Home / Continuous / Surface

Surface

Everything you expose to the internet, found and kept current. Surface answers what exists, and it is where every other module starts.

This module is part of the base package

Every other module depends on an accurate picture of what exists. An unverified asset register is where missed exposure tends to hide, and an application nobody has discovered cannot be tested. Surface is paired with Perimeter in the base package: Surface finds what is there, Perimeter tests it.

What it covers

  • Domains, subdomains and hosts, including the ones nobody meant to publish
  • A verified asset register, kept current as your estate changes
  • New names as they appear, through certificate transparency and DNS
  • Ownership attribution, so we know which assets are actually yours
  • Change detection: what appeared, what disappeared, and what moved since the last cycle

How the work is carried out

A consultant directs this module and does the work that needs judgement, with automation carrying the continuous load between their passes. Your intervals are set during onboarding and recorded in the service agreement, because a schedule that suits one application would be wrong for a large, sprawling estate. What is fixed is the shape: a scheduled layer that runs the same checks on fixed intervals so change is visible, and an exploratory layer that a consultant directs based on what turns up. Reporting is monthly.

What the tooling handles

  • Keeps discovery and enumeration running across the full in-scope range
  • Watches certificate transparency and DNS for names you did not know about
  • Flags every change to the estate between consultant passes

What our consultants do

  • Decide which newly found assets are yours and which belong to someone else
  • Verify scope and domain ownership before anything runs
  • Judge which changes matter and direct the next cycle accordingly
  • Confirm the register with you, so testing runs against agreed ground

Every finding in this module is reproduced or confirmed by a consultant before it reaches you.

What you receive

  • Validated findings, each reproduced or confirmed by a consultant
  • A maintained asset register you can rely on
  • A monthly written report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • Verification of fixes once you have applied them

What is out of scope

  • Testing the services that are found, which is the Perimeter module
  • Authenticated testing of applications and APIs, which is the Access module
  • Cloud control plane and IAM configuration, which is the Cloud module
  • Anything not on the confirmed asset register

Prerequisites

Nothing runs until these are in place. We pause rather than proceed against an unconfirmed register.

  • Signed authorisation to test
  • A starting list of domains and ranges, which we verify rather than take on trust
  • Domain ownership we can verify independently
  • No credentials are required for this module

Next module: Perimeter