EU-hosted · Passive · Read-only

Know how secure your
business is. Continuously.

Your company's digital perimeter, continuously monitored — without a security team. First results in 6 minutes.

From €299/mo · EU-hosted · No installation · Cancel anytime

ASM — example.com · Last scan 2 hours ago
0/100
Moderate risk
Requires attention
Findings requiring action
Redis database exposed to the internetCriticalFix →
SPF record missing — email spoofing possibleCriticalFix →
TLS certificate expires in 8 daysHighFix →
DMARC p=none — no enforcementMediumFix →
2
Critical
4
High
23
Subdomains
HSTS on
No installation
EU-hosted · GDPR compliant
Passive — reads public data only
ISO 27001 & NIS2 support
First results ~6 min
How it helps

Three questions,
answered immediately.

When the dashboard opens you know instantly — no training, no security expert needed.

01
How secure are we?
One number tells it all. Security Health Score 0–100 — weighted, prioritised, plain language. No jargon.
Score 74 — Moderate
02
Is anything urgent?
Critical findings surface first. No technical monologue — a clear, prioritised action list every time.
Redis exposed to the internet — fix now
03
What do we need to do?
Every finding includes a plain-language remediation guide. No terminology — a concrete next step.
Add SPF record to DNS settings
How it works

Four steps. Zero configuration.

No agents, no firewall changes. Type your domain — get results.

1

Add your domain

Type one address. example.com. Under 30 seconds.

2

We scan automatically

Subdomains, ports, certificates, GitHub leaks. Passively, read-only.

3

Get a clear report

Prioritised list — critical first. Remediation guide included.

4

Alerts on changes

New service found — alert. Score changes — alert. PDF for management.

What we detect

Everything an attacker
sees — you see first.

Continuous, passive monitoring from nine sources. All read-only, all automatic.

Subdomain Discovery

Certificate Transparency logs and 70+ DNS prefixes. All subdomains found automatically.

Open Ports

17 risk ports: SSH, RDP, Redis, MySQL, PostgreSQL, MongoDB, Elasticsearch and more.

TLS & Certificates

Expiry warnings at 14, 30 and 60 days — before your customers notice.

DNS Security

DMARC, SPF and DKIM — the foundation for preventing email spoofing and domain hijacking.

Cloud Storage

AWS S3, Azure Blob, GCS — public listing and sensitive files exposed.

GitHub Secrets

19 key patterns from public repositories. API keys, certificates, connection credentials.

Admin Interfaces

Login pages and management panels on the internet identified as primary attacker targets.

Subdomain Takeover

CNAME chains to unclaimed services. 19 service fingerprints — Heroku, GitHub Pages etc.

Security Headers

HSTS, CSP, X-Frame-Options and Referrer-Policy checked on every subdomain.

Product preview

Dashboard built for
non-security professionals.

The CEO understands it. The CTO loves it. The security expert trusts it.

Overview
Findings
Domains
Compliance
Reports
example.com
Critical findings
2
Requires immediate attention
Security Health Score
74/100
Moderate — trend improving
Monitored domains
3
23 subdomains discovered
Last scan
2h ago
Next: ~4h from now
Priority queue
Critical and high findings first
2 critical
Redis database exposed (port 6379)
db.example.com · Found 3 days ago
SPF record completely missing
example.com · DNS · Found 7 days ago
TLS certificate expires in 8 days
api.example.com · TLS · Expires 31.7.2026
dev.example.com:22 SSH open to internet
dev.example.com · Port 22 · OpenSSH 8.4
Score trend
Last 8 scans
Mon
Tue
Wed
Thu
Fri
Sat
Sun
74
Lower is better — target below 30
Regulations

Regulators ask.
You have the answer.

NIS2, DORA, GDPR and ISO 27001 require a documented asset inventory and continuous monitoring. ASM produces these automatically.

NIS2 Art. 21

Network & Information Security

Requires documented ICT asset inventory, continuous monitoring and change management. In force from 18.10.2024.

Up to €10M or 2% of turnover
DORA Art. 9

Digital Operational Resilience

Financial institutions: complete ICT mapping and continuous visibility into internet-facing services. In force since 1/2025.

National supervisory authority sanctions
GDPR Art. 32

Technical & Organisational Safeguards

Open database ports or leaked access keys must be documented as risk for personal data. 72h breach notification obligation.

Up to €20M or 4% of turnover
ISO 27001:2022 A.8.8

Technical Vulnerability Management

Auditors expect a continuous process, systematic prioritisation and verifiable remediation. ASM produces direct audit evidence.

Certification suspension
Pricing

Built for SMBs.
Priced accordingly.

No long-term contracts. No surprises. Monthly, cancel anytime.

Starter
One company, one domain. Perfect to get started.
€299/mo
  • 1 root domain
  • Daily scans
  • Email alerts
  • PDF & CSV reports
  • ISO 27001 & SOC 2 support
  • Exposure timeline
Get started
Most popular
Pro
Attack path analysis shows what findings could lead to.
€599/mo
  • 3 root domains
  • All Starter features
  • Attack path generation
  • Executive reporting
  • NIS2 & DORA mapping
  • Teams / Slack integration
Get started with Pro
Enterprise
Tailored solution for larger needs.
Contact us
  • Unlimited domains
  • Custom SLA
  • On-prem option
  • SIEM integration
  • Dedicated account manager
  • Custom onboarding
Contact sales
FAQ

Common questions

Is this legal?
Yes. We only read what's already publicly visible on the internet. We don't try passwords, don't send payloads, don't touch target systems. Our user-agent always identifies who we are.
How does this differ from penetration testing?
A pentest is done once or twice a year — as soon as it's finished, infrastructure continues to change. We monitor from the outside, continuously, automatically. Pentest and ASM complement each other.
Will it flood me with unnecessary alerts?
No. Every finding is validated before it's shown. A critical alert is sent at most once per day per finding. Low-priority findings appear on the dashboard, not in your inbox.
Does this help meet NIS2 or DORA requirements?
Yes. NIS2 Art. 21 requires asset inventory, continuous monitoring and change management — ASM produces these automatically. The dashboard serves as direct audit evidence.
Is data stored in the EU?
Yes. All data is stored on EU-based servers. GDPR compliant. Data Processing Agreement available on request. No US dependencies.

Your attack surface is public.
Your visibility into it isn't.

Start monitoring today. First results in 6 minutes.