External Scanner · Prevent
A security audit for companies, seen from the outside.
Axyom walks through what your company exposes to the internet and sorts it into findings prioritized by risk. The same work an attacker would do, with the report landing in your inbox instead of theirs.
Nothing to install, no credit card needed. First result in minutes.
What it is
An external attack surface scanner.
It is the inventory of everything your company exposes to the internet, on purpose and by accident: domains, subdomains, open ports, certificates, software versions, headers and email configuration. It is done from the outside, with the same public sources anyone could use, without installing anything inside.
The problem it solves is that this surface grows every week and nobody looks at the whole of it. Every campaign landing page, every staging environment, every subdomain someone spun up for a demo and every certificate renewed by hand is a visible piece. Your team knows them one by one; nobody has the complete list in a single place.
The cost of not looking does not show up on the IT bill. It shows up when a large customer sends you their security questionnaire, when the insurer asks for the technical picture before quoting, or when someone walks in through an admin panel that had been open for two years because nobody remembered it existed.
45
days of validity in the scoring model
- What it is
- The platform's entry sensor: it inventories and classifies your public surface. Each analysis gathers domains, subdomains and exposed services in the same file.
- Who it is for
- Companies of 10 to 250 employees that publish more on the internet than they control. If your digital footprint grows faster than your security team, this is your starting point.
- Where it fits
- In every plan, starting with the free one, and it is never sold on its own. It is the base the rest of the platform's modules build on.
- What we need
- Only your domain to start mapping your public surface. For the full package, verify it with a TXT record in your DNS or an email from the domain itself.
- Cadence
- Check the date of the last analysis and the available schedule in your account. You can request a new review whenever you publish something new or change your infrastructure.
What each pass looks at
Every surface a third party can see of you.
All of the work is non-intrusive and none of the tests needs a signed pentest engagement to run.
- Ports and services
- What is exposed to the internet and which version it runs, on the ports where real services are concentrated.
- Certificates and TLS
- The complete encryption posture: certificate, protocols, ciphers and HSTS.
- Web perimeter
- Known vulnerabilities and CVEs, insecure configuration and exposure in what you publish.
- Technology and headers
- What your website runs on and which security headers are missing, CSP and anti-clickjacking included.
- The domain's complete authentication: SPF, DKIM and DMARC.
- WAF and CDN
- Whether there is protection in front of your website, and from which vendor.
- WordPress
- Core version, plugins and themes when your website runs on it.
- Public breaches
- Known leaks associated with your domain's email addresses.
- Subdomains and ownership
- The surface nobody remembers standing up, and who owns each asset.
Part of the pass is pure discovery: subdomains, hosts and ownership exist to find targets for the rest of the tests. We do not count them as detection, because counting them that way would inflate the figure.
Priority
Why the list does not fill up with noise.
Three mechanisms decide what rises and what gets grouped, and all three are open in the catalog so anyone can audit them.
Order
OWASP Risk Rating
Every finding is scored with OWASP's open methodology, which weighs the likelihood that someone exploits it and the technical impact if they succeed. Because it is a public standard, the order of your list can be audited and challenged.
Context
Your sector counts for 25%
A regulated company scores 7 out of 9 on non-compliance and on privacy violation, against the 2 and 3 of the generic profile. The same finding carries different weight depending on who it happens to.
Grouping
Eight types with a severity cap
SPF, headers, HSTS and the TLS baseline family never rise above medium, and each type is grouped per domain into a single finding. The same problem repeated across twenty subdomains does not flood your list.
Hard caps and expiry
With one open critical the score does not go above 65, and with three or more it stays at 55. A scan keeps its coverage fresh for 45 days; after that, the score stops taking the old picture at face value. And what the scanner sees wins over what the company declares: if the questionnaire says RDP is closed and the scanner finds it open, the scanner wins.
What each pass leaves behind
Three things you can use the same day.
The report
Executive summary, Axyom Risk Score out of 100, risk level and the findings ordered by severity. Each one with three fixed blocks: what it is, why it affects you and what to do now. In HTML and in branded PDF.
The action plan
Every finding comes with paths to close it. Each action carries estimated effort, cost range, default owner, required evidence and expiry.
