attack surface monitoring

We don't know exactly what you're running. We know exactly what changed since yesterday.

SurfaceDiff scans your domains, subdomains, DNS, ports, TLS certificates and web services on a schedule - and tells you the moment something new appears. Yesterday it wasn't public. Today it is. You get the evidence.

Manage multiple customer domains? Explore the Hosting Pilot. Running managed infrastructure at MSP, MSSP or data centre scale? See the guided assessment for managed cloud providers.

acme-shop.io2 min ago
highnew

Sensitive public port opened: 203.0.113.4:6379

redis · no auth · absent from yesterday's scan

scan → normalize → diff → alert

How it works

01scan

We scan what's actually public

Subdomains, DNS records, open ports, TLS certificates, live web services and crawlable endpoints - the same reconnaissance an attacker would run, on a schedule.

02normalize

Raw results become one snapshot

Every scan is normalized into a single structured snapshot, so this week's result can be compared with last week's - not just skimmed.

03diff

We diff it against last time

New hosts, new ports, changed certificates, services that vanished. Exposures you've already reviewed stay quiet - only real change surfaces.

04alert

You get the incident, with evidence

A severity, a title, and the exact evidence behind it - timestamped and kept, so "yesterday it wasn't there" is something you can prove.

Built to be trusted with this

Full-surface scanning

DNS, subdomains, open ports, TLS certificates, web services and crawlable endpoints - not just a port scan.

What's running, not just what's open

Open ports get fingerprinted for real service and version evidence, gathered safely without tripping your own security tooling.

Noise you control

Mark a port or service as an exposure once, with a reason, and future scans stay quiet about it - until you say otherwise.

An audit trail, not just a dashboard

Every mute, un-review and re-enable is logged with who did it and why - useful the day someone asks why this was open.

Team roles, not shared logins

Owner, admin, member and viewer roles - scope a client's login to just the domains they own, not your whole account.

Built for shared infrastructure

One change on a shared server becomes one incident, not fifty - and pricing counts a shared host once, not per domain on it.

Go back to any scan

Every scan is kept, not just the latest. Browse any past snapshot, or compare two dates side by side to see exactly what changed - useful the day someone asks what was exposed, not just what's exposed now.

See what's actually exposed.

Add a domain, get a baseline, and know the moment it changes.

Scan your domain free