Contact us

Platform · Discovery

Find what you don't know about, without touching anything you don't own.

Three discovery surfaces: passive external OSINT, identity and OAuth grants, and what your people declare they actually use. Together they produce a technology estate with ownership, not just a list of detections, but who uses it, why, and whether it matters.

Available

How it works

Technology & Asset Discovery, step by step.

01

Look from outside

Passive sources only: DNS, certificate transparency, public endpoints. No probing, no login attempts, no scanning what you don't own.

02

Look at identity

OAuth grants and SSO logs show which tools actually have access to company data, the Shadow AI that never went through IT.

03

Ask people

Discussions surface what logs can't: why the tool is used, what for, and what would happen without it.

04

Assign ownership

Every asset gets an owner, a purpose, and a posture, detection without ownership is just anxiety.

Evidence tiers

Where each claim stands.

T1

Declared

Tools people tell us they rely on.

T2

Corroborated

Declared usage matched to an OAuth grant or SSO record.

T3

Verified

Externally observable assets: subdomains, certificates, mail records.

Stated limits

What it will not do.

Will not touch personal accounts or collect passwords.

Will not scan, probe, or attempt logins on anything you don't own.

Will not treat an unknown tool as misconduct, discovery is not discipline.

Will not require agents or software installed on employee devices.

Features

3 available · 1 in preview · 1 on the roadmap.

FeatureStatus
Passive external footprint scanThe free scan on this site is this surface.Available
Identity & OAuth grant inventoryAvailable
Shadow AI detection via grantsDesign-partner preview
Asset ownership assignmentAvailable
Continuous estate monitoringRoadmap · Q1 2028
Available, ships today Design-partner preview Dated roadmap

Questions we actually get

Asked by real skeptics.

What exactly do you touch?
Three things: public data about your domain (DNS, certificate logs), identity grants you explicitly authorize read-only access to, and conversations with your people. Nothing else. The full scope is documented so your security team can approve it without asking us.
Where does the data live?
Canadian data residency is standard. Enterprise deployments offer dedicated tenancy, customer-managed keys, and air-gap options. Full details in the Trust Center.
Is the free scan the same thing?
It's the first of the three surfaces, the passive external one, the only one that needs nothing from your team. The other two are where the surprises are.

Related

See this pillar inside a real diagnostic.

The two-week engagement uses every pillar above, and hands you the evidence-linked output.