Attack surface monitoring
Attack surface monitoring that proves the fix.
ProvenClosed finds what your company exposes to the internet — subdomains, open ports, certificates, headers, known vulnerabilities and your AWS configuration — re-scans it on a schedule, and re-checks every fix instead of trusting the ticket.
Attack surface monitoring means continuously finding the internet-facing assets an organization owns and checking them for exposures an attacker could use. External attack surface management (EASM) is the same idea kept as an inventory. ProvenClosed does both, and adds what a finding alone does not give you: proof that a fix held.
What it watches
Your external attack surface, the way an attacker sees it.
Every scan is run by a pinned, sandboxed scanner — so the check that found an exposure is the same check that clears it.
Asset discovery
Subdomains and hosts from DNS and certificate transparency, kept as one inventory — with what appeared this week.
Exposed services
The ports that matter — databases, remote access, admin panels — checked on every machine you own.
TLS & security headers
Expired, expiring, untrusted or mismatched certificates, old protocols, and missing browser protections on every web host.
Known vulnerabilities
100 hand-reviewed detection templates, pinned to one commit — nothing downloaded fresh and fired at your production.
AWS posture
World-open security groups, public buckets and databases, stale access keys, users without MFA — read through a role, never a stored key.
Business & ProLookalike domains
Names that could be mistaken for yours, confirmed by a certificate being issued — shown as observations, never accusations.
ProLeaked secrets
Your domain named beside a credential in public code, found before someone else finds it.
ProAI exposure
Model servers and AI consoles answering the internet without authentication.
ProCoverage you can read
Every scan says what it did not look at — a name that did not resolve, a host it may not probe — instead of calling the estate clean.
How it finds things — and what it will not touch
Public records first
A domain you add is mapped from what is already public: its DNS and the certificate transparency logs every publicly trusted certificate is written to. Subdomains and hosts are kept as one inventory, with what appeared since the last scan marked as new.
Active checks only after you prove you own it
Nothing is sent to a domain until you publish a DNS TXT record that proves you control it. Until then it gets a passive baseline from public records only. The proof expires and is re-checked, because domains change hands. Private and internal addresses are refused outright, even when a public name points at them.
On your schedule
Re-scans run monthly on the free plan and as often as every six hours on Business and Pro. A scan window in your own time zone keeps probes off production at the hours you name.
Findings you can act on
- Fix first. A short, ordered list instead of a long one, with the exact command where a fix is one command.
- What changed. Every scan is compared with the last, so a new port or a new subdomain is news rather than noise.
- Hand-off. Send a finding to GitHub Issues, or to your own systems through signed webhooks and the API — on Business and Pro.
Scanners you can inspect
Every scanner image is pinned by digest and can be pulled by anyone, so the exact scanner behind a result can be inspected and re-run. Each run is a fresh, unprivileged, read-only container cut off from our own systems. How ProvenClosed treats your estate.
Monitoring and testing
Attack surface monitoring and a VAPT answer different questions.
Neither replaces the other. A test goes deep at one moment; monitoring watches every day and proves which fixes held.
| Attack surface monitoring (ProvenClosed) | VAPT or penetration test | |
|---|---|---|
| When | Continuously, on a schedule | At a point in time, often once a year |
| Who does it | Pinned, automated scanners | People trying to break in |
| Scope | Everything discovered on the domains and AWS accounts you prove you own | What was agreed for the engagement |
| Depth | Known exposures and misconfigurations | Manual, creative, chained exploitation |
| Proof a fix held | A later scan by the same scanner, then a signed certificate anyone can verify | A retest, where one is part of the engagement |
| Regulatory audit | Not a CERT-In empanelled audit | Where a regulator requires one |
ProvenClosed is not a CERT-In empanelled auditor, and its certificates are not VAPT certificates. It complements a penetration test; it does not replace one.
See what you expose
in minutes.
Free for one domain, with no card. Active scans begin once you prove it is yours.