Continuous external security testing with evidence-led verification. High and Critical candidates are cross-checked before they are presented as confirmed findings.
No login required. Passive scan only — no intrusive testing without ownership verification.
Evidence and assurance controls built into every paid scan
Every finding is backed by captured evidence. Every AI verdict cites a specific HTTP response, DNS record, or TLS parameter. Unverified High and Critical candidates are held for analyst review.
No CVEs, IPs, or versions introduced by the model. Every claim links to raw captured evidence you can verify yourself.
Wildcard DNS profiling, CDN detection, and adversarial cross-verification suppress common scanner noise and route uncertain High/Critical candidates to review.
Scheduled scans build measured history. See what improved, what regressed and what is new — with evidence for every change.
Keep internet-facing posture current without pretending automated monitoring replaces scoped manual, internal or authenticated testing.
Track a higher-is-better Security Posture Score, the A–F grade and the exact findings introduced or resolved at each scheduled scan.
Observed version fingerprints are checked against current vulnerability intelligence. Unversioned technologies are not converted into generic CVE claims.
Classified endpoints, canonical technical records and control mappings stay within the authenticated portal and protected report stream