Free Tool — Passive Scan

What does the public internet already know about your infrastructure?

Every certificate you ever issued is in a public log. Every staging host you meant to lock down answers from anywhere. Enter your domain and see it the way an outsider does.

Passive scan. Reads your public DNS, TLS certificates and HTTP headers. Nothing is written to your infrastructure.

Why this exists

Founders hear about their infrastructure problems from customers, not from their own dashboards. By the time a staging box shows up in a breach report or a cert expiry takes the site down, the window to fix it quietly has closed.

This scan only reads what is already public: Certificate Transparency logs, DNS records, and HTTP response headers. It does not log in, send payloads, fuzz, or generate load. Nobody's infrastructure is touched, only observed.

If the findings are worth acting on, that is what we do. One senior engineer accountable for the whole platform, on a flat monthly fee.