
Each risk is labeled with the control frameworks your auditors, insurers and board already use — so nobody on your side has to translate a scanner result into a control reference.
Findings map to the CSF function and category they answer — an inventory of active corporate subdomains lands under asset identification — so the report drops straight into a gap assessment instead of starting one.
Each exposure carries the technique an attacker would actually use against it, so a finding reads as an attack path your team can reason about — not as another scanner line item.
Every CVE we surface is checked against the live CISA KEV catalog. A match is escalated to Critical automatically, so anything being exploited in the wild right now rises to the top of your list.
A report-level coverage roll-up shows which framework functions the audit touched, and the alignment travels with you into the PDF and HTML exports you hand to auditors.
Every check, every finding, every export — free with an account. No paid tier, no locked report, no sales call. The project runs on voluntary contributions from the people it helps.
Full-depth audit: brand impersonation, credential exposure, perimeter and cloud intelligence, source-code exposure, framework alignment, playbook and exports.
Caps keep third-party lookup costs survivable. They are not an upsell — nothing is held back from a free account.
Contributions cover the lookups and hosting, and unlock continuous coverage: weekly checks, monthly re-audits, change detection and trends.
Run a full audit now — it takes about a minute, costs nothing, and the whole report is yours.