External change detected
staging-api.company.com
A previously observed staging endpoint is publicly reachable again.
The change expands the public surface and may bypass the intended production path.
OUTSIDE watches what changes outside your organization, explains why it matters, preserves the evidence, and carries approved work through remediation and post-change verification. Supported connected actions stay scoped, audited, and reversible.
No agents · No credentials for the snapshot · Evidence first
staging-api.company.com
A previously observed staging endpoint is publicly reachable again.
The change expands the public surface and may bypass the intended production path.
staging-api.company.com
The approved provider change was applied within its defined scope.
The result was re-checked and the before-and-after evidence was retained.
Point-in-time scanners are useful for discovery, but the operational risk remains after the report. OUTSIDE is built for the work between the first observation and a result your team can verify.
A point-in-time result starts the work. Someone still has to understand the change, find the owner, choose a safe response, and prove the outcome.
New hosts, returned services, certificate changes, and configuration drift appear between assessments. Guardian keeps those changes visible.
OUTSIDE keeps the observation, reasoning, decision, action, and post-change check together, without turning uncertain signals into invented vulnerabilities.
Continuously compare the verified external surface and surface meaningful new, returned, or changed exposure.
Connect the evidence, history, context, and likely ownership so the team knows what changed and why it matters.
Guide the fix, record approval, and run a scoped provider action only where OUTSIDE supports it.
Re-check the external result, preserve before-and-after evidence, and keep supported changes reversible.
Guardian keeps the verified external surface under watch. It separates new, returned, and materially changed exposure from background noise, then links each signal to evidence, context, ownership, and the next decision.
A previously observed staging asset is publicly reachable again.
OUTSIDE keeps the observation, decision, action, and verification in one auditable record. It does not pretend every finding can be fixed automatically: unsupported actions remain guided; supported provider controls require approval and stay reversible.
For every recommendation: evidence, context, priority, and a concrete operator checklist.
For supported provider actions: scoped credentials, explicit approval, and least-privilege execution.
After the work: a new external observation and preserved before-and-after proof.
OUTSIDE turns continuous exposure work into a repeatable service: one operating view for client change, recommendations, SLA attention, reporting, and verified closure.
OUTSIDE includes passive discovery, but discovery is the entry point—not the product boundary. The product is the evidence-first operating loop that keeps change visible until the result is verified.
| Operational question | OUTSIDE | Typical scanner |
|---|---|---|
| Primary job | Track external exposure from meaningful change to verified outcome. | Find assets, misconfigurations, or vulnerabilities at a point in time. |
| When something changes | Explain what changed, why it matters, and which decision is next. | Create another finding or alert for the queue. |
| Evidence | Keep observation, context, decision, and before-and-after proof together. | Keep scan output or a point-in-time report. |
| Remediation | Guide every fix and execute approved provider controls where supported. | Hand the finding to another workflow or operator. |
| After the fix | Re-check the public result and retain verification evidence. | Often manual, assumed, or handled by a separate tool. |
| Reversibility | Keep rollback available for supported connected actions. | Usually outside the scanner workflow. |
A cinematic replay of how public information gradually reveals your infrastructure — starting from a single domain. Ideal for demos and board conversations. Depicts discovery, never exploitation.
Correlated signals — legacy naming, graph isolation, dated technology, absence from your primary site — flag possibly forgotten assets, with the reasoning shown.
Repeated scans diff your external surface: new hostnames, returning services, and technology shifts, so nothing appears unnoticed.
A deterministic 0–100 protection posture. Open “Why is my posture 37/100?” to see every penalty and mitigation. It measures how contained your surface is — not a probability of being hacked.
Disclosed technology versions are matched against a curated CVE set and enriched with live CISA KEV (exploited in the wild, ransomware links, federal deadlines) and FIRST.org EPSS probability. A version banner is an item to confirm — never a confirmed exploit.
Bring your keys and OUTSIDE reaches further on verified targets: passive-DNS (SecurityTrails, Shodan) and Censys service discovery expand the surface; AbuseIPDB, GreyNoise, VirusTotal and HaveIBeenPwned add reputation, classification and breach exposure.
Reconstruct your external surface as it was on any day, diff any two moments, and replay how exposure evolved — grounded only in observations that were actually recorded.
Read the surface as a dependency graph: what relies on what, and exactly which assets break if a shared CDN, nameserver, address or technology fails or is compromised.
A code-backed inventory of exactly what OUTSIDE detects — passive or active, always-on or operator-keyed — kept honest by a test that fails if the registry ever drifts from what a real scan produces.
OUTSIDE watches which vulnerabilities are being exploited and drafts evidence-backed proposals for coverage it doesn't yet have. It proposes and prepares; you approve. It never changes itself.
The external snapshot uses only public, non-invasive data sources. No exploitation, no brute force, no unauthorized access — ever.
Targets are normalized and validated; private, loopback, link-local, and cloud-metadata ranges are refused at a single chokepoint.
Deeper inspection is gated behind DNS TXT / file-based domain ownership verification. Unverified targets get a clearly-labeled external view.
Scan quotas, concurrency controls, request timeouts, and structured audit logging keep the platform from becoming a mass-scanning tool.
Single, Business and Agency include Guardian, ORIGIN, FORWARD, Aegis and verified remediation where the integration supports it. They differ by capacity and agency tools. Annual billing charges for 10 months.
Clear answers about what OUTSIDE observes, when verification is required, how integrations work, and what changes after you start monitoring.
Answers are selected from reviewed OUTSIDE FAQ content. The assistant cannot inspect your systems or account.
Start passively. Verify ownership when you are ready, then let Guardian keep meaningful external change visible until your team closes the loop.
The free snapshot is the starting point · Verify ownership to keep watch with Guardian