External Vulnerability Scanning

Your external perimeter changes every week, and nobody has a free afternoon to walk it. Topscan scans everything of yours that faces the internet on a schedule, orders the findings by what to fix first, and keeps one number you can show upward.

14 days of the full Advanced plan · no card required · first results in 5–10 minutes

  • ~16 hostnames found
  • ~10 answering
  • most teams expect 3–4

what the first scan turns up at a company your size

Topscan targets list: monitored hosts with findings by severity and last activity

Security Challenges
Every Team Faces

What happens in practice

  • Security work keeps losing to releases, incidents and infrastructure changes

  • A service goes up that nobody wrote down, and nothing flags it

  • Something exposed last month was fine last month — nobody rechecked

  • Raw scanner output arrives with no order to work in, so it stays unread

  • Leadership asks how things stand and the honest answer takes a week to assemble

How Topscan handles it

  • Discovery maps domains, subdomains, IPs and the services answering on them

  • Scans run on a recurring schedule, so nothing depends on someone remembering

  • Every finding names the affected target, its severity and the fix

  • Findings arrive in an order of work, CRITICAL first, each with a remediation deadline

  • One security score and a remediation history answer the upward question in a minute

How External Scanning Works

  1. Step 1

    Map what faces the internet

    Add your domains and IP addresses. Discovery maps outward from there using public certificate transparency logs, DNS and one ordinary HTTP request per host, and gives you the hostnames that exist, which of them answer and what runs on them.

    In companies of your size that list usually comes to around sixteen names, with about ten answering. Most teams expect three or four.

    • Domains, subdomains & IPs
    • Services answering
    • Technology detection
    Topscan Discovery: found hostnames with their status code and detected technologies
  2. Step 2

    Confirm the targets, then scan them

    You choose which discovered hosts become monitored targets. Port checks and active templates run only on targets you have explicitly confirmed — discovery itself never touches ports. Confirming a target is also how you state you are authorised for it.

    • Review queue
    • Confirm before scanning
    • Open ports on confirmed targets
    Attack surface: a prompt to review nine newly discovered hosts above the confirmed targets
  3. Step 3

    Fix in a useful order

    Instead of raw scanner output you get findings ordered CRITICAL to LOW, each with the affected target, what was found, a recommended fix and a remediation deadline. Every result carries the evidence it came from, so the engineer who owns it can confirm it in a browser before touching anything.

    • CRITICAL to LOW ordering
    • Recommended fix
    • Remediation deadline
    Issues: a finding with its severity, SLA deadline and the affected targets
  4. Step 4

    Scan again, and see what moved

    The schedule is the product. Between two scans four days apart, half of one team’s short-lived hosts had disappeared on their own and the rest were still answering — which is exactly why a list made once is already wrong.

    Remediation history and a single security score from 0 to 100 turn that into something you can put in front of a board without translating scanner output.

    • Recurring scans
    • Security Score 0–100
    • Remediation history
    • Audit evidence
    Scans: a weekly schedule above completed scans with the number of issues each one found
Features

Features & Capabilities in one workflow

  • External footprint discovery

    Domains, subdomains, IPs and the services answering on them, mapped outward from public certificate transparency logs and DNS — including the assets nobody wrote down.

  • Recurring scans on confirmed targets

    New exposures are found on the schedule, not at the next audit. What went up this week is reported this week.

  • Findings in an order of work

    Severity ranking, the affected target, a recommended fix and a deadline — so the list can be worked through instead of read.

  • One number for upward reporting

    A security score from 0 to 100 plus remediation history: current status, trend, and the fixes behind it, without walking anyone through raw output.

Who Topscan Is Built For

  • CTO at a software company

    When security has no dedicated owner, get recurring visibility into what’s exposed and a clear list of what to fix first.

  • Head of DevOps

    Infrastructure moves fast. Track new services, cloud instances and public assets as they appear, not after someone stumbles on them.

  • Teams preparing for an audit

    Use monitoring activity and remediation history to support SOC 2 or ISO 27001 preparation instead of rebuilding evidence at the last minute. Your auditor should confirm applicability.

  • Anyone reporting upward

    Show a CEO or a board one score, the trend, and the fixes behind it — not a scanner export.

Findings go where your team already works

Scans trigger from your own pipeline and results arrive in the tools your engineers already have open — no extra dashboard to keep watch on.

