Continuous external security testing with evidence-led verification. High and Critical candidates are cross-checked before they are presented as confirmed findings.
No login required. Passive scan only — no intrusive testing without ownership verification.
Built for security teams around the world
Every finding is backed by captured evidence. Every AI verdict cites a specific HTTP response, DNS record, or TLS parameter. Unverified High and Critical candidates are held for analyst review.
No CVEs, IPs, or versions introduced by the model. Every claim links to raw captured evidence you can verify yourself.
Wildcard DNS profiling, CDN detection, and adversarial cross-verification suppress common scanner noise and route uncertain High/Critical candidates to review.
Daily scans build a trend line. See what improved, what regressed, and what's new — with evidence for every change.
Your board asks "are we secure?" once a quarter. With PerimAssure, the answer is always current — backed by evidence, not assumptions.
Track your security grade daily. See what changed, what improved, and what regressed — with evidence. Board-ready reporting built in.
We fingerprint your exact tech stack and cross-reference NVD daily. When a new CVE drops for your software versions, you're alerted within hours.
Every finding mapped to ISO 27001, SOC 2, and GDPR controls. Hand the PDF directly to auditors. No manual spreadsheet work.
16 independent scan modules running in parallel. Every finding is evidence-backed, AI cross-verified, and mapped to CWE/OWASP.
DNS catch-all profiling before enumeration. If *.domain resolves identically, subdomain findings are suppressed.
CDN/serverless detection from header signatures. Origin-hunting skipped when behind Cloudflare, Fastly, or Vercel.
AI cannot introduce findings. Every verdict must cite a specific HTTP response, DNS record, or TLS parameter.
If AI cross-verification is uncertain, findings are withheld — never promoted to confirmed.
Three steps from domain to actionable intelligence. No agents to install, no access to grant.
Type your domain and hit scan. We begin passive reconnaissance immediately — no login, no configuration, no access required.
16 modules run in parallel: TLS, DNS, headers, subdomains, CVEs, breach intel, supply chain, API discovery, and more. Every finding is evidence-backed.
A grade, risk score, and prioritised findings — with raw evidence, remediation steps, and compliance mapping. Upgrade for daily monitoring.
You shouldn't have to choose between depth and frequency. Or between accuracy and affordability.
| Manual Pentest | Basic Scanners | PerimAssure | |
|---|---|---|---|
| Cost per asset | £5,000–£15,000 | £40/mo | From £149/mo |
| Time to first report | 4–6 weeks | Minutes | Minutes |
| Testing frequency | Once a year | Continuous | Daily |
| Depth of testing | Deep (manual) | Shallow | Deep (AI-driven) |
| False positive rate | Low | Very high | Zero (cross-verified) |
| 0-day CVE response | Next year's test | Basic matching | Within 24 hours |
| Attack surface mapping | Manual recon | None | 16 automated modules |
| Breach intelligence | Not included | Not included | Dark web monitoring |
| Evidence transparency | Varies by tester | Minimal | Full raw evidence |
Start with one asset. Scale to your entire estate. Every plan includes daily scanning, evidence-backed findings, and false-positive controls. Cancel any time.
Daily active testing with CVE intelligence and evidence-backed reporting. The core of continuous assurance.
Offensive-grade reconnaissance. Evidence-led verification. Breach intelligence. Analyst review controls.
Full-service security operations. We find it, we fix it, we report it. Your external security team.
A traditional pentest is a one-time manual assessment that costs £5,000–£15,000 and takes weeks to deliver. It's deep but instantly stale. PerimAssure delivers the same depth of external testing — automated, daily, and AI-verified — for a fraction of the cost. We don't replace internal/authenticated testing, but for external perimeter security, we make annual pentests optional.
Every High and Critical candidate is checked against captured evidence and an adversarial refutation pass. Wildcard DNS and CDN-aware controls suppress common noise; uncertain candidates are held for analyst review rather than labelled as confirmed vulnerabilities.
No. PerimAssure is entirely external — we test what an attacker would see from the outside. No SSH access, no source code, no internal network access required. This is black-box testing from the internet, exactly like a real threat actor would approach your infrastructure.
We fingerprint your tech stack from response headers, JavaScript libraries, and framework signatures. When a new CVE is published that matches your exact software versions, you're alerted within 24 hours. This is the key advantage of continuous monitoring — a traditional pentest can't warn you about vulnerabilities disclosed after the test date.
Passive scans observe publicly available information only. Active scans send legitimate HTTP requests that may appear in logs, but they're designed to be safe and non-destructive. We never attempt exploitation. If you'd like to allowlist our scanner IP range, we provide it on request.
Monthly plans can be cancelled before the next renewal. Annual plans are prepaid 12-month commitments at a 10% discount; cancellation stops the next annual renewal but does not shorten or refund the current committed term except where required by law. Your scan history and reports remain accessible until the paid term ends.
On 28 July 2026, researchers disclosed TokenLover and YaksaLover — AI-powered phishing kits that automate full BEC chains against Microsoft 365. Within 48 hours, our engine was checking every customer domain for the specific email misconfigurations these kits exploit. A cheap scanner wouldn't know. Your annual pentest wouldn't catch it until next year.
Don't have the bandwidth to remediate critical findings? Our security engineers review your specific issues and provide hands-on fixes — not generic advice. Pricing is per-issue, scoped after we review the finding. No retainer. No lock-in. Faster than hiring a consultant, cheaper than a pentest firm.
We'll review your critical findings and send a fixed-price proposal within 24 hours.
Or email remediation@perimassure.com directly
Run a free passive scan now. No login required. Upgrade to continuous monitoring when you're ready.