A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.
All compliance →Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.
All security →To the people you sell to, raise from or answer to.
All industries →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →You cannot defend what you have forgotten you own. We find everything your company has exposed to the internet, watch it for change and leaked credentials, and rank what we find by whether an attacker could actually use it, so your team fixes the right thing first.
Get startedMost breaches start with something the owner did not know was exposed: a forgotten subdomain, a staging box, an open admin panel, a credential in a dump. We keep the outside view of your company current so those do not sit unnoticed.
We map your domains, subdomains, hosts, cloud endpoints, APIs and exposed services from the attacker's side of the firewall, and keep finding the new ones as your team ships, so the inventory is never a year out of date.
We watch for your credentials in breach and infostealer dumps, your brand named on ransomware and extortion leak sites, and look-alike domains registered to impersonate you, and surface each as a tracked finding instead of a raw feed.
When a new host appears, a port opens, a certificate lapses or a service version changes, you hear about it close to when it happens, not at the next annual test.
Discovery produces a long list. We rank it by whether an attacker could actually use each item against you, not by severity label alone, so your team spends its time on what matters.
Every finding gets an owner, a fix and a target date, tracked to closed in your portal with counts you can show a buyer or a board.
Clean reporting that doubles as SOC 2 and ISO 27001 evidence of continuous monitoring, so the same work serves your audit.
A scanner checks the assets on your list. Attack surface management is what finds the assets that never made the list, and feeds them into the scan. A point-in-time penetration test then goes deep on what matters most. The three fit together:
Attack surface management keeps the inventory and the exposure current. Vulnerability management scans and tracks the known assets to closed. Penetration testing proves, by hand, what an attacker could do with the highest-risk findings. Many teams start with discovery because it is the fastest way to learn what they are actually defending.
If you work with vendors whose exposure is your problem too, our third-party risk service applies the same outside view to them. And if you need someone to own all of this end to end, our fractional CISO service can run it.
On the compliance side, a documented monitoring and readiness position can take real money off an audit quote, as in our cost audit case study. And it is not only SOC 2 and ISO 27001: privacy regimes expect the same discipline, including Quebec Law 25.
Tell us your main domain and we will scope continuous discovery and monitoring that fits your stack.
Book a CallVulnerability management scans the assets you already know about. Attack surface management starts a step earlier: it finds what is exposed in the first place, including the hosts, subdomains and services nobody remembered to put on the list. The two run together, with discovery feeding the scan scope.
No. Discovery tooling produces a long list of things that look exposed. What you pay for is triage by real exploitability and getting the findings that matter actually fixed, led by a published security researcher who knows which exposure an attacker uses first.
Yes. We watch for your credentials in breach and infostealer dumps, for your company and brand named in ransomware and extortion leak sites, and for look-alike domains registered to impersonate you. Each is surfaced as a tracked finding, not a raw feed you have to read yourself.
Yes. Continuous monitoring of exposure and a documented, tracked remediation process map directly to SOC 2 CC7.1 and ISO 27001 controls 8.8 and 8.16. We produce reporting that serves as evidence directly.
Knowing your assets and watching them for exposure is not a nice-to-have in the major frameworks. Several name it directly, and a few write down how often it has to happen.
| Framework | Status | What the requirement says |
|---|---|---|
| ISO/IEC 27001:2022A.8.8 and A.8.16 | Required | Technical vulnerabilities must be identified and acted on (8.8), and systems must be monitored for anomalous behaviour and exposure (8.16). Keeping a current external inventory is how you evidence both. |
| SOC 2CC7.1 and CC7.2 | Expected | Requires procedures to detect and act on new vulnerabilities and configuration changes, and to monitor for anomalies. Auditors sample your monitoring output, triage records and remediation timelines against your own stated policy. |
| PCI DSS v4.0Requirements 11.3 and 12.5.1 | Required | Scanning on a set cadence, plus a maintained inventory of in-scope system components. You cannot scope either honestly without first knowing what is exposed. |
| NIST CSF 2.0ID.AM and DE.CM | Expected | Asset management requires a maintained inventory of what you expose, and continuous monitoring requires watching it for change. Attack surface management is the operational form of both. |
On PCI external scans, plainly: we are not an Approved Scanning Vendor, and only an ASV can produce a passing external scan attestation for PCI DSS 11.3.2. We coordinate the ASV, remediate what the scan returns and manage the rescan until it passes. The same list of what we cannot sign is on the internal audit page.
Free PDFs, no card
SOC 2 readiness, ISO 27001 gaps, incident response and vendor security, as PDFs you can print or forward. Free, no card.
From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.