Attack Surface Management

One current view of everything you expose to the internet: which hosts exist, what runs on them, how their TLS looks, and a timestamped record of how that changed.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • Ports
  • Running services
  • Technologies
  • TLS status
  • Activity log

what every confirmed target carries in its profile

Topscan attack surface: hosts, services and their status

Security Challenges
Every Team Faces

What happens in practice

  • A deployment exposes a service that was meant to stay internal

  • A certificate expires and users notice before the team does

  • Nobody can say what the perimeter looked like last month

  • An audit asks for activity history that was never recorded

  • Leadership asks for status and assembling the answer takes a week

How Topscan handles it

  • Discovery finds the hosts tied to your domains and connected cloud accounts

  • Every confirmed target gets a profile: ports, services, technologies, TLS

  • Scheduled rescans keep that profile current

  • Findings and changes are timestamped in an activity log

  • Reporting turns that history into something you can hand to an auditor

How Attack Surface Management Works

  1. Step 1

    Add a target

    Start with a domain or an IP. Topscan maps your external environment outward from it — no manual asset list required.

    • Domain & IP input
    • Automatic discovery
    • No inventory setup
    Topscan: discovered hosts ready to be added as targets
  2. Step 2

    Build the host view

    On the hosts you have confirmed, Topscan checks open ports, running services, detected technologies and TLS status, and puts them in one profile. Discovery itself never touches ports — that happens only on targets you approve.

    • Open ports
    • Running services
    • Technologies
    • TLS status
    Topscan: host profile with ports, services and TLS
  3. Step 3

    Rescan on a schedule

    Targets are rechecked on a recurring schedule, so the profile reflects the infrastructure as it is now rather than as it was when you added it.

    • Scheduled scanning
    • Timestamped events
    • New-asset reporting
    Topscan: recurring scan schedule
  4. Step 4

    Use the history

    The activity log gives you a dated trail of what was exposed and when. That is what answers an audit question, and what turns a status update to leadership into a five-minute job instead of a week of assembly.

    • Activity log
    • Historical host data
    • Reporting
    • Audit support
    Topscan: dated activity log of the perimeter
Features

Features & Capabilities in one view

  • Host Profile

    Ports, services, technologies and certificate status for each confirmed target, in one place, without gathering it by hand.

  • SSL/TLS tracking

    Certificate dates on every discovered host, so an expiry is a warning rather than an outage. The oldest we have seen still serving traffic was two years past expiry.

  • Activity log

    A timestamped record of external changes and findings — the artefact an auditor asks for and nobody keeps by hand.

  • Scheduled external scanning

    Recurring checks on confirmed targets, so the picture stays current between pentests.

Who Topscan Is Built For

  • CTO

    One view of what is exposed and what changed, without adding another fragmented workflow.

  • Head of DevOps

    Track internet-facing assets across accounts as services and endpoints keep changing.

  • Senior DevOps Engineer

    Find forgotten services and keep monitoring tied to the infrastructure as it actually is.

  • Tech Lead preparing for an audit

    Use dated records and reporting to support SOC 2 or ISO 27001 preparation. Your auditor should confirm applicability.

Integrate scans into your pipeline

Trigger a scan from your own pipeline and get findings where your team already reads them.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your security

One subscription covers the attack surface, your web apps and your code — against buying an ASM tool, a DAST tool and a code scanner from three vendors.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: adding a domain

Step 1 · Add a domain

One domain is enough to start the map.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
No. A pentest is a deep look on one day; this is a shallow look every day. A pentest tells you how far someone could get, continuous monitoring tells you what changed since Friday.
No. It is built for CTOs, DevOps leads and engineers who carry security alongside delivery — the workflow is discover, confirm, monitor, report.
You authorise scanning when you add a target and confirm ownership. Discovery uses only public registries, DNS and a single ordinary HTTP request. Port checks and active templates run only on targets you have explicitly confirmed — that boundary is deliberate, because an unauthorised port scan is a criminal matter in some jurisdictions.
Every finding ships with the evidence that produced it — hostname, status code, response header, certificate date — so you can verify it in a browser in ten seconds. Mark it as a false positive or snooze it, and it stops resurfacing.
Activity history and reporting help assemble the evidence, and we are going through a SOC 2 audit ourselves. Your auditor should confirm applicability.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

Find vulnerabilities before attackers do

Add one domain and see what answers. 14 days of the full Advanced plan, no card.

14 days of the full Advanced plan · no card required