Asset Discovery & Perimeter Monitoring

Your perimeter is bigger than your inventory. Topscan maps every internet-facing host tied to your domain — including the staging box from last year and the API gateway nobody owns — and keeps that list current as it changes.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • ~16 hostnames found
  • ~10 answering
  • most teams expect 3–4

what the first run turns up at a company your size — and discovery uses no licences, so mapping the whole footprint costs nothing

Topscan Discovery: discovered hostnames with their status code and detected technologies

Security Challenges
Every Team Faces

What happens in practice

  • A release exposes a service nobody wrote down

  • Cloud accounts create resources faster than the spreadsheet updates

  • Staging environments and old API endpoints stay online for months

  • A certificate expires on a host that quietly dropped out of monitoring

  • The documented perimeter and the real one drift apart

How Topscan handles it

  • Discovery maps subdomains, IPs, APIs and exposed services from public records

  • New hosts surface every cycle, not at the next audit

  • Connected AWS accounts feed discovery automatically

  • Certificate dates are tracked on every host discovery finds

  • Nothing enters monitoring until you confirm it

How Asset Discovery Works

  1. Step 1

    Start from what you own

    Add one domain or IP. Discovery maps outward from there — there is no asset list to prepare and no spreadsheet to maintain.

    • Domain & IP input
    • Automatic expansion
    • No manual inventory
    Topscan: adding a target by domain or IP
  2. Step 2

    See the whole footprint

    You get the hostnames tied to your domain, which of them answer, what runs on them and when their certificates expire. In companies of your size that list usually runs to around sixteen names, with about ten of them answering. Most teams expect three or four.

    • Subdomains & IPs
    • APIs & services
    • Detected technologies
    • TLS status
    Topscan Discovery: hostnames with their status code and detected technologies
  3. Step 3

    Confirm what to monitor

    New hosts arrive in a review queue. You decide what becomes a monitored target and what gets dismissed. Discovery identifies what exists; it never probes on its own.

    This is also where the bill is decided: discovery is free, and a licence is used only when a host enters monitoring.

    • Review queue
    • Confirm before scanning
    • Dismiss what isn't yours
    Attack surface: a prompt to review nine newly discovered hosts above the confirmed targets
  4. Step 4

    Stay current as it changes

    Discovery runs on a schedule, so the inventory keeps pace with deploys and cloud changes. Anything that appeared this week is reported this week.

    • Recurring discovery
    • New-asset notifications
    • Cloud-connected assets
    Scans: a recurring schedule above completed scans with the number of issues each one found
Features

Features & Capabilities in one place

  • Continuous asset discovery

    Subdomains, IPs, APIs and exposed services, mapped outward from public certificate transparency logs and DNS.

  • Living inventory

    One current view of what faces the internet — not a list that was accurate in March.

  • New asset detection

    A host that appeared this week is reported this week, together with the technologies running on it and its certificate dates.

  • Confirmation before scanning

    Discovery finds what exists. Nothing is probed, and no port is touched, until you approve the host as a target.

Who Topscan Is Built For

  • CTO

    Know the real size of your external footprint without commissioning an audit.

  • Head of DevOps

    Catch shadow infrastructure and forgotten services as environments change.

  • Senior DevOps Engineer

    Keep an accurate asset inventory without maintaining it by hand.

  • Teams preparing for an audit

    Show a current, monitored inventory of internet-facing assets. Your auditor should confirm applicability.

Send new assets straight to your team chat

Discovery events go where your team already works — no extra dashboard to keep open.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your perimeter

Discovery maps everything; you pay only for the hosts you decide to monitor.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: adding a domain

Step 1 · Add one domain

No inventory to prepare.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
Subdomains, IP addresses, APIs, exposed services and the technologies running on them, plus the certificate dates on every host across your external footprint.
Every TLS certificate ever issued for your domain is published permanently in public certificate transparency logs — that is how the system is designed to work, and those logs are open to everyone. Discovery reads those records, resolves the names and makes one ordinary HTTP request per host: the same request your browser makes when you type the address. Public registries, DNS, one HTTP GET. No ports are checked, nothing is probed, and no credentials are used anywhere.
No. New hosts arrive in a review queue and are only scanned after you confirm them as targets. Discovery itself does not touch ports.
No. External discovery needs only a domain or an IP. An AWS account is connected with an access key stored in an encrypted vault. Nothing runs on your servers.
No. Discovery is included and maps your whole footprint at no charge. A licence — $4 a month per infrastructure host — is used only when you put a host under monitoring, so the hosts you dismiss cost nothing.
It produces the two things auditors ask for: evidence of regular scanning and a current inventory of what is exposed. Auditor seats are free and read-only. Your auditor should confirm applicability.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Find the hosts you forgot before someone else does

Add one domain. The first map takes about five minutes, and it costs nothing to look.

14 days of the full Advanced plan · no card required