OUTSIDE
Sign inWatch demo
Evidence-first external exposure management

From external exposure to verified remediation.

OUTSIDE watches what changes outside your organization, explains why it matters, preserves the evidence, and carries approved work through remediation and post-change verification. Supported connected actions stay scoped, audited, and reversible.

No agents · No credentials for the snapshot · Evidence first

Before · Change detectedHigh risk

External change detected

staging-api.company.com

Evidence

A previously observed staging endpoint is publicly reachable again.

Why it matters

The change expands the public surface and may bypass the intended production path.

Approved remediation
Cloudflare
Connected provider
Resolution verified
After · Resolution verifiedPassed

Resolution verified

staging-api.company.com

Controlled action

The approved provider change was applied within its defined scope.

Post-change check

The result was re-checked and the before-and-after evidence was retained.

Verified after 5m 42sRollback available
Immutable audit trailObserved · Explained · Approved · Applied · Verified · Preserved
Passive snapshot
Low-friction starting point
Evidence preserved
From observation to outcome
Guardian monitoring
Change stays visible
The gap scanners leave open

Finding exposure is not the same as resolving it.

Point-in-time scanners are useful for discovery, but the operational risk remains after the report. OUTSIDE is built for the work between the first observation and a result your team can verify.

01

Scanners create findings

A point-in-time result starts the work. Someone still has to understand the change, find the owner, choose a safe response, and prove the outcome.

02

Change creates the blind spot

New hosts, returned services, certificate changes, and configuration drift appear between assessments. Guardian keeps those changes visible.

03

Closure needs evidence

OUTSIDE keeps the observation, reasoning, decision, action, and post-change check together, without turning uncertain signals into invented vulnerabilities.

The OUTSIDE loop

A finding is only useful when the loop closes.

01

Observe

Continuously compare the verified external surface and surface meaningful new, returned, or changed exposure.

02

Understand

Connect the evidence, history, context, and likely ownership so the team knows what changed and why it matters.

03

Remediate

Guide the fix, record approval, and run a scoped provider action only where OUTSIDE supports it.

04

Verify

Re-check the external result, preserve before-and-after evidence, and keep supported changes reversible.

OUTSIDE Guardian

Catch change before it becomes forgotten exposure.

Guardian keeps the verified external surface under watch. It separates new, returned, and materially changed exposure from background noise, then links each signal to evidence, context, ownership, and the next decision.

Exposure DriftSecurity checklistRemediation guidesExecutive digestSlack · Teams · Jira
Exposure Drift · 30 days
External exposure is becoming simpler.
watching
+3
new assets
2
review items
8/10
controls
Review

A previously observed staging asset is publicly reachable again.

Evidence to closure

A recommendation is not a resolution.

OUTSIDE keeps the observation, decision, action, and verification in one auditable record. It does not pretend every finding can be fixed automatically: unsupported actions remain guided; supported provider controls require approval and stay reversible.

  • Evidence-backed guidance tells the operator what to change and why.
  • Approvals and ownership remain explicit before a connected action runs.
  • Post-change checks verify the externally visible result.
  • Supported automated changes retain an audit trail and rollback path.
Guided

For every recommendation: evidence, context, priority, and a concrete operator checklist.

Controlled

For supported provider actions: scoped credentials, explicit approval, and least-privilege execution.

Verified

After the work: a new external observation and preserved before-and-after proof.

For MSPs, MSSPs, and agencies

Operate across clients. Prove the outcome.

OUTSIDE turns continuous exposure work into a repeatable service: one operating view for client change, recommendations, SLA attention, reporting, and verified closure.

  • Multi-tenant workspaces, roles, client groups, and isolated portals
  • Portfolio-level changes, priorities, and SLA tracking
  • White-label reports and client-ready evidence
  • API, Slack, Teams, Jira, and ticket workflows
Explore agency operations
OUTSIDE AgencyClient outcome view
30
client domains
17
open decisions
42
verified this month
Acme Commerce3Resolution verified
Northstar Labs0Resolution verified
Atlas Financial2Resolution verified
Velora Systems1Resolution verified
Why OUTSIDE

Not another ASM scanner.

OUTSIDE includes passive discovery, but discovery is the entry point—not the product boundary. The product is the evidence-first operating loop that keeps change visible until the result is verified.

