Continuous security monitoringMeet the team

Continuous Security Assurance, Backed by Evidence. We find it. We fix it.

Continuous security testing with evidence-led verification. High and Critical candidates are cross-checked before they are presented as confirmed findings.

No login required. Passive scan only — no intrusive testing without ownership verification.

60s
First results
19
Specialised modules
2-pass
Evidence review
Perimeter posture Live
B
portal.meridian-payments.co.uk
Security Posture Score: 79/100 · Last scan: today
TLS / cipher hygiene
PASS
Exposed secrets (.git, .env)
PASS
Email security (DMARC)
PASS
Subresource integrity
MEDIUM
Security headers
LOW
19 modules · 42 controls assessedCross-verified ✓

Evidence and assurance controls built into every paid scan

Captured evidence
HTTP, DNS and TLS records
Inspectable
Review controls
Uncertain High/Critical candidates held
Fail closed
Audit history
Protected reports and measured changes
Traceable
Aligned to:OWASP Top 10CVSS 3.1CWESOC 2 control mappingGDPR control mapping

Governance and assurance standards

Security and AI assurance backed by certified management systems

Certified information security management

ISO/IEC 27001:2022

PerimAssure is certified to ISO/IEC 27001:2022. Its information security management system supports controlled operations, evidence handling and continual improvement across the service.

PerimAssure certified management system

Certified AI management

ISO/IEC 42001:2023

PerimAssure is certified to ISO/IEC 42001:2023. Its AI management system applies evidence traceability, human review, bounded decisions and audit history to support responsible AI governance.

PerimAssure certified management system

Security evidence you can inspect

Every finding is backed by captured evidence. Every AI verdict cites a specific HTTP response, DNS record, or TLS parameter. Unverified High and Critical candidates are held for analyst review.

Evidence-first

No CVEs, IPs, or versions introduced by the model. Every claim links to raw captured evidence you can verify yourself.

Evidence-led noise reduction

Wildcard DNS profiling, CDN detection, and adversarial cross-verification suppress common scanner noise and route uncertain High/Critical candidates to review.

Posture over time

Scheduled scans build measured history. See what improved, what regressed and what is new — with evidence for every change.

For CISOs, CTOs & Board-level

Replace the annual external-security snapshot with continuous security monitoring

Your board needs current evidence, not an annual snapshot. PerimAssure tracks externally observable posture and measured changes between specialist assessments.

Traditional pentest

  • • Deep, scoped point-in-time assessment
  • • Can include manual, authenticated and internal testing
  • • Best suited to defined systems and assurance events
  • • Limited visibility between assessment dates
  • • Complements continuous external monitoring

PerimAssure

  • ✓ From £149 per asset per month
  • ✓ First report delivered in minutes, not weeks
  • ✓ Assure monthly; Assure+ daily
  • ✓ CVE matching when version evidence is observed
  • ✓ Evidence-led cross-verification with uncertain High/Critical candidates held for review

Measured posture history

Track a higher-is-better Security Posture Score, the A–F grade and the exact findings introduced or resolved at each scheduled scan.

Version-matched CVE intelligence

Observed version fingerprints are checked against current vulnerability intelligence. Unversioned technologies are not converted into generic CVE claims.

Protected decision-ready evidence

Classified endpoints, canonical technical records and control mappings stay within the authenticated portal and protected report stream.

For DevOps & SecOps teams

Nineteen specialised modules. One inspectable evidence trail.

19 specialised modules cover externally observable configuration, exposure and attack-surface signals. Findings retain captured evidence and relevant CWE/OWASP mappings.

TLS & Cipher AuditSnapshot
DNS HygieneSnapshot
Web App SecuritySnapshot
Subdomain EnumerationAssure
Cloud Storage ExposureAssure
Email SecurityAssure
Service DiscoveryAssure
JavaScript AnalysisAssure
Supply Chain RiskAssure
API Security & FuzzingAssure+
AI Red Team (LLM)Assure+
Attack Surface DiscoveryAssure+
Breach & Dark Web IntelAssure+
CDN & Cache SecurityAssure+
Access Control AuditAssure+
GraphQL SecurityAssure+
BEC ResilienceAssure
CDN Origin ExposureAssure+
Out-of-band ConfirmationAssure+

How we eliminate false positives

LAYER 1

Wildcard guard

DNS catch-all profiling before enumeration. If *.domain resolves identically, subdomain findings are suppressed.

