Continuous security monitoring

Know your perimeter
is secure. Every day.

Continuous external security testing with evidence-led verification. High and Critical candidates are cross-checked before they are presented as confirmed findings.

No login required. Passive scan only — no intrusive testing without ownership verification.

60s
First results
16
Scan modules
2-pass
Evidence review
Perimeter posture Live
B
portal.meridian-payments.co.uk
Risk score: 29/100 · Last scan: today
TLS / cipher hygiene
PASS
Exposed secrets (.git, .env)
PASS
Email security (DMARC)
PASS
Subresource integrity
MEDIUM
Security headers
LOW
16 modules · 42 controls verifiedCross-verified ✓

Built for security teams around the world

ISO 27001
Information Security Management
Certified
ISO 42001
AI Management System
Certified
Cyber Essentials
UK Government Backed
Certified
Aligned to:OWASP Top 10CVSS 3.1CWECRESTSOC 2GDPR

A scanner that never lies

Every finding is backed by captured evidence. Every AI verdict cites a specific HTTP response, DNS record, or TLS parameter. Unverified High and Critical candidates are held for analyst review.

Evidence-first

No CVEs, IPs, or versions introduced by the model. Every claim links to raw captured evidence you can verify yourself.

Evidence-led noise reduction

Wildcard DNS profiling, CDN detection, and adversarial cross-verification suppress common scanner noise and route uncertain High/Critical candidates to review.

Posture over time

Daily scans build a trend line. See what improved, what regressed, and what's new — with evidence for every change.

For CISOs, CTOs & Board-level

Replace the annual external-security snapshot with continuous security monitoring

Your board asks "are we secure?" once a quarter. With PerimAssure, the answer is always current — backed by evidence, not assumptions.

Traditional pentest

  • £5,000–£15,000 for a single point-in-time snapshot
  • 4–6 weeks from scoping call to final report
  • Stale the day after delivery — no ongoing monitoring
  • If a 0-day drops tomorrow, you won't know until next year
  • Report quality depends on individual tester skill

PerimAssure

  • From £149/mo — 90% cheaper than a single manual test
  • First report delivered in minutes, not weeks
  • Daily automated re-testing — posture always current
  • 0-day CVE matching within 24 hours of disclosure
  • Evidence-led cross-verification with uncertain High/Critical candidates held for review

Posture trending

Track your security grade daily. See what changed, what improved, and what regressed — with evidence. Board-ready reporting built in.

0-day response in hours

We fingerprint your exact tech stack and cross-reference NVD daily. When a new CVE drops for your software versions, you're alerted within hours.

Compliance-ready evidence

Every finding mapped to ISO 27001, SOC 2, and GDPR controls. Hand the PDF directly to auditors. No manual spreadsheet work.

For DevOps & SecOps teams

Deep external security reconnaissance. Evidence, not noise.

16 independent scan modules running in parallel. Every finding is evidence-backed, AI cross-verified, and mapped to CWE/OWASP.

TLS & Cipher AuditWatch
DNS HygieneWatch
Web App SecurityWatch
Subdomain EnumerationAssure
Cloud Storage ExposureAssure
Email SecurityAssure
Service DiscoveryAssure
JavaScript AnalysisAssure
Supply Chain RiskAssure
API Security & FuzzingAssure+
AI Red Team (LLM)Assure+
Attack Surface DiscoveryAssure+
Breach & Dark Web IntelAssure+
CDN & Cache SecurityAssure+
Access Control AuditAssure+
GraphQL SecurityAssure+

How we eliminate false positives

LAYER 1

Wildcard guard

DNS catch-all profiling before enumeration. If *.domain resolves identically, subdomain findings are suppressed.

LAYER 2

Platform awareness

CDN/serverless detection from header signatures. Origin-hunting skipped when behind Cloudflare, Fastly, or Vercel.

LAYER 3

Evidence-only rule

AI cannot introduce findings. Every verdict must cite a specific HTTP response, DNS record, or TLS parameter.

LAYER 4

Fail-closed verifier

If AI cross-verification is uncertain, findings are withheld — never promoted to confirmed.

How it works

Three steps from domain to actionable intelligence. No agents to install, no access to grant.

01

Enter your domain

Type your domain and hit scan. We begin passive reconnaissance immediately — no login, no configuration, no access required.

02

We scan externally

16 modules run in parallel: TLS, DNS, headers, subdomains, CVEs, breach intel, supply chain, API discovery, and more. Every finding is evidence-backed.

03

Get your report

A grade, risk score, and prioritised findings — with raw evidence, remediation steps, and compliance mapping. Upgrade for daily monitoring.

The old model is broken

You shouldn't have to choose between depth and frequency. Or between accuracy and affordability.

Manual PentestBasic ScannersPerimAssure
Cost per asset£5,000–£15,000£40/moFrom £149/mo
Time to first report4–6 weeksMinutesMinutes
Testing frequencyOnce a yearContinuousDaily
Depth of testingDeep (manual)ShallowDeep (AI-driven)
False positive rateLowVery highZero (cross-verified)
0-day CVE responseNext year's testBasic matchingWithin 24 hours
Attack surface mappingManual reconNone16 automated modules
Breach intelligenceNot includedNot includedDark web monitoring
Evidence transparencyVaries by testerMinimalFull raw evidence

Pentest-grade depth. Fraction of the cost.

Start with one asset. Scale to your entire estate. Every plan includes daily scanning, evidence-backed findings, and false-positive controls. Cancel any time.

Assure

£149/moper asset

Daily active testing with CVE intelligence and evidence-backed reporting. The core of continuous assurance.

