How it works

Nothing Is Touched Until It Is Proven Yours

Coverage reaches an asset in three steps, and the score reached in the second decides what happens in the third.

Nothing is installed anywhere, and no credential is ever held.

Find It. Prove It. Secure It.

  1. ClearSkies ASM Discover view, step two: assets found under the authorized domains, with their discovery source and when each was first seen

    Find it before they do

    Discovery runs continuously against the root domains the customer authorizes, querying many independent sources rather than one scanner: Certificate Transparency logs watched live, cloud object storage enumerated across the public providers, and passive DNS, registration records and internet-wide scan data checked against each other. An asset enters inventory only once more than one source agrees it is real.

  2. ClearSkies ASM Discover view, step one: domain ownership verification, with each domain pending or verified

    Prove it is yours

    Several independent signals are scored in parallel and combined into one confidence score from 0 to 100, so no single signal pushes an asset into scope on its own. They fail differently: certificate lineage, WHOIS and RDAP data, DNS and SOA relationships, favicon hashes, JARM fingerprints, and address and domain reputation. Every score carries its reasoning, so an analyst can defend it when an owner disputes it.

  3. ClearSkies ASM Discover view, step three: scanned assets with their findings, risk score and last scan, and the findings of one asset expanded

    Then look for the way in

    Only assets in the confirmed band are actively probed, which keeps the platform away from infrastructure that may belong to somebody else. Within the confirmed inventory the assessment covers known vulnerabilities and the misconfigurations that carry no CVE at all: exposed management interfaces, default or missing authentication, open cloud storage, weak or expiring TLS, and missing SPF, DKIM and DMARC records, which are frequently the actual way in.

Confidence That Determines What Happens Next

A false positive in exposure management is almost never a detection error. It is an attribution error: a shared address, a parked domain or a hosting range swept into scope by resemblance. That failure costs more than a missed finding, because it reaches a report. So the decision is made deterministically, recorded with its evidence, and it governs the platform’s behavior from that point on.

Confidence bandScoreWhat the platform does
Confirmed70 and aboveAutomatically in scope. Active assessment permitted. Alerts may fire. Findings are eligible for board and client reporting.
Likely40 to 69Automatically in scope with elevated review priority, and surfaced for analyst confirmation before it carries the same weight as a confirmed finding.
Suspicious10 to 39Held in the shadow-IT queue. Observed passively, never actively probed. An analyst decision is required to promote or discard it.
UnknownBelow 10Discarded from inventory. Logged for traceability so the decision is auditable, but not surfaced in any queue or report.

A platform that promotes everything it finds will eventually probe infrastructure that is not the customer’s, and a platform that promotes nothing is a scanner with an inbox.

The four bands make the decision explicit, evidenced and reviewable, so the line between what is monitored and what is touched is a matter of record rather than of configuration drift.

Analyst decisions feed back into the engine. A contested asset resolved by an analyst seeds the auto-learning model, a false-positive mark stops the finding recurring as noise, and favicon and JARM baselines retrain on each tenant’s own confirmed assets, so accuracy improves with every scan rather than through manual tuning.

Every Change Tracked. Every Finding Driven to Resolution.

An attack surface is a timeline rather than a list, so every asset is versioned and alerting fires on what moved. Findings also end somewhere: each runs through an explicit state machine from new to resolved, risk acceptance carries a mandatory expiry date, and the work happens in Jira, Slack, Teams and email rather than in a portal nobody opens.

ClearSkies ASM Discover view: the verify, discover, scan and monitor pipeline, enrolled domains, and live certificate-transparency events including a flagged typosquat

Nothing to Install. Nothing to Hand Over. No Blind Spots.

  • Agents required

    None. No software is installed on any customer or third-party system at any point.

  • Credentials required

    None. Discovery and assessment are unauthenticated and work from the public internet only.

  • Internal inventories

    Not required. Discovery is unseeded, so a customer does not have to hand over a database export to be covered.

  • Dark web scope

    Included per authorized root domain, covering credential leaks, breach dumps, brand abuse and access-broker listings tied to that domain.

See Your Own Surface for Fifteen Days

Discovery and assessment run against your own root domains before any commitment, so the first thing you see is your own inventory rather than a demonstration environment.

Start a 15-day trial