01
Discover
Map the public footprint associated with your domain — domains, subdomains, certificates, IPs, technologies, and services.
- Domains
- Subdomains
- Certificates
- IPs
- Technologies
- Services
External security intelligence
SecurityPosture continuously maps your public digital footprint, analyzes your external security posture, and tells you what deserves attention — before someone else finds it.
No credentials required · Passive external analysis
External attack surface
example.com
4
Assets
6
Tech
1
Findings
Discovery
A passive discovery pass already reveals a surprising amount about your public footprint.
Target: acme.com
Public footprint
Workflow
Four steps that turn public signals into a prioritized list of what actually matters.
01
Map the public footprint associated with your domain — domains, subdomains, certificates, IPs, technologies, and services.
02
Evaluate publicly observable security signals across DNS, TLS, HTTP, email, headers, and configuration.
03
Correlate observations into meaningful findings — explained in plain English, not raw scanner noise.
04
Get prioritized recommendations instead of another endless security dashboard.
Features
Discovery, analysis, prioritization, and monitoring — designed as one coherent product, not a pile of scanner outputs.
Know what is publicly exposed.
Discover domains, subdomains, certificates, public endpoints, and other externally observable assets.
Know what powers your public infrastructure.
Identify frameworks, hosting providers, CDNs, analytics platforms, SaaS integrations, and other technologies.
Understand your domain configuration.
Analyze DNS, SPF, DKIM, DMARC, CAA, MX, nameservers, and TLS certificates.
Analyze publicly observable web security controls.
Check HTTPS, HSTS, CSP, security headers, cookie attributes, and TLS configuration.
Understand what your company exposes publicly.
Surface relevant documents, repositories, technology references, and public-facing services.
Turn hundreds of observations into a short list of actions.
Severity-ranked findings so your team knows what to fix first.
3
High
7
Medium
14
Low
Security information in plain English.
Instead of "DMARC p=none", see: Email impersonation protection is not fully enforced — and why that matters.
Your security posture changes every day.
Detect new subdomains, technologies, certificate changes, DNS shifts, and new public services.
Report preview
Scores, category breakdowns, and priority findings — animated into view the way a real scan would populate.
SecurityPosture
acme.com
Last scan: 2m ago
0
Posture score
0
Assets
0
Technologies
External posture
Priority findings
High
Public staging environment
High
Email authentication needs attention
Medium
Unnecessary public service
Attacker perspective
SecurityPosture doesn't need access to your internal systems to answer an important question: what does the outside world already know about you?
Your view
Outsider's view
SecurityPosture connects the dots.
Evidence-based AI
Deterministic collection and security rules produce findings. AI turns those findings into clear language and next steps.
Observed
No DMARC enforcement detected
Finding
Email security requires attention
AI explanation
Attackers may have an easier time spoofing your domain in certain circumstances.
Recommendation
Review and strengthen your DMARC policy.
Continuous monitoring
SecurityPosture continuously watches for meaningful changes to your public footprint.
Monday
api.example.com discovered
Tuesday
New certificate detected
Wednesday
Security header changed
Thursday
New SaaS technology detected
Friday
Issue resolved
Who it's for
Know what you've exposed before customers, investors, or security reviewers ask.
Understand changes to your external infrastructure without manually tracking every asset.
Maintain an always-current view of your organization's external security posture.
Voices
Engineering, security, and founders using SecurityPosture to understand what the internet already sees.
“We thought we had two public properties. SecurityPosture showed staging, docs, and a forgotten API host before our SOC 2 reviewer did.”
Maya Chen
Head of Engineering · B2B SaaS · Series B
Boundaries
Clear product boundaries build trust — for your customers and for the teams you ask to run a scan.
What we do
What we don't do
Security & privacy
No credentials required for basic scans. We don't claim certifications we haven't earned — we ship clear controls you can evaluate.
External analysis starts from your domain alone — nothing to install or hand over.
Scan data is protected in transit and at rest with modern encryption practices.
Workspace-scoped access so only the right people see your posture reports.
Each analysis runs in isolation so one customer's scan never bleeds into another.
Clear controls over how long scan history and findings are retained.
Track who initiated scans and accessed reports for accountability.
Pricing
Pricing for continuous monitoring will expand as the product ships. The first value is clear: see what the internet already sees.
$0
Run an external scan and see your public footprint.
Coming soon
Continuous change detection across your external assets.
Custom
For orgs that need shared workspaces and reporting.
FAQ
Get started
Enter your domain and discover your external security posture in minutes.
No credentials required · Passive external analysis
Start with a free external analysis →