Operational questionOUTSIDETypical scanner
Primary jobTrack external exposure from meaningful change to verified outcome.Find assets, misconfigurations, or vulnerabilities at a point in time.
When something changesExplain what changed, why it matters, and which decision is next.Create another finding or alert for the queue.
EvidenceKeep observation, context, decision, and before-and-after proof together.Keep scan output or a point-in-time report.
RemediationGuide every fix and execute approved provider controls where supported.Hand the finding to another workflow or operator.
After the fixRe-check the public result and retain verification evidence.Often manual, assumed, or handled by a separate tool.
ReversibilityKeep rollback available for supported connected actions.Usually outside the scanner workflow.
Investigation depth

Deep technology when the evidence needs it.

Attacker View

A cinematic replay of how public information gradually reveals your infrastructure — starting from a single domain. Ideal for demos and board conversations. Depicts discovery, never exploitation.

Shadow asset detection

Correlated signals — legacy naming, graph isolation, dated technology, absence from your primary site — flag possibly forgotten assets, with the reasoning shown.

Change detection

Repeated scans diff your external surface: new hostnames, returning services, and technology shifts, so nothing appears unnoticed.

Explainable protection posture

A deterministic 0–100 protection posture. Open “Why is my posture 37/100?” to see every penalty and mitigation. It measures how contained your surface is — not a probability of being hacked.

Technology behind the loop

Go deeper without losing the path to an outcome.

Exploited-vulnerability correlation

Disclosed technology versions are matched against a curated CVE set and enriched with live CISA KEV (exploited in the wild, ransomware links, federal deadlines) and FIRST.org EPSS probability. A version banner is an item to confirm — never a confirmed exploit.

Threat & telemetry enrichment

Bring your keys and OUTSIDE reaches further on verified targets: passive-DNS (SecurityTrails, Shodan) and Censys service discovery expand the surface; AbuseIPDB, GreyNoise, VirusTotal and HaveIBeenPwned add reputation, classification and breach exposure.

Chronos · security time machine

Reconstruct your external surface as it was on any day, diff any two moments, and replay how exposure evolved — grounded only in observations that were actually recorded.

Digital Twin · dependency & blast radius

Read the surface as a dependency graph: what relies on what, and exactly which assets break if a shared CDN, nameserver, address or technology fails or is compromised.

Capability registry · radical transparency

A code-backed inventory of exactly what OUTSIDE detects — passive or active, always-on or operator-keyed — kept honest by a test that fails if the registry ever drifts from what a real scan produces.

Evolution · learns what to build next

OUTSIDE watches which vulnerabilities are being exploited and drafts evidence-backed proposals for coverage it doesn't yet have. It proposes and prepares; you approve. It never changes itself.

Responsible use

A security product, built securely.

Passive by default

The external snapshot uses only public, non-invasive data sources. No exploitation, no brute force, no unauthorized access — ever.

SSRF & egress guarded

Targets are normalized and validated; private, loopback, link-local, and cloud-metadata ranges are refused at a single chokepoint.

Ownership verification

Deeper inspection is gated behind DNS TXT / file-based domain ownership verification. Unverified targets get a clearly-labeled external view.

Rate limited & auditable

Scan quotas, concurrency controls, request timeouts, and structured audit logging keep the platform from becoming a mass-scanning tool.

Pricing

The same OUTSIDE system in every paid plan. Choose your domain capacity.

Snapshot
Freeone-off
  • One-off passive outside view
  • Map of publicly visible assets
  • Attacker View without exploitation
  • Prioritized findings
Create free account
Single
€49/mo
  • 1 registrable domain, including its subdomains
  • Continuous monitoring, with an alert when something changes
  • Why it changed, what it affects, and the next step
  • Verified remediation and rollback where supported
Protect one domain
BusinessPopular
€99/mo
  • Up to 5 registrable domains, including subdomains
  • Everything in Single
  • Known-exploited vulnerabilities matched to your technology
  • Full change history, and what each asset depends on
  • Verified remediation and rollback where supported
  • Weekly executive digest
Protect up to five domains
Agency
€299/mo
  • No fixed protected-domain limit (fair use)
  • Everything in Business
  • Client workspaces and team roles
  • White-label reports and issue workflows
  • API access
See how it works for MSPs

Single, Business and Agency include Guardian, ORIGIN, FORWARD, Aegis and verified remediation where the integration supports it. They differ by capacity and agency tools. Annual billing charges for 10 months.

Questions, answered

What teams ask before their first scan.

