Platform

External Scanner · Prevent

Axyom walks through what your company exposes to the internet and sorts it into findings prioritized by risk. The same work an attacker would do, with the report landing in your inbox instead of theirs.

Nothing to install, no credit card needed. First result in minutes.

What it is

An external attack surface scanner.

It is the inventory of everything your company exposes to the internet, on purpose and by accident: domains, subdomains, open ports, certificates, software versions, headers and email configuration. It is done from the outside, with the same public sources anyone could use, without installing anything inside.

The problem it solves is that this surface grows every week and nobody looks at the whole of it. Every campaign landing page, every staging environment, every subdomain someone spun up for a demo and every certificate renewed by hand is a visible piece. Your team knows them one by one; nobody has the complete list in a single place.

The cost of not looking does not show up on the IT bill. It shows up when a large customer sends you their security questionnaire, when the insurer asks for the technical picture before quoting, or when someone walks in through an admin panel that had been open for two years because nobody remembered it existed.

45

days of validity in the scoring model

What it is
The platform's entry sensor: it inventories and classifies your public surface. Each analysis gathers domains, subdomains and exposed services in the same file.
Who it is for
Companies of 10 to 250 employees that publish more on the internet than they control. If your digital footprint grows faster than your security team, this is your starting point.
Where it fits
In every plan, starting with the free one, and it is never sold on its own. It is the base the rest of the platform's modules build on.
What we need
Only your domain to start mapping your public surface. For the full package, verify it with a TXT record in your DNS or an email from the domain itself.
Cadence
Check the date of the last analysis and the available schedule in your account. You can request a new review whenever you publish something new or change your infrastructure.

What each pass looks at

Every surface a third party can see of you.

All of the work is non-intrusive and none of the tests needs a signed pentest engagement to run.

Ports and services
What is exposed to the internet and which version it runs, on the ports where real services are concentrated.
Certificates and TLS
The complete encryption posture: certificate, protocols, ciphers and HSTS.
Web perimeter
Known vulnerabilities and CVEs, insecure configuration and exposure in what you publish.
Technology and headers
What your website runs on and which security headers are missing, CSP and anti-clickjacking included.
Email
The domain's complete authentication: SPF, DKIM and DMARC.
WAF and CDN
Whether there is protection in front of your website, and from which vendor.
WordPress
Core version, plugins and themes when your website runs on it.
Public breaches
Known leaks associated with your domain's email addresses.
Subdomains and ownership
The surface nobody remembers standing up, and who owns each asset.

Part of the pass is pure discovery: subdomains, hosts and ownership exist to find targets for the rest of the tests. We do not count them as detection, because counting them that way would inflate the figure.

Priority

Why the list does not fill up with noise.

Three mechanisms decide what rises and what gets grouped, and all three are open in the catalog so anyone can audit them.

Order

OWASP Risk Rating

Every finding is scored with OWASP's open methodology, which weighs the likelihood that someone exploits it and the technical impact if they succeed. Because it is a public standard, the order of your list can be audited and challenged.

Context

Your sector counts for 25%

A regulated company scores 7 out of 9 on non-compliance and on privacy violation, against the 2 and 3 of the generic profile. The same finding carries different weight depending on who it happens to.

Grouping

Eight types with a severity cap

SPF, headers, HSTS and the TLS baseline family never rise above medium, and each type is grouped per domain into a single finding. The same problem repeated across twenty subdomains does not flood your list.

Hard caps and expiry

With one open critical the score does not go above 65, and with three or more it stays at 55. A scan keeps its coverage fresh for 45 days; after that, the score stops taking the old picture at face value. And what the scanner sees wins over what the company declares: if the questionnaire says RDP is closed and the scanner finds it open, the scanner wins.

What each pass leaves behind

Three things you can use the same day.

01

The report

Executive summary, Axyom Risk Score out of 100, risk level and the findings ordered by severity. Each one with three fixed blocks: what it is, why it affects you and what to do now. In HTML and in branded PDF.

02

The action plan

Every finding comes with paths to close it. Each action carries estimated effort, cost range, default owner, required evidence and expiry.