LAYER 2

Platform awareness

CDN/serverless detection from header signatures. Origin-hunting skipped when behind Cloudflare, Fastly, or Vercel.

LAYER 3

Evidence-only rule

AI cannot introduce findings. Every verdict must cite a specific HTTP response, DNS record, or TLS parameter.

LAYER 4

Fail-closed verifier

If AI cross-verification is uncertain, findings are withheld — never promoted to confirmed.

How it works

Three steps from domain to actionable intelligence. No agents to install, no access to grant.

01

Enter your domain

Type your domain and hit scan. We begin passive reconnaissance immediately — no login, no configuration, no access required.

02

We scan externally

Specialised modules assess TLS, DNS, headers, subdomains, version-matched CVEs, breach signals, supply chain and API exposure. Findings retain captured evidence.

03

Get your report

A grade, higher-is-better Security Posture Score, measured changes and prioritised findings — with protected evidence and remediation guidance.

The people behind PerimAssure

Built by founders and operators, not a faceless scanner.

Experience across commercial strategy, AI engineering, leadership and communication shapes the way we build security assurance that teams can use.

Meet the executive team

Thomas Davies

Founder & CEO

Xen Lategan

Co-founder & CTO

Kim Wylie

Founding Operating Partner and Fractional Chief People Officer

Tom Buttle

Founding Operating Partner

The old model is broken

You shouldn't have to choose between depth and frequency. Or between accuracy and affordability.

Manual PentestBasic ScannersPerimAssure
Cost per asset£5,000–£15,000Low-cost scannersFrom £149/mo
Time to first report4–6 weeksMinutesMinutes
Testing frequencyDefined by engagementVariesAssure monthly · Assure+ daily
Depth of testingDeep, manual and scopedUsually broad and automatedEvidence-led external assessment
Finding verificationSpecialist judgementVariesCaptured evidence + review gates
CVE intelligencePoint-in-timeOften genericVersion-matched on scheduled scans
Attack surface mappingManual reconVaries19 specialised modules
Breach intelligenceNot includedNot includedDark web monitoring
Evidence transparencyVaries by testerMinimalFull raw evidence

Continuous external security from £149 per asset.

Start with monthly active testing through Assure, or choose Assure+ for daily monitoring, deeper reconnaissance and breach intelligence. Enterprise services are scoped to your estate.

Assure

£149/moper asset

Monthly active testing with version-matched CVE intelligence and evidence-backed reporting.

  • Authorised active perimeter testing (ACTIVE_SAFE)
  • Deep TLS/cipher audit (protocol, cert chain, OCSP)
  • Subdomain enumeration & takeover detection
  • Cloud storage exposure scanning (S3, GCS, Azure Blob)
  • Exposed services & port detection
  • CVE matching on each scheduled scan when version evidence is observed
  • Email security audit (MX, DKIM, DMARC alignment)
  • Evidence-backed findings (CVSS, CWE, OWASP)
  • Signed PDF reports + public security badge
  • One change-led result after each scheduled scan
  • Monthly automated re-scan baseline
Most popular

Assure+

£299/moper asset

Offensive-grade reconnaissance. Evidence-led verification. Breach intelligence. Analyst review controls.

  • Everything in Assure, plus:
  • 8-technique attack surface mapping
  • Wayback Machine & JavaScript endpoint extraction
  • API discovery & fuzzing (Swagger, GraphQL, REST)
  • Exploit pattern matching (debug modes, known vuln paths)
  • Breach & dark web credential exposure monitoring
  • Evidence-led cross-verification with uncertain High/Critical candidates held for analyst review
  • AI-generated attack chain narratives (MITRE ATT&CK)
  • Compliance mapping (ISO 27001, SOC 2, GDPR)
  • Remediation code snippets & priority guidance
  • Slack/webhook instant alerts
  • Custom scan scheduling (daily/weekly/on-demand)

Enterprise

Customscoped agreement

Private code, authenticated application and external assurance tailored to your environment.

