Asset Discovery & Perimeter Monitoring
Your perimeter is bigger than your inventory. Topscan maps every internet-facing host tied to your domain — including the staging box from last year and the API gateway nobody owns — and keeps that list current as it changes.
14 days of the full Advanced plan · no card required · first results in 5–10 minutes
- ~16 hostnames found
- ~10 answering
- most teams expect 3–4
what the first run turns up at a company your size — and discovery uses no licences, so mapping the whole footprint costs nothing

Security Challenges
Every Team Faces
What happens in practice
A release exposes a service nobody wrote down
Cloud accounts create resources faster than the spreadsheet updates
Staging environments and old API endpoints stay online for months
A certificate expires on a host that quietly dropped out of monitoring
The documented perimeter and the real one drift apart
How Topscan handles it
Discovery maps subdomains, IPs, APIs and exposed services from public records
New hosts surface every cycle, not at the next audit
Connected AWS accounts feed discovery automatically
Certificate dates are tracked on every host discovery finds
Nothing enters monitoring until you confirm it
How Asset Discovery Works
Step 1
Start from what you own
Add one domain or IP. Discovery maps outward from there — there is no asset list to prepare and no spreadsheet to maintain.
- Domain & IP input
- Automatic expansion
- No manual inventory

Step 2
See the whole footprint
You get the hostnames tied to your domain, which of them answer, what runs on them and when their certificates expire. In companies of your size that list usually runs to around sixteen names, with about ten of them answering. Most teams expect three or four.
- Subdomains & IPs
- APIs & services
- Detected technologies
- TLS status

Step 3
Confirm what to monitor
New hosts arrive in a review queue. You decide what becomes a monitored target and what gets dismissed. Discovery identifies what exists; it never probes on its own.
This is also where the bill is decided: discovery is free, and a licence is used only when a host enters monitoring.
- Review queue
- Confirm before scanning
- Dismiss what isn't yours

Step 4
Stay current as it changes
Discovery runs on a schedule, so the inventory keeps pace with deploys and cloud changes. Anything that appeared this week is reported this week.
- Recurring discovery
- New-asset notifications
- Cloud-connected assets

Features & Capabilities in one place
Continuous asset discovery
Subdomains, IPs, APIs and exposed services, mapped outward from public certificate transparency logs and DNS.
Living inventory
One current view of what faces the internet — not a list that was accurate in March.
New asset detection
A host that appeared this week is reported this week, together with the technologies running on it and its certificate dates.
Confirmation before scanning
Discovery finds what exists. Nothing is probed, and no port is touched, until you approve the host as a target.
Who Topscan Is Built For
CTO
Know the real size of your external footprint without commissioning an audit.
Head of DevOps
Catch shadow infrastructure and forgotten services as environments change.
Senior DevOps Engineer
Keep an accurate asset inventory without maintaining it by hand.
Teams preparing for an audit
Show a current, monitored inventory of internet-facing assets. Your auditor should confirm applicability.
Send new assets straight to your team chat
Discovery events go where your team already works — no extra dashboard to keep open.
GitHub
GitLab
Slack
Jira
AWS
- CI/CD webhook
Fair pricing for your perimeter
Discovery maps everything; you pay only for the hosts you decide to monitor.
Basic
$129/ month
For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.
- 3 infrastructure hosts — an IP, a hostname or a subdomain
- 1 web application tested while it’s running
- 10 repositories scanned by SAST
Advanced
14 days free trialBest value$269/ month
For companies of 20–60 with AWS infrastructure and active CI/CD.
- 8 infrastructure hosts, 2 web applications, 20 repositories
- AWS integration — cloud assets discovered automatically
- Slack routing and Jira tickets for findings
Pro
$449/ month
For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.
- 15 infrastructure hosts, 4 web applications, 40 repositories
- Custom SLA by severity and per target, Severity Override with an audit trail
- Two-way CI/CD webhook and Attack Surface change tracking with alerts
You pay for what you monitor — not for seats, scans or findings
Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.
In every paid plan
- External infrastructure scanning
- Static code analysis, all supported languages
- Remediation history with dates
- Role-based access control
- Attack Surface and Security Score
- Dependency scanning (SCA)
- CI/CD webhook to trigger a scan
- Unlimited scans and users
- Web application scanning
- Statuses, SLA and snooze on every finding
- Email alerts
- Free read-only seats for auditors
Walk through it before you sign up
Five clicks through the real product. No form, no demo call.

Step 1 · Add one domain
No inventory to prepare.
Step 1 of 5 — click the highlighted spot
FAQ
Topscan builds on the best in class scanning engines
Still have questions?
Contact usFind the hosts you forgot before someone else does
Add one domain. The first map takes about five minutes, and it costs nothing to look.
14 days of the full Advanced plan · no card required