03

The living posture

Your domain, subdomains and findings drawn as a map of paths, with a FAIR-lite economic model that puts euros on each scenario. The score has a daily history and moves when you close things.

Where it fits in the platform

Every finding arrives with the control it answers to.

The recommendation is written for whoever reads it: the version for a CEO with no security background and the one for the IT lead are two different texts, not the same paragraph with more or less jargon. Findings are mapped to the ISO 27001, NIS2 and ENS controls that match their scope.

Limits

What this scanner does not do.

Check the scope before turning on the module and coordinate with your team the actions that fall to them.

It exploits nothing

It observes and classifies exposure. Testing whether a finding is actually exploitable is the pentesting module's job, under an active engagement and inside its window.

Non-intrusive does not mean invisible

Part of the pass only reads third-party sources; the rest does send requests to your servers, which is why the full package waits until you verify the domain.

Port scanning runs in a light profile

It covers the most common ports with version detection, not the full range. Review the port scope alongside the result of each run.

The web test suite checks your HTTPS perimeter

It looks for insecure configuration, exposure and known CVEs in what you publish. It does not claim to be a complete test suite.

It only looks at what is public

It does not see inside your laptops (that is EDR), nor your Microsoft 365 or Google Workspace configuration, nor the AI apps with OAuth permissions (that is AI Risk).

It does not touch your infrastructure to fix it

It produces the finding, the action and the recommendation. Your team or your provider carries out the fix, and the evidence is uploaded to the portal.

The date of the analysis matters

The results describe the last run. Check when the surface was reviewed and request a new pass when it changes.

DORA and SOC 2 are outside the auditable scope

Declared as such in the catalog. We do not present them as available until they are.

Plans

The scanner is included in every plan.

It is not sold on its own: what you buy is the complete platform. It starts on the free plan and stays the same on Base, Pro and Max.

Free

To see your real risk before deciding anything.

€0

No cost · No card.

Everything to get looking:

  • Continuous scan External surface, 24/7
  • Posture and risk map Real-time CyberScore
  • Leaked credentials Counted, no detail
Start free

Base

For companies that want the whole platform without a security team of their own.

€190 / month

Self-serve · No commitment.

Everything in Free, plus:

  • Integrations Microsoft 365, Google Workspace and cloud
  • AI risk Apps with permissions over your data
  • Prioritized backlog Monthly remediation
  • 1 domain Continuously scanned
Get Base

Pro

For teams that need every sensor active and an expert behind it.

€990 / month

Advisor on escalation · No commitment.

Everything in Base, plus:

  • Security advisor On escalation, with SLA
  • Threat Intelligence Exposed credentials, under watch
  • Recurring pentesting Authenticated, report reviewed by Axyom
  • MDR 24/7 Up to 20 managed devices
  • Up to 5 domains All continuously scanned
Get Pro

Max

For high exposure or compliance demands.

€1,990 / month

Dedicated advisor · No commitment.

Everything in Pro, plus:

  • Dedicated security advisor A fixed person, monthly session
  • Priority response Incidents
  • Compliance by framework Downloadable evidence and attestation
  • Audit support Customer questionnaires and due diligence
Contact sales

FAQs.

Does the scan touch my systems?

Part of the pass only reads public third-party sources and does not send a single request to your servers. The rest does send traffic to your perimeter, which is why it waits until you prove the domain is yours. Non-intrusive does not mean invisible: our traffic will show up in your logs.

Do I need to install anything or sign a contract?

Nothing is installed and there is no pentest engagement to sign for the first analysis. For the full package you only verify that the domain is yours, with a TXT record in your DNS or an email from the domain itself.

How often does it run?

Check the schedule and the date of the last run in your account. You can request a new review whenever you publish something new. The results describe the scope and timing of each analysis.

Why does my score not go up even though I close things?

Because what the scanner sees wins over what you declare, there are hard caps with open criticals (65 with one, 55 with three or more) and every scan expires after 45 days. The score moves when you close the action and upload the evidence.

Does the scanner check whether a finding is exploitable?

No. It observes and classifies exposure. Testing real exploitability is the pentesting module's job, under explicit authorization and inside its window.

Choose how to start.

On your own

Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.

With our team

Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.

Start now.