What it costs, before you talk to anyone.
These figures are read from the same catalogue checkout uses, so what you see is what you pay. Start with a free scan; a plan is what turns it into something you watch.
Early Access pricing, held through 2026
Monitor
One person keeping an eye on it.
Billed annually as €756
- Continuous external asset discovery
- DNS, TLS, email and header checks
- Full findings with remediation guidance
- Alerts when something changes
Manage
RecommendedA team that has to show the work got done.
Billed annually as €1,908
Everything in Monitor
- SLA policies and breach tracking
- Assign findings to remediators
- Risk register and risk acceptance
- Branded PDF reports
Govern
A group with subsidiaries, SSO and cloud accounts.
Billed annually as €4,308
Everything in Manage
- Single sign-on (OIDC)
- AWS, GCP and Microsoft asset import
- Subsidiary hierarchy and group reporting
What we check
Every scan covers these areas, using only publicly accessible signals tied to your domains. Nothing to install, and no access to your systems required.
SPF, DKIM, DMARC
Records and resolution
Certificates and cipher suites
CSP, HSTS and related browser protections
Certificate transparency logs
48 distinct findings across these families — and nothing intrusive runs unless you ask for it.
Common questions
Do I need to install anything?
No. The free scan and monitoring are based on public signals tied to your domain.
Does the free scan require signup?
No. Signup happens only when you want to unlock the full results and start monitoring.
What happens after the trial?
Your subscription starts automatically unless you cancel before your trial ends. Trial length is shown on each plan above.
How much of my attack surface is covered?
Discovery expands the same way on every plan — out from each domain you add to the subdomains, IP addresses and services connected to it. Plans differ by capability, not by how much is covered: higher tiers add things like SLA policies, finding ownership and compliance reporting on top of the same discovery.
Is this invasive scanning?
No. The free scan reads public records — DNS, certificate transparency, and email security settings — and makes a single ordinary request to your website to check its security headers and TLS setup, much like a browser visit. It does not probe ports, test for vulnerabilities, or attempt any form of access.