Questions
Asked before signing up.
Straight answers about what ProvenClosed does, what it never does, and what it does not claim.
What is ProvenClosed?
ProvenClosed is attack surface monitoring with verified remediation. It finds what a company exposes to the internet, re-checks every fix with the same pinned scanner that found the problem, and signs a certificate of what it observed that anyone can verify on their own machine. What it watches.
What is verified remediation?
Verified remediation means a fix is confirmed by evidence rather than by a ticket status: a later scan by the same scanner observes that the exposure is gone, and the product keeps watching for it to come back. How a fix is verified.
How is ProvenClosed different from other attack surface monitoring (EASM) tools?
It finds exposures the way attack surface tools do, and then does what a finding alone does not: it re-checks each fix with the scanner that found it, keeps watching, and signs what it observed so that an auditor or a customer can check it without trusting ProvenClosed.
Is ProvenClosed a VAPT or a penetration test?
No. A penetration test is a person trying to break in at one point in time. ProvenClosed watches your external attack surface continuously, re-checks every fix and signs what it observed. It is not a CERT-In empanelled auditor and does not issue VAPT certificates — use it between tests, to catch what changed and prove which fixes held.
Does it replace our annual VAPT?
No. It complements a penetration test and does not replace one. Where a regulator requires a VAPT and its revalidation — as SEBI's CSCRF does for regulated entities — that is work for a CERT-In empanelled auditor. SEBI CSCRF for vendors.
Will it scan anything I don't own?
No packet is sent to a domain until you prove you own it with a DNS TXT record. Before that it builds a passive baseline from public records only. Private and internal addresses are refused outright, even if a public name points at them.
Does it install an agent or change anything in my infrastructure?
No. It observes from outside and reads your cloud through a read-only role. There is no agent to install, and it never changes your infrastructure.
Do you need my AWS access keys?
No. You create a read-only role that trusts ProvenClosed's identity through OIDC. ProvenClosed assumes it only when it reads, with credentials that expire within the hour. No key is stored, and the role cannot change anything.
How often does it scan?
Monthly on the free plan, and as often as every six hours on Business and Pro. A scan window in your own time zone keeps probes off production at the hours you name. Plans.
How does someone check a certificate?
They download verify.py — one Python file, meant to be read before it is run — and run it on the certificate. It checks the signature against the key set published at this site, checks the certificate's transparency-log proof without contacting the log, and re-prints every claim from the signed data. Step by step.
What does “verified with limitations” mean?
The exposure was seen gone, but something weakens the proof — for example, the scanner was updated between the scan that saw it and the scan that found it gone. The certificate names the reason instead of rounding it up to a clean pass.
Which compliance frameworks does it map to?
SOC 2, ISO/IEC 27001:2022 and SEBI CSCRF. Each check is mapped to the controls it produces evidence for — evidence a control owner can cite, never an assessment and never a statement that a control is met. The full mapping.
Is ProvenClosed itself SOC 2 or ISO 27001 certified?
Not yet. ProvenClosed does not hold its own SOC 2 report or ISO 27001 certificate, and says so. How it treats your data.
Where is my data stored?
In India, in AWS Mumbai (ap-south-1). Secrets such as MFA seeds and integration tokens are encrypted by the application, and backups are encrypted and kept off the server in the same region.
What does it cost?
Monitoring one domain is free, with no card. The paid plans — with signed certificates, AWS posture, integrations and the deeper scans — are in early access while billing is being built. Ask for access.
How do I report a security problem in ProvenClosed?
Write to security@provenclosed.com. Please give us a chance to fix it before telling anyone else, and do not access data that is not yours while you look.