
See your company the way an
attacker sees it
Every new subdomain, every forgotten staging server, every leaked password grows your attack surface β usually unnoticed. We monitor it continuously and report what is new. Free initial check, monitoring from β¬249 per month.
The problem is not the attack. It is the time before it.
In mid-sized companies, months often pass between the moment a system becomes attackable and the moment somebody notices. In that window a staging system with production data sits on the internet, a certificate expires, an employee password circulates from somebody else's breach. Nobody did anything wrong β nobody was looking. Attack surface monitoring closes exactly that gap: it looks at your company continuously from the outside and reports changes, not inventory.
What we monitor
Everything reachable from outside β and everything circulating about you
Monitoring by the numbers
Low barrier to entry, immediate insight
How you start
From a domain to a first result within days
Name a domain
We only need your primary domain. No access to your systems, no installation, no agents β everything runs from the outside.
Attack surface discovery
Automated discovery of subdomains, services, certificates and cloud resources attributable to your company.
Manual review
A human looks it over. Automated results contain false positives and third-party systems β we sort both out before you see anything.
Initial report
What is reachable, what of it is risky, what needs doing now? Two pages for leadership, details for your engineers.
Continuous monitoring
From here we report changes: a new service, a new subdomain, a new breach hit. Existing inventory does not keep re-announcing itself.
Handover into the cycle
What monitoring flags as critical gets examined in depth in a penetration test. That is how visibility turns into evidenced security.
What monitoring does β and does not do
Attack surface monitoring is not a SOC. We draw that line deliberately.
What it does
- Visibility of everything reachable from outside
- Alerts on new exposure, not on unchanged inventory
- Leak monitoring for credentials on your domains
- Monthly report in presentable form
- Manual review instead of raw tool output
- A prepared basis for pentests and compliance evidence
What it does not do
- 24/7 monitoring with a response commitment
- Intervention in your systems or active blocking
- Monitoring of internal networks with no external exposure
- A replacement for endpoint protection or SIEM
- A guarantee that nothing is missed
- Automatic remediation of findings
If you need genuine 24/7 detection with a response commitment we will say so plainly and refer you to a specialist managed security provider. Monitoring with us means continuous visibility with regular expert review.
Why this is the highest-value entry point
Low price, immediate insight
You see what you did not know
Almost every initial check surfaces something nobody had on their radar β an old staging environment, a forgotten service, an access path from a 2021 project.
No project, no effort
No installation, no agents, no access to your systems. You name a domain, we deliver a result.
Closes the gap between tests
A pentest is a snapshot. Monitoring makes sure nothing appears unnoticed between two snapshots.
Evidence for NIS2 and CRA
Continuous detection is exactly what NIS2 expects for risk management and what the CRA presupposes for reporting capability. The report is dated and archived.
EU hosting
Operated exclusively in the EU, encrypted storage, GDPR-compliant processing. On-premise on request.
Monitoring pricing
Starting costs nothing β continuing costs less than one consulting day a year
Attack surface check
The free first look
- One domain
- Automated attack surface discovery
- Manual review of the findings
- Two-page PDF report
- No installation, no system access
- No obligation, no contract
Basic check
Deeper first check with platform access
- Everything in the free check
- Multiple domains and cloud resources
- Matching against known breach data
- Platform access for your team
- Trigger scans yourself
- Result history and status tracking
Ongoing monitoring
Continuous coverage
- Basic: one domain, monthly scan and report
- Pro (β¬599): up to five domains, weekly
- Alerts on new exposure
- Continuous leak monitoring
- Pro: 2 hours of analyst time per month
- Credited against the Security Cycle retainer
Frequently asked questions on attack surface monitoring
Technical, legal, organisational
No. Monitoring works exclusively from the outside β using the same means available to an attacker: public DNS data, certificate transparency logs, reachable services, publicly available breach databases. There is nothing to install and no credentials to hand over. That is precisely what makes the entry so easy.
Request your free attack surface check
One domain is enough. Within a few working days you receive a two-page report on what an attacker can see about your company today β no contract, no system access.