Skip to main content
For startups and small teamsFirst-pass recon

See your attack surfacebefore they do.

Request a free first pass with your domain and permission. Mapping runs in minutes. A person validates the findings. You get a client-ready summary. No card or commitment is required.

  • First pass is free
  • Validated, not noise
  • Human review intact

What the first pass
maps.

The scan starts from your domain and works outward across everything reachable from the open internet. This is the external surface an attacker sees first.

01 · DOMAINS

Domains and subdomains

We enumerate the domains and subdomains tied to your name, including the ones nobody remembers standing up.

02 · SERVICES

Exposed services

Open ports, public services, and forgotten infrastructure that an attacker can reach from the open internet.

03 · PORTALS

Login portals

Admin panels, dashboards, and auth endpoints that are reachable without ever touching your network.

04 · SECRETS

Leaked secrets

API keys, tokens, and credentials exposed in public code, configs, or responses, validated before we report them.

Leaked secrets → See how the exposed API keys scanner validates leaked credentials, or browse the exposure library.

A validated summary.
Not scanner noise.

A raw scanner hands you thousands of alerts and walks away. Adversary validates first, then reports what an attacker can actually reach.

In the summary
  • A validated list of real exposures, not every theoretical hit.
  • Evidence attached to each finding, so the result is checkable.
  • A severity on every item, so you fix the right thing first.
  • A remediation note per finding, written for an engineer.
  • A summary you can hand to a customer, an auditor, or an investor.
What we leave out
  • Thousands of low-signal alerts you have to triage yourself.
  • Findings with no proof behind them.
  • A wall of CVSS numbers with no path to a fix.
  • Generic output that ignores what is actually reachable.
  • A dashboard you have to learn before it tells you anything.

New to the terms? → Read the attack surface glossary

Built for the team that shipped first.

You built the product before you built the security program. That is normal. A first-pass scan tells you what that tradeoff exposed, so you can fix the parts that matter before a customer review, an auditor, or an attacker finds them for you.

Straight answers
before you ask.

Is the first-pass scan really free?
Yes. The first-pass external scan is free, and you request it through the contact form on this page. We map your public-facing surface and send back a short, validated summary at no cost. Deeper, ongoing assessment work is a paid engagement, and we will tell you the scope and price before any of that starts. There is no card and no commitment to get the first pass.
What do I get back?
A client-ready summary of your external attack surface, not a raw scanner dump. It lists the domains, subdomains, exposed services, and login portals we found, plus any leaked secrets or misconfigurations we could validate. Each item carries evidence, a severity, and a remediation note. We drop the noise. You see what an attacker would actually reach, and what to fix first.
How long does it take?
The first-pass mapping runs in minutes once we have your domains. Validation and the written summary follow after a person reviews the findings, so expect the report rather than an instant dashboard. We confirm exposures before we report them, so the turnaround buys you accuracy. You get a summary you can hand to your team or an investor without caveats.
Who is this for?
Startups and small teams without a dedicated security function. Founders preparing for a customer security review, a SOC 2 effort, or due diligence. Teams that shipped fast and want to know what they exposed along the way. If you have one domain or a small portfolio and no clear picture of your external surface, this is the entry point.
What do you need from me to start?
Your primary domain and permission to look at the assets that belong to you. We only assess the external surface you own or control. We do not test third parties on your behalf. Request the scan, confirm the scope in the reply, and we begin from there.
Is this a self-serve scanner I can run myself?
No. There is no button that runs an automated scan against an arbitrary domain. You request a scan, we confirm scope, and Adversary runs the first-pass mapping with human review on the findings. That review is the point. It is why you get validated exposures instead of a list of maybes.

Use the internet without the internet using you.

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.

Free for 30 days. No card required.

Ghost. A private route for your browser. Shield. An isolated browser, off your device. Choose the mode. Close when finished.