Attack surface monitoring

Attack surface monitoring that proves the fix.

ProvenClosed finds what your company exposes to the internet — subdomains, open ports, certificates, headers, known vulnerabilities and your AWS configuration — re-scans it on a schedule, and re-checks every fix instead of trusting the ticket.

Attack surface monitoring means continuously finding the internet-facing assets an organization owns and checking them for exposures an attacker could use. External attack surface management (EASM) is the same idea kept as an inventory. ProvenClosed does both, and adds what a finding alone does not give you: proof that a fix held.

What it watches

Your external attack surface, the way an attacker sees it.

Every scan is run by a pinned, sandboxed scanner — so the check that found an exposure is the same check that clears it.

Asset discovery

Subdomains and hosts from DNS and certificate transparency, kept as one inventory — with what appeared this week.

Exposed services

The ports that matter — databases, remote access, admin panels — checked on every machine you own.

TLS & security headers

Expired, expiring, untrusted or mismatched certificates, old protocols, and missing browser protections on every web host.

Known vulnerabilities

100 hand-reviewed detection templates, pinned to one commit — nothing downloaded fresh and fired at your production.

AWS posture

World-open security groups, public buckets and databases, stale access keys, users without MFA — read through a role, never a stored key.

Business & Pro

Lookalike domains

Names that could be mistaken for yours, confirmed by a certificate being issued — shown as observations, never accusations.

Pro

Leaked secrets

Your domain named beside a credential in public code, found before someone else finds it.

Pro

AI exposure

Model servers and AI consoles answering the internet without authentication.

Pro

Coverage you can read

Every scan says what it did not look at — a name that did not resolve, a host it may not probe — instead of calling the estate clean.

How it finds things — and what it will not touch

Public records first

A domain you add is mapped from what is already public: its DNS and the certificate transparency logs every publicly trusted certificate is written to. Subdomains and hosts are kept as one inventory, with what appeared since the last scan marked as new.

Active checks only after you prove you own it

Nothing is sent to a domain until you publish a DNS TXT record that proves you control it. Until then it gets a passive baseline from public records only. The proof expires and is re-checked, because domains change hands. Private and internal addresses are refused outright, even when a public name points at them.

On your schedule

Re-scans run monthly on the free plan and as often as every six hours on Business and Pro. A scan window in your own time zone keeps probes off production at the hours you name.

Findings you can act on

  • Fix first. A short, ordered list instead of a long one, with the exact command where a fix is one command.
  • What changed. Every scan is compared with the last, so a new port or a new subdomain is news rather than noise.
  • Hand-off. Send a finding to GitHub Issues, or to your own systems through signed webhooks and the API — on Business and Pro.

Scanners you can inspect

Every scanner image is pinned by digest and can be pulled by anyone, so the exact scanner behind a result can be inspected and re-run. Each run is a fresh, unprivileged, read-only container cut off from our own systems. How ProvenClosed treats your estate.

Monitoring and testing

Attack surface monitoring and a VAPT answer different questions.

Neither replaces the other. A test goes deep at one moment; monitoring watches every day and proves which fixes held.

Attack surface monitoring (ProvenClosed)VAPT or penetration test
WhenContinuously, on a scheduleAt a point in time, often once a year
Who does itPinned, automated scannersPeople trying to break in
ScopeEverything discovered on the domains and AWS accounts you prove you ownWhat was agreed for the engagement
DepthKnown exposures and misconfigurationsManual, creative, chained exploitation
Proof a fix heldA later scan by the same scanner, then a signed certificate anyone can verifyA retest, where one is part of the engagement
Regulatory auditNot a CERT-In empanelled auditWhere a regulator requires one

ProvenClosed is not a CERT-In empanelled auditor, and its certificates are not VAPT certificates. It complements a penetration test; it does not replace one.

See what you expose
in minutes.

Free for one domain, with no card. Active scans begin once you prove it is yours.