External attack surface management,
from the attacker’s side of the firewall.
You cannot defend an asset you do not know you own. GuardianGaze discovers your internet-facing estate, assesses it across six modules, and scores it 0–100: without an agent, a credential or a scoping call.
Assessed by domain. No access to your environment required.
Discover, observe, prioritise, act
Attack surface management is a loop, not a report. Each pass re-discovers the estate, because the estate changes without telling you.
Discover
Subdomain enumeration and liveness checks find the estate nobody documented, staging hosts, forgotten marketing sites, acquired-company domains.
Observe
Technology discovery, exposed ports and services, security headers, certificate and DNS posture, cloud misconfiguration across AWS, GCP and Cloudflare.
Prioritise
CVEs are ranked with CVSS, EPSS and KEV so you work on what is actually being exploited, not the longest list.
Act
Every finding carries severity, evidence, remediation and an SLA, mapped to MITRE ATT&CK and to the control it breaks.
Breadth, with the evidence attached
Most outside-in platforms stop at infrastructure. The attack surface a real attacker uses also includes your brand and your people.
Nothing to install
Everything is observed from the public internet. No agents, no credentials, no scoping call, the same vantage point an attacker has.
Findings, not a feed
Each finding records what was observed, where, why it matters and who it affects. Prioritised and evidence-backed rather than a raw dump of every open port.
Monitored, not sampled
Continuous monitoring with on-demand rescans, so the picture reflects the estate today rather than the quarter it was last reviewed.
What gets discovered and assessed
Six modules, one score. Each finding carries severity, evidence, remediation and an SLA.
Infrastructure and applications
- Subdomain enumeration and liveness across the estate
- Technology discovery on every live host and high-signal path
- CVE detection backed by NVD, prioritised with CVSS, EPSS and KEV
- Exposed IPs, ports, services and service-level CVEs
- Security headers and subresource integrity
- Cloud posture and misconfiguration across AWS, GCP and Cloudflare
Domain, brand and people
- SPF, DKIM, DMARC, MTA-STS and TLS-RPT, email spoofability as a headline finding
- MX and mail-provider fingerprinting, DNS hygiene
- Typosquat and lookalike-TLD registrations against your brand
- WHOIS and abuse intelligence on hostile registrations
- Leaked credentials belonging to your people, found in breach data
- AI brand-mention intelligence across web and social

One rating for the organisation, six module scores underneath it
Common questions
How is this different from a vulnerability scanner?
A scanner tests hosts you already know about and usually needs credentials or network access. Attack surface management starts by finding the assets you did not know were exposed, from outside, and then assesses them. GuardianGaze needs no access to your environment at all.
Do you need access to our systems?
No. Discovery and assessment run entirely from the public internet. Cloud posture checks are the one exception and are optional, using read-only scoped access to AWS, GCP or Cloudflare if you choose to connect them.
What do you actually look at?
Six modules: brand protection, domain security, application security, network security, cloud security and compliance. Each produces a deterministic 0 to 100 score, and findings roll up into one overall rating for the organisation.
Can you assess companies other than our own?
Yes. Because assessment is outside-in and needs no permission from the target, the same process rates any company by domain, which is how the vendor and supply-chain use cases work.
See your external attack surface as an attacker sees it
Start with your own domain. The first report usually finds an exposed host nobody remembered owning.
Free for your own organisation. Assessed by domain, no access required.