  • GitHub
  • GitLab
  • Slack
  • Jira
  • Email
  • AWS
  • CI/CD webhook

Fair pricing for your perimeter

One plan covers the external perimeter, your web apps and your code — which is why one small team can afford to run all three.

  • Basic

    $129/ month

    For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.


    • 3 infrastructure hosts — an IP, a hostname or a subdomain
    • 1 web application tested while it’s running
    • 10 repositories scanned by SAST
  • Advanced

    14 days free trialBest value

    $269/ month

    For companies of 20–60 with AWS infrastructure and active CI/CD.


    • 8 infrastructure hosts, 2 web applications, 20 repositories
    • AWS integration — cloud assets discovered automatically
    • Slack routing and Jira tickets for findings
  • Pro

    $449/ month

    For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.


    • 15 infrastructure hosts, 4 web applications, 40 repositories
    • Custom SLA by severity and per target, Severity Override with an audit trail
    • Two-way CI/CD webhook and Attack Surface change tracking with alerts

You pay for what you monitor — not for seats, scans or findings

Discovery costs nothing: it maps your whole footprint and a licence is used only when you put a host under monitoring. Scans are never billed, so a weekly schedule costs the same as a monthly one, and the whole team reads findings on any paid plan — developers, whoever tracks remediation, and read-only seats for auditors.

In every paid plan

  • External infrastructure scanning
  • Static code analysis, all supported languages
  • Remediation history with dates
  • Role-based access control
  • Attack Surface and Security Score
  • Dependency scanning (SCA)
  • CI/CD webhook to trigger a scan
  • Unlimited scans and users
  • Web application scanning
  • Statuses, SLA and snooze on every finding
  • Email alerts
  • Free read-only seats for auditors
Need more than your plan includes? Extra licences are $4 per infrastructure host, $45 per web application and $9 per repository — the same rate on every paid plan, with no volume pricing to negotiate. The 14-day trial gives you the full Advanced plan and needs no card.

Walk through it
before you sign up

Five clicks through the real product. No form, no demo call.

Topscan: adding a target domain

Step 1 · Add a target

Point Topscan at a domain or an IP. Nothing else to prepare.

Step 1 of 5 — click the highlighted spot

FAQ

Topscan builds on the best in class scanning engines

Still have questions?

Contact us
Add a domain while you sign up and discovery answers within five to ten minutes — that is your first map of what faces the internet, before anything is scanned. Scanning comes after you confirm what to monitor: a fast check finishes in five to fifteen minutes, a full infrastructure audit in thirty to ninety, and a deep web application scan can run up to a few hours. Those are typical times, not guarantees — the real duration depends on the target: how many hosts answer, how large the application is and how quickly it responds.
Running a scanner is a Tuesday afternoon. Knowing what to run it against next month, after two releases and a new cloud account, is the part that doesn't fit in an afternoon. Discovery, the recurring schedule, the ordering and the reporting sit in one workflow, so the checks keep happening when the week gets busy.
Domains, subdomains and IP addresses, the web applications and APIs answering on them, exposed services and open ports on confirmed targets, and the technologies detected across those hosts.
No. A pentest is a deep look on one day; this is a shallow look every day. What tends to catch teams your size isn't the flaw a pentester would find — it's the host that appeared three months after the pentest and nobody wrote down.
Discovery uses only public registries, DNS and a single ordinary HTTP request per host. Port checks and active templates run only on targets you have explicitly confirmed, and confirming a target means you state you are authorised for it.
Request rate is limited and the engine observes rather than exploits — nothing destructive is sent and no data is modified.
It produces the two things auditors ask for: evidence of regular scanning and a current record of what is exposed and what was fixed. Auditor seats are free and read-only. Your auditor should confirm applicability.
Customer data is stored in the Hetzner cloud in Ashburn, Virginia, US. None of the developers have access to the production environment — only the Head of DevOps does, and every action he takes is logged. No customer data leaves our infrastructure or is passed to third-party systems, including third-party AI services: everything happens inside a closed environment. We are currently going through a SOC 2 audit and track our processes in Drata. If you delete your account, all data is permanently removed from our servers within 180 days.

See what answers on your perimeter this week

Add one domain. The first map takes about five minutes, and it costs nothing to look.

14 days of the full Advanced plan · no card required