OUTSIDE turns public infrastructure evidence into a living map—then Guardian correlates meaningful change after every scheduled observation.
Passive, public sources only · No login required for an external snapshot
northstarlabs.example becomes the deterministic root entity.
Guardian correlates every verified observation into meaningful change intelligence: Exposure Drift, a living security checklist, evidence-backed recommendations, tailored remediation, grouped workflow alerts, and a weekly executive digest.
Every certificate, DNS record, and subdomain is public. Staging environments, old portals, and new APIs appear on the internet whether or not anyone is tracking them.
An outsider needs nothing but your domain to begin mapping infrastructure. OUTSIDE shows you exactly what that reconnaissance reveals — from the defender's side.
Every result separates observed fact from inference from possible risk, with confidence scores and evidence. No fabricated vulnerabilities, no sensationalism.
Passive sources — certificate transparency, DNS, public web signals — surface hostnames and services.
Assets are normalized and entity-resolved into a single graph with relationship confidence.
Weak signals combine into shadow-asset, non-production, and authentication classifications.
A transparent exposure score and evidence-backed findings tell you what to review and why.
A cinematic replay of how public information gradually reveals your infrastructure — starting from a single domain. Ideal for demos and board conversations. Depicts discovery, never exploitation.
Correlated signals — legacy naming, graph isolation, dated technology, absence from your primary site — flag possibly forgotten assets, with the reasoning shown.
Repeated scans diff your external surface: new hostnames, returning services, and technology shifts, so nothing appears unnoticed.
A deterministic 0–100 posture score. Open “Why is my score 37?” to see every penalty and mitigation. It measures how contained your surface is — not a probability of being hacked.
The external snapshot uses only public, non-invasive data sources. No exploitation, no brute force, no unauthorized access — ever.
Targets are normalized and validated; private, loopback, link-local, and cloud-metadata ranges are refused at a single chokepoint.
Deeper inspection is gated behind DNS TXT / file-based domain ownership verification. Unverified targets get a clearly-labeled external view.
Scan quotas, concurrency controls, request timeouts, and structured audit logging keep the platform from becoming a mass-scanning tool.
Pricing reflects scanning, provider, and AI-explanation costs per monitored domain and frequency.
Enter your domain and watch your public digital footprint appear.
Passive, public sources only · No login required for an external snapshot