The living posture
Your domain, subdomains and findings drawn as a map of paths, with a FAIR-lite economic model that puts euros on each scenario. The score has a daily history and moves when you close things.
Where it fits in the platform
Every finding arrives with the control it answers to.
The recommendation is written for whoever reads it: the version for a CEO with no security background and the one for the IT lead are two different texts, not the same paragraph with more or less jargon. Findings are mapped to the ISO 27001, NIS2 and ENS controls that match their scope.
Continuous Compliance
Where these findings end up, converted into control status, with their evidence and their attestation.
Learn morePentesting
The layer that does test whether a finding is exploitable, under explicit authorization and with a reviewed report.
Learn moreCyber Insurance
Your posture provides the technical context to prepare a quote request.
Learn moreLimits
What this scanner does not do.
Check the scope before turning on the module and coordinate with your team the actions that fall to them.
It exploits nothing
It observes and classifies exposure. Testing whether a finding is actually exploitable is the pentesting module's job, under an active engagement and inside its window.
Non-intrusive does not mean invisible
Part of the pass only reads third-party sources; the rest does send requests to your servers, which is why the full package waits until you verify the domain.
Port scanning runs in a light profile
It covers the most common ports with version detection, not the full range. Review the port scope alongside the result of each run.
The web test suite checks your HTTPS perimeter
It looks for insecure configuration, exposure and known CVEs in what you publish. It does not claim to be a complete test suite.
It only looks at what is public
It does not see inside your laptops (that is EDR), nor your Microsoft 365 or Google Workspace configuration, nor the AI apps with OAuth permissions (that is AI Risk).
It does not touch your infrastructure to fix it
It produces the finding, the action and the recommendation. Your team or your provider carries out the fix, and the evidence is uploaded to the portal.
The date of the analysis matters
The results describe the last run. Check when the surface was reviewed and request a new pass when it changes.
DORA and SOC 2 are outside the auditable scope
Declared as such in the catalog. We do not present them as available until they are.
Plans
The scanner is included in every plan.
It is not sold on its own: what you buy is the complete platform. It starts on the free plan and stays the same on Base, Pro and Max.
Free
To see your real risk before deciding anything.
No cost · No card.
Everything to get looking:
- Continuous scan External surface, 24/7
- Posture and risk map Real-time CyberScore
- Leaked credentials Counted, no detail
Base
For companies that want the whole platform without a security team of their own.
Self-serve · No commitment.
Everything in Free, plus:
- Integrations Microsoft 365, Google Workspace and cloud
- AI risk Apps with permissions over your data
- Prioritized backlog Monthly remediation
- 1 domain Continuously scanned
Pro
For teams that need every sensor active and an expert behind it.
Advisor on escalation · No commitment.
Everything in Base, plus:
- Security advisor On escalation, with SLA
- Threat Intelligence Exposed credentials, under watch
- Recurring pentesting Authenticated, report reviewed by Axyom
- MDR 24/7 Up to 20 managed devices
- Up to 5 domains All continuously scanned
Max
For high exposure or compliance demands.
Dedicated advisor · No commitment.
Everything in Pro, plus:
- Dedicated security advisor A fixed person, monthly session
- Priority response Incidents
- Compliance by framework Downloadable evidence and attestation
- Audit support Customer questionnaires and due diligence
FAQs.
Does the scan touch my systems?
Part of the pass only reads public third-party sources and does not send a single request to your servers. The rest does send traffic to your perimeter, which is why it waits until you prove the domain is yours. Non-intrusive does not mean invisible: our traffic will show up in your logs.
Do I need to install anything or sign a contract?
Nothing is installed and there is no pentest engagement to sign for the first analysis. For the full package you only verify that the domain is yours, with a TXT record in your DNS or an email from the domain itself.
How often does it run?
Check the schedule and the date of the last run in your account. You can request a new review whenever you publish something new. The results describe the scope and timing of each analysis.
Why does my score not go up even though I close things?
Because what the scanner sees wins over what you declare, there are hard caps with open criticals (65 with one, 55 with three or more) and every scan expires after 45 days. The score moves when you close the action and upload the evidence.
Does the scanner check whether a finding is exploitable?
No. It observes and classifies exposure. Testing real exploitability is the pentesting module's job, under explicit authorization and inside its window.
Choose how to start.
On your own
Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.
With our team
Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.