Type a domain
One root domain is enough — we discover the rest ourselves. No verification needed for a passive scan.
Takes 5 secondsFree · no signup · no agent
Type your domain. In about two minutes we map every subdomain, IP, open port and outdated product we can find from outside — then tell you, in plain English, which three things to fix first.
Domain to scan
How it works
One root domain is enough — we discover the rest ourselves. No verification needed for a passive scan.
Takes 5 secondsDNS, certificate logs, WHOIS and banners are stitched into a single picture of your perimeter.
Runs in ~2 minutesYou get a ranked list of what to fix first, each item explained in plain English with an effort estimate.
Shareable link, no loginCoverage
Four passes over your public footprint — each one written up in language you can forward to a non-engineer.
Forgotten hostnames, shadow IT and stale staging edges that attackers still probe every week.
staging. · old-blog. · vpn.Every internet-facing TCP service, with a straight answer on whether it should be public at all.
3306 MySQL → should never be openWeb servers, frameworks, CDNs and versions read from public banners and response headers.
nginx 1.18.0 · PHP 7.4 (EOL)Discovered products cross-referenced against known CVEs, then ranked by real-world exploitability.
CVE-2024-4577 · exploited in the wildQuestions
Still unsure? A security engineer will walk your results with you — free, no pitch.
Book 20 minutes →EASM continuously maps what the internet can see of your organization — domains, subdomains, IPs, open ports and the products running on them. Trusteed uses that map as the first stage of CTEM: discover exposure, validate what is actually exploitable, then mobilize a fix.
Free plan keeps watching one domain, alerts you on new hosts and ports, and filters the noise so you only hear about what matters.