Clear answers about what OUTSIDE observes, when verification is required, how integrations work, and what changes after you start monitoring.

OUTSIDE Assistant

Answers are selected from reviewed OUTSIDE FAQ content. The assistant cannot inspect your systems or account.

What does OUTSIDE actually do?
OUTSIDE starts with a company domain and maps the external digital surface visible from the internet. It separates observed evidence from inference and possible concern, shows relationships between assets, and explains what deserves review. It is an external visibility and monitoring product, not a penetration test.
Is scanning safe, and can I scan any domain?
The public snapshot uses passive, publicly available sources by default. Active checks, continuous monitoring, and remediation require an authenticated account and verified control of the target. Only scan domains you own or are authorized to assess. Domain owners can also use the published opt-out mechanism.
Which data sources does OUTSIDE use?
Core discovery uses public certificate-transparency, DNS, HTTP, and TLS observations. Optional organization-owned integrations can add passive DNS, breach intelligence, reputation, service exposure, cloud attribution, and other context. A provider failure is shown as incomplete coverage, never as a passing result.
Why do I need to verify a domain?
Verification proves that your organization controls the target before OUTSIDE performs active observations or stores continuous history. You verify with a DNS TXT record or the supported web-file method. Verification does not transfer DNS control and can be removed after it is confirmed.
What is OUTSIDE Guardian?
Guardian compares scheduled scans over time. It highlights exposure drift, maintains a living checklist, creates evidence-backed recommendations, routes grouped alerts, and prepares an executive digest. It reports what changed and why it matters without claiming that a system was exploited.
Can I connect my own provider and cloud accounts?
Yes. OUTSIDE supports organization-owned credentials for intelligence and account-attribution providers through one guided connection flow. Credentials are tested, encrypted, tenant-scoped, and used only for the selected organization. Write-capable actions such as Cloudflare DMARC remediation are explicit, previewed, audited, and reversible where supported.
Does AI decide what is a finding?
No. Discovery, findings, scores, and evidence are deterministic. Optional AI can explain an existing result in plainer language, but it cannot add assets, findings, or scores. Secrets and personal-data patterns are redacted before a model call, and a deterministic explanation remains available without AI.
How much does OUTSIDE cost?
Free Snapshot is one passive external snapshot, not continuous protection. Every paid plan includes all production-ready OUTSIDE capabilities: Single is €49/month for one protected registrable domain, Business is €99/month for up to five, and Agency is €299/month for unlimited domains under fair use plus multi-client operations. Subdomains do not consume extra slots. Annual plans cost €490, €990, and €2,990.
What counts as one protected domain?
One registrable root domain, such as example.com, uses one slot. Its subdomains are included in that slot. A different registrable root uses another slot. Pending verification can reserve a slot temporarily; paused, archived, and removed domains do not consume active capacity.
Are all security capabilities included in every paid plan?
Yes. Single, Business, and Agency receive the same production-ready security engine, including Guardian, Chronos, Evidence, Digital Twin, ORIGIN, FORWARD, and supported Aegis remediation. A specific action still appears only when the Capability Registry confirms that the provider, target, permissions, verification, and rollback conditions are genuinely supported.
Is Agency really unlimited?
Agency has no fixed protected-domain slot limit and adds multi-client fleet operations. Fair use still applies to concurrency, provider rate limits, queue fairness, and abuse prevention so one workspace cannot degrade service for others.
Can I switch plans, and what happens when I downgrade?
You can upgrade without removing protected domains. A downgrade is accepted only when active domain use fits the destination plan. Pause or archive excess domains first; OUTSIDE preserves their history and never silently deletes protection records to force a downgrade.
Is Free Snapshot continuous monitoring?
No. Free Snapshot is one passive external assessment and product demonstration. Continuous Guardian monitoring, stored change history, connected remediation, and ongoing verification begin after target ownership is verified and a paid protected-domain plan is active.
How does OUTSIDE handle my data and credentials?
Customer records are tenant-scoped, provider credentials are encrypted, and production uses durable database storage with bounded retention controls. Public demos use synthetic data. OUTSIDE minimizes model inputs, avoids tenant and domain labels in product telemetry, and exposes documented export, revocation, retention, and offboarding procedures.

Keep watch after the first snapshot.

Start passively. Verify ownership when you are ready, then let Guardian keep meaningful external change visible until your team closes the loop.

https://
Or watch a demo:

The free snapshot is the starting point · Verify ownership to keep watch with Guardian