attack surface monitoring

We don't know exactly what you're running. We know exactly what changed since yesterday.

SurfaceDiff scans your domains, subdomains, DNS, ports, TLS certificates and web services on a schedule - and tells you the moment something new appears. Yesterday it wasn't public. Today it is. You get the evidence.

Manage multiple customer domains? Explore the Hosting Pilot. Running managed infrastructure at MSP, MSSP or data centre scale? See the guided assessment for managed cloud providers. Scanning your own servers? See best practices, including allowlisting our scanner.

SurfaceDiff incidents list - real findings with severity, type, status and review history, e.g. a service fingerprint change closed with a logged reason

How it works

01scan

We scan what's actually public

Subdomains, DNS records, open ports, TLS certificates, live web services and crawlable endpoints - the same reconnaissance an attacker would run, on a schedule.

02normalize

Raw results become one snapshot

Every scan is normalized into a single structured snapshot, so this week's result can be compared with last week's - not just skimmed.

03diff

We diff it against last time

New hosts, new ports, changed certificates, services that vanished. Exposures you've already reviewed stay quiet - only real change surfaces.

04alert

You get the incident, with evidence

A severity, a title, and the exact evidence behind it - timestamped and kept, so "yesterday it wasn't there" is something you can prove.

Built to be trusted with this

Full-surface scanning

DNS, subdomains, open ports, TLS certificates, web services and crawlable endpoints (pages and API paths a crawler can reach from the site) - not just a port scan.

What's running, not just what's open

Open ports get fingerprinted for real service and version evidence, gathered safely without tripping your own security tooling.

Noise you control

Mark a port or service as an exposure once, with a reason, and future scans stay quiet about it - until you say otherwise.

An audit trail, not just a dashboard

Every mute, un-review and re-enable is logged with who did it and why - useful the day someone asks why this was open.

Team roles, not shared logins

Owner, admin, member and viewer roles - scope a client's login to just the domains they own, not your whole account.

Built for shared infrastructure

One change on a shared server becomes one incident, not fifty - and pricing counts a shared host once, not per domain on it.

Go back to any scan

Every scan is kept, not just the latest. Browse any past snapshot, or compare two dates side by side to see exactly what changed - useful the day someone asks what was exposed, not just what's exposed now.

Built by people who use it themselves

“We run SurfaceDiff on our own hosting infrastructure - for example yourpdf.store, and others. It's already caught things we'd have missed: a shared-host service fingerprint flapping that turned out to be a real config issue, and a scanning gap where our own fail2ban was blocking the very checks we rely on. If it works well enough for us to trust it on our own servers, it'll work for yours.”
Mark, Founder

See what's actually exposed.

Add a domain, get a baseline, and know the moment it changes.

Scan your domain free