You cannot secure what you do not know is online.
Most companies can name their main website. Almost none can name every subdomain, every forgotten staging server, or every login panel a former contractor spun up two years ago and never took down. Attackers do not need your inventory to find these things: they scan the whole internet for a living. Right now, the gap between what you think is exposed and what is actually reachable is the same gap an attacker walks through.
attack-surface discovery
Everything you expose, before an attacker maps it.
We watch your whole internet-facing surface, every server, login page and forgotten subdomain, and keep watching, so a new exposure surfaces the day it appears, not the week after a breach.
capabilities
Continuous discovery
Passive and active scans find every internet-facing asset, subdomains, servers and forgotten login pages, and keep finding them.
Exposed services
We flag the open ports and running services that hand an attacker a way in.
TLS and email hygiene
Expiring or weak certificates, and domains missing SPF and DMARC that let anyone spoof your email.
Exploit-aware ranking
Findings are ordered by what an attacker can actually use, so the exploitable ones sit at the top.
NIS2 mapping
Each exposure is tied to the risk it creates, in the terms your NIS2 report needs.
Scheduled re-scans
Set a cadence per domain, so a new exposure surfaces the day it appears, not the week after.
How module scry works
- 01
Start from one domain
You give us one domain. We expand outward from it: subdomains, the servers behind them, and every internet-facing service we can reach, the same starting point an attacker uses. No agent, no credentials, nothing installed on your side.
- 02
See what is actually running
We fingerprint what is running on each host and check it against known problems: expired or weak TLS certificates, exposed admin and login panels, weak SPF or DMARC on your mail domain, HTTP hygiene issues, and services that should not be public at all. Each finding names the exact host and the exact problem, with the evidence attached.
- 03
We rank and re-check on a schedule
Each finding is ranked by how exploitable it really is, not just its raw severity, and mapped to the relevant NIS2 measure and CWE. We re-check continuously on a schedule, so a new exposure surfaces the day it appears, not at the next annual pentest.
Where it fits
- scryyou are heresee what you are exposing
- hexprove it can’t be broken into
- wardfix it, and confirm it’s gone
- sigilturn it into compliance evidence
Common questions about module scry
Do you install anything or access our internal systems?
No. Module scry is entirely passive and external. We resolve DNS, connect to public ports, and read what a server offers on a normal handshake, the same as a browser or search engine would. Nothing is installed, nothing is authenticated into, and nothing is tested to failure.
How is this different from a vulnerability scanner?
A vulnerability scanner mostly hands you a CVSS score. We hand you the same finding ranked by whether it is actually reachable and exploitable from the outside, plus the NIS2 measure and CWE it maps to, with the evidence attached. For a small team, that is the difference between a wall of output and the two or three things worth fixing first.
Does a finding mean we are automatically NIS2 non-compliant?
No. A finding tells you which measure of your NIS2 obligations it relates to and attaches the evidence, so you have a documented starting point. It does not decide compliance for you, and it does not replace a risk assessment. Module sigil is where that ongoing evidence becomes a structured report you can hand to an auditor.
The NIS2 deadline isn't moving. Your setup can start today.
See what your company exposes to the internet, free and EU-hosted, with no security team required.
*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.