  • Everything in Assure+, plus:
  • Private source-code review with tailored rules and AI-assisted analysis
  • Authenticated portal and API assurance with dedicated test identities
  • Environment-specific assurance models, evidence and remediation priorities
  • Securely authorised scope, encrypted credentials and an operator-controlled kill switch
  • Asset volumes and cadence designed for your estate
  • Managed remediation and a contracted critical-response SLA
  • Named security contact
  • Board-ready quarterly posture reports
  • Multi-entity management and branded reporting
  • API and custom webhook integration
  • Quarterly strategy review with your CISO/CTO
  • Priority emerging threat response
  • Custom compliance frameworks

Frequently asked questions

How is this different from a traditional penetration test?+

A specialist penetration test is a scoped point-in-time assessment and can include manual, authenticated and internal testing. PerimAssure complements it with scheduled external monitoring, evidence-led findings and change history between assessments. Assure scans monthly and Assure+ scans daily.

How does PerimAssure reduce false positives?+

Every High and Critical candidate is checked against captured evidence and an adversarial refutation pass. Wildcard DNS and CDN-aware controls suppress common noise; uncertain candidates are held for analyst review rather than labelled as confirmed vulnerabilities.

Do I need to give you access to my servers?+

No. PerimAssure is entirely external — we test what an attacker would see from the outside. No SSH access, no source code, no internal network access required. This is black-box testing from the internet, exactly like a real threat actor would approach your infrastructure.

How does 0-day CVE monitoring work?+

When a versioned technology fingerprint is observed, PerimAssure compares it with current vulnerability intelligence during scheduled monitoring. Confirmed version matches are reported with the supporting evidence; unversioned signals are not converted into generic vulnerability claims.

Will your scans trigger my WAF or IDS?+

Passive scans observe publicly available information only. Active scans send legitimate HTTP requests that may appear in logs, but they're designed to be safe and non-destructive. We never attempt exploitation. If you'd like to allowlist our scanner IP range, we provide it on request.

Can PerimAssure help us prepare for Cyber Essentials?+

Yes, for readiness support. PerimAssure can identify internet-facing gaps and provide partial external evidence for firewalls, secure configuration and security update management. It cannot verify user access control or malware protection, certify your organisation, guarantee a pass or replace the official self-assessment, assessor, Certification Body or internal control review.

Can I cancel at any time?+

Monthly plans can be cancelled before the next renewal. Annual plans are prepaid 12-month commitments at a 10% discount; cancellation stops the next annual renewal but does not shorten or refund the current committed term except where required by law. Your scan history and reports remain accessible until the paid term ends.

Threat intelligence refreshed regularly · Evidence matched on scheduled scans

Your scanner should evolve faster than the threats

PerimAssure checks internet-facing controls against current threat and vulnerability intelligence. It reports matches only when the observed evidence supports them, while coverage limits remain visible rather than being presented as clean results.

Low-cost scanners

A list of ports and CVEs

  • Large unprioritised finding lists
  • Verification quality varies by product
  • No context, no prioritisation
  • No exploit chain analysis
  • New threats? Wait for next version
PerimAssure (from £149/mo)

Daily intelligence. Evidence-led prioritisation.

  • Assure monthly; Assure+ daily
  • Version evidence checked against current intelligence
  • Evidence-led cross-verification and analyst review controls
  • Attack chain narratives explain real risk
  • On-demand remediation available
Pentesting (£5,000–£15,000)

Deep but instantly stale

  • 4–6 weeks from scoping to report
  • Stale the day after delivery
  • No monitoring between annual tests
  • 0-day drops? Wait until next year
  • Quality depends on individual tester
19
Specialised external assessment modules
2-pass
Evidence and refutation workflow
1
Change-led result per scheduled scan
Portal
Protected canonical reports and evidence
On-demand remediation

We find it. We can fix it.

Don't have the bandwidth to remediate critical findings? Our security engineers review your specific issues and provide hands-on fixes — not generic advice. Pricing is per-issue, scoped after we review the finding. No retainer. No lock-in. Faster than hiring a consultant, cheaper than a pentest firm.

  • Scoped to your specific critical findings
  • Priced per-issue after review — no surprise invoices
  • Implemented by engineers, verified by re-scan
  • Available to all Assure and Assure+ customers

Get a remediation quote

We'll review your critical findings and send a fixed-price proposal within 24 hours.

Or email remediation@perimassure.com directly

See your external posture in two minutes

Run a free passive scan now. No login required. Most complete in one to two minutes; delayed scans are saved and recover automatically.