  • Authorised active perimeter testing (ACTIVE_SAFE)
  • Deep TLS/cipher audit (protocol, cert chain, OCSP)
  • Subdomain enumeration & takeover detection
  • Cloud storage exposure scanning (S3, GCS, Azure Blob)
  • Exposed services & port detection
  • Daily CVE matching against your exact tech stack
  • Email security audit (MX, DKIM, DMARC alignment)
  • Evidence-backed findings (CVSS, CWE, OWASP)
  • Signed PDF reports + public security badge
  • Grade-change & CVE email alerts
  • Monthly automated re-scan baseline
Most popular

Assure+

£299/moper asset

Offensive-grade reconnaissance. Evidence-led verification. Breach intelligence. Analyst review controls.

  • Everything in Assure, plus:
  • 8-technique attack surface mapping
  • Wayback Machine & JavaScript endpoint extraction
  • API discovery & fuzzing (Swagger, GraphQL, REST)
  • Exploit pattern matching (debug modes, known vuln paths)
  • Breach & dark web credential exposure monitoring
  • Evidence-led cross-verification with uncertain High/Critical candidates held for analyst review
  • AI-generated attack chain narratives (MITRE ATT&CK)
  • Compliance mapping (ISO 27001, SOC 2, GDPR)
  • Remediation code snippets & priority guidance
  • Slack/webhook instant alerts
  • Custom scan scheduling (daily/weekly/on-demand)

Enterprise

Customunlimited assets

Full-service security operations. We find it, we fix it, we report it. Your external security team.

  • Everything in Assure+, plus:
  • Unlimited assets — entire estate covered
  • Managed remediation by our security engineers
  • 8-hour SLA on Critical findings
  • Dedicated security engineer assigned to your account
  • Board-ready quarterly posture reports
  • White-labeled PDF reports (your brand)
  • Multi-tenant management (subsidiaries, acquisitions)
  • API access & custom webhook integrations
  • Quarterly strategy review with your CISO/CTO
  • Priority emerging threat response
  • Custom compliance frameworks

Frequently asked questions

How is this different from a traditional penetration test?+

A traditional pentest is a one-time manual assessment that costs £5,000–£15,000 and takes weeks to deliver. It's deep but instantly stale. PerimAssure delivers the same depth of external testing — automated, daily, and AI-verified — for a fraction of the cost. We don't replace internal/authenticated testing, but for external perimeter security, we make annual pentests optional.

How does PerimAssure reduce false positives?+

Every High and Critical candidate is checked against captured evidence and an adversarial refutation pass. Wildcard DNS and CDN-aware controls suppress common noise; uncertain candidates are held for analyst review rather than labelled as confirmed vulnerabilities.

Do I need to give you access to my servers?+

No. PerimAssure is entirely external — we test what an attacker would see from the outside. No SSH access, no source code, no internal network access required. This is black-box testing from the internet, exactly like a real threat actor would approach your infrastructure.

How does 0-day CVE monitoring work?+

We fingerprint your tech stack from response headers, JavaScript libraries, and framework signatures. When a new CVE is published that matches your exact software versions, you're alerted within 24 hours. This is the key advantage of continuous monitoring — a traditional pentest can't warn you about vulnerabilities disclosed after the test date.

Will your scans trigger my WAF or IDS?+

Passive scans observe publicly available information only. Active scans send legitimate HTTP requests that may appear in logs, but they're designed to be safe and non-destructive. We never attempt exploitation. If you'd like to allowlist our scanner IP range, we provide it on request.

Can I cancel at any time?+

Monthly plans can be cancelled before the next renewal. Annual plans are prepaid 12-month commitments at a 10% discount; cancellation stops the next annual renewal but does not shorten or refund the current committed term except where required by law. Your scan history and reports remain accessible until the paid term ends.

Updated daily · New exploits checked within 24 hours

Your scanner should evolve faster than the threats

On 28 July 2026, researchers disclosed TokenLover and YaksaLover — AI-powered phishing kits that automate full BEC chains against Microsoft 365. Within 48 hours, our engine was checking every customer domain for the specific email misconfigurations these kits exploit. A cheap scanner wouldn't know. Your annual pentest wouldn't catch it until next year.

Cheap scanners (£50/mo)

A list of ports and CVEs

  • Run once, dump 500+ findings
  • 60%+ false positive rate
  • No context, no prioritisation
  • No exploit chain analysis
  • New threats? Wait for next version
PerimAssure (from £149/mo)

Daily intelligence. Evidence-led prioritisation.

  • Scans daily — posture always current
  • New exploits added within 24–48h
  • Evidence-led cross-verification and analyst review controls
  • Attack chain narratives explain real risk
  • On-demand remediation available
Pentesting (£5,000–£15,000)

Deep but instantly stale

  • 4–6 weeks from scoping to report
  • Stale the day after delivery
  • No monitoring between annual tests
  • 0-day drops? Wait until next year
  • Quality depends on individual tester
£370K+
Average cost of a single cyber incident for SMBs
48h
Time to add new exploit checks after public disclosure
43%
Of all cyber attacks target small businesses
£120K
Average loss per BEC incident (UK)
On-demand remediation

We find it. We can fix it.

Don't have the bandwidth to remediate critical findings? Our security engineers review your specific issues and provide hands-on fixes — not generic advice. Pricing is per-issue, scoped after we review the finding. No retainer. No lock-in. Faster than hiring a consultant, cheaper than a pentest firm.

  • Scoped to your specific critical findings
  • Priced per-issue after review — no surprise invoices
  • Implemented by engineers, verified by re-scan
  • Available to all Assure and Assure+ customers

Get a remediation quote

We'll review your critical findings and send a fixed-price proposal within 24 hours.

Or email remediation@perimassure.com directly

See your external posture in 60 seconds

Run a free passive scan now. No login required. Upgrade to continuous monitoring when you're ready.