# ProvenClosed > Attack surface monitoring with verified remediation. ProvenClosed watches what a company exposes to the internet, re-checks every fix with the same pinned scanner, and issues signed certificates that anyone can verify on their own machine with one open script. Customer data is stored in India (AWS Mumbai, ap-south-1). ## What it does - Discovers subdomains and hosts from DNS and Certificate Transparency, and checks open ports, TLS certificates and protocols, browser security headers and known vulnerabilities (100 reviewed templates pinned to one commit). - Sends nothing to a domain until its owner proves control with a DNS TXT record; before that it builds a passive baseline from public records only. The proof expires and is re-checked. - Reads AWS configuration through a read-only IAM role the customer creates and trusts through OIDC. No access key is stored. - Only a later scan can mark a finding fixed. After that it keeps watching for the exposure to come back. - Signs a certificate (a DSSE envelope) stating what was observed, when, by which scanner build, what the scan covered and what it could not establish. A certificate is in one of three states: VERIFIED, VERIFIED WITH LIMITATIONS, or OBSERVED ONLY. - Records each production certificate's fingerprint (a hash, nothing about the customer's estate) in Sigstore's public transparency log. The inclusion proof travels in the certificate and is checked offline, so a certificate cannot be backdated or quietly withdrawn. - Maps each check to the SOC 2, ISO/IEC 27001:2022 and SEBI CSCRF controls it is evidence for. ## What it is not - Not a VAPT or a penetration test, and not a CERT-In empanelled auditor. Its certificates are not VAPT certificates. It is meant for the time between VAPTs, and complements a penetration test rather than replacing one. - The control mapping is evidence a control owner can cite, not an assessment. ProvenClosed never states that a control is met or that anyone is compliant. - It does not install an agent and never changes a customer's infrastructure. - ProvenClosed does not yet hold its own SOC 2 report or ISO 27001 certificate. ## Plans - Free: one domain, up to 10 assets, one member, a monthly re-scan, 30 days of history. No card. - Business and Pro: in early access, priced by agreement. Signed certificates, evidence packs, control mapping, AWS posture, GitHub Issues hand-off, signed webhooks and API keys; re-scans as often as every 6 hours. Pro adds lookalike domains, leaked secrets and AI exposure. ## Pages - [Home](https://provenclosed.com/): ProvenClosed monitors what your company exposes to the internet, re-checks every fix, and signs a certificate your auditor can verify on their own machine. - [Attack surface monitoring](https://provenclosed.com/attack-surface-monitoring): External attack surface monitoring: subdomains, open ports, TLS, security headers, known vulnerabilities and AWS posture, re-scanned on a schedule, every fix re-checked. - [Verified remediation](https://provenclosed.com/verified-remediation): Verified remediation: a later scan by the same pinned scanner confirms an exposure is gone, keeps watching for it, and signs a certificate anyone can check offline. - [Compliance evidence](https://provenclosed.com/compliance): Evidence for SOC 2, ISO/IEC 27001:2022 and SEBI CSCRF between VAPTs: each fix is mapped to the controls it is evidence for, and never presented as an assessment. - [For SEBI vendors](https://provenclosed.com/sebi-cscrf): Selling to a SEBI-regulated entity? Signed, dated evidence that your internet-facing fixes held, mapped to SEBI CSCRF identifiers. Not an assessment or a VAPT. - [Pricing](https://provenclosed.com/pricing): Free for one domain: a passive baseline, active scans once you prove you own it, a monthly re-scan. Signed certificates come with Business and Pro, in early access. - [Security](https://provenclosed.com/security): How ProvenClosed treats your estate and data: passive until you prove ownership, read-only, no stored cloud keys, row-level tenant isolation, data in AWS Mumbai. - [Verify a certificate](https://provenclosed.com/verify): Check a ProvenClosed remediation certificate on your own machine, without an account or trusting us: one open script, verify.py, and the published key set. - [FAQ](https://provenclosed.com/faq): Answers about ProvenClosed: how it differs from a VAPT or an EASM tool, what it scans and never scans, AWS without stored keys, certificates, data and cost. ## Checking a certificate - [verify.py](https://provenclosed.com/verify.py): the offline verifier — one Python file, meant to be read before it is run. It trusts one issuer, provenclosed.com, and exits 0 only for a production-verified certificate (3 for a valid one that is not, 1 for a refusal). - [Public key set](https://provenclosed.com/.well-known/vexora-attestation-keys.json): the keys certificates are signed with. ## Contact - hello@provenclosed.com — questions and early access - security@provenclosed.com — security reports