Continuous external vulnerability scanning

Continuous vulnerability scanning without the enterprise complexity

Verify a domain, uncover internet-facing risk, and give your team a clear remediation plan. Start with one verified target.

No credit card required · Ownership verification before scanning

How it works

From verified target to verified fix

  1. 01

    Verify scope

    Prove control of a domain and explicitly authorize each target before scanning begins.

  2. 02

    Monitor continuously

    Schedule bounded, non-destructive checks against the public assets you approved.

  3. 03

    Fix and prove

    Assign findings, verify remediation with a rescan, and share current evidence.

See your external exposure in one place

Monitor verified domains, DNS policy, TLS certificates, HTTPS redirects, and HTTP security headers from one operational view.

  • Explicit severity

    Every retained finding has a visible priority.

  • Verified scope

    Results stay tied to the target you authorized.

  • Current status

    Rescans keep remediation evidence up to date.

Fast activation

Verify a domain and launch a safe baseline scan without installing an agent.

Actionable priority

Combine catalog severity, verified scope, check outcome, and remediation context.

Continuous coverage

Schedule recurring scans and receive alerts when your exposure changes.

Verified remediation

Rescan on demand and preserve evidence that a finding was fixed.

Vulnerability management

From exposed asset to verified fix

A focused workflow for reviewing trusted findings, assigning remediation, verifying the fix, and preserving evidence.

Finding ownership

Assign issues, set due dates, and keep remediation context with the finding.

CriticalVS-1042

TLS certificate validation failed

app.northstar.dev:443

MCMaya ChenDue Friday

Authorized asset inventory

Keep verified domains, DNS policy, certificates, and approved HTTPS check state in one shared inventory.

Catalog-owned prioritization

Rank bounded configuration findings using server-owned severity and the verified target context.

Catalog severityCritical
Ownership proofVerified
Connection scopePublic
Evidence shapeBounded

Focused alerts

Send scan-completion and critical-finding email through the configured notification boundary.

@

Security email

VulnerabilityScan · now

Critical TLS finding detected

Certificate validation failed on app.northstar.dev

Review finding

Continuous monitoring

Schedule safe recurring checks and rescan on demand when a fix ships.

Weekly baseline

Active
MTWTFSS
Next scan Tue, 02:00 UTC
DNS
CAA
TLS
HTTP
Remediation workflow

Make the next security decision obvious

Keep findings, owners, due dates, evidence, and verification history together. Turn scanning into measurable progress.

Evidence stays attached

See the affected asset, approved check, bounded evidence, and risk signals.

Owners stay accountable

Assign findings to the people who can fix them and track status over time.

Reports stay current

Generate executive and technical evidence from the latest verified scan state.

Fixes stay verified

Run a remediation rescan and preserve proof that the exposure is gone.

What you get

Core controls to keep exposure work moving

Move from safe scanning to prioritized remediation and current evidence in one focused workflow.

Continuous coverage

Schedule recurring external checks across the assets your team verifies.

Asset coverage12 / 12
All verified assets monitored

Fast triage

Filter by severity, asset, check family, owner, and remediation state.

CriticalTLSOpen

TLS certificate validation failed

app.northstar.dev:443

Predictable pricing

Pay for monitored assets you explicitly add, with no discovery-based surprise charges.

Monitored assets

12 of 25

Discovery never creates surprise charges.

Security-first controls

Ownership verification, scoped policies, audit trails, and tenant-aware controls are built into the workflow.

Verified
Scoped
Allowed

Exposure insights

Track asset coverage, open findings, remediation progress, and risk trends at a glance.

Open risk

7

−42%

Safe scan engine

Rate-limited, non-destructive templates run only against explicitly verified targets.

safe-baseline / job-1842
Target ownership verified
Private ranges blocked
5 approved checks loaded
Checking HTTPS configuration…
Know what is exposed.
Know what is exposed.

Your first scan is one verified domain away

Three assets free for 14 days. No card required.

Start free