Managed Exposure
Everything an attacker can see of your customer from the outside, watched continuously and reported in your template. The whole service works from what the internet already publishes, so there is no agent to deploy, no credential to request and no change window to book. That is why it is the easiest thing to put in front of an account that has never bought security from you before.
$59.25USDper domain / month
List $79 — what your customer pays. You keep the difference. · 25% off list
- Priced by
- per domain / month
- Delivered as
- Your brand, your template
- Client access
- None needed
- Runs on
- zcrCTEM
Scoped before you quote, not after you have sold it
No agent, no VPN, no credentials, no change window — we start from a domain name, so you can sell it on Monday and show output on Tuesday.
Discovery is continuous rather than quarterly: new subdomains, exposed admin panels, expiring certificates and newly opened services are picked up as they appear.
Every finding is verified by an analyst before it reaches you, so you receive an exposure with evidence attached, not a raw scanner queue to filter yourself.
Each finding carries a fix instruction written for the person who has to make the change, not a CVE number and a link.
Discovery stays passive and non-intrusive, which is why it needs no penetration test authorisation from the customer before it starts.
Billed per registered domain per month; subdomains discovered underneath it are part of the same unit.
You quote it, we operate it, you deliver it
Your price is the published list price minus 25%, on every line in the catalogue. You decide what your customer pays and keep the difference, so your margin is settled before the quotation leaves your office.
Our engineers work it from Bangkok on UTC+7, against a methodology that is written down rather than improvised per customer. A senior engineer reads every finding before it leaves the building, because you are the one who has to defend it.
Findings, reports and escalations reach you in your template with your logo on them. Your customer talks to you, and our name is not on the ticket.
What a partner checks before putting this on their price list
Do we need the customer's permission before we start?
No account, agent or change on the customer side is required, because discovery stays passive and works from information the customer already publishes to the internet. There is no test authorisation to chase before you can show a first report.
Can we run it on a prospect who is not a customer yet?
Yes — discovery is passive and reads only what that organisation already publishes, so a prospect domain is no different from a customer domain. It is a common way to open a conversation, and the output is yours to hand over however you want to position it.
How is this different from a vulnerability scan?
A vulnerability scan checks hosts you already know about, usually from inside. This starts from what the internet knows about your customer — domains, certificates, exposed services, forgotten hosts nobody has an inventory entry for — and keeps watching them as they change.
Does it replace a penetration test?
No — exposure monitoring tells you what is reachable and what looks weak, while a penetration test proves what an attacker could actually do with it. The natural pairing is exposure every month and a pentest once a year.
What if the customer has hundreds of subdomains?
They are all included, because you are billed per registered domain per month rather than per asset discovered. An estate that grows during the year does not change the invoice.
Can we white-label the report?
Yes — reports are produced in your template with your logo and your contact details, and our name does not appear anywhere in them.
- CRITICAL RDP exposed to the internet 203.0.113.44:3389 2m ago
- CRITICAL Staff credentials in a published combolist 3 accounts · verified 18m
- HIGH TLS certificate expires in 6 days vpn.example.com 1h
- HIGH Dangling subdomain points at an empty bucket old-cdn.example.com 3h
- MEDIUM Login endpoint has no rate limiting portal.example.com 6h
- MEDIUM Tier-2 supplier disclosed a breach supply chain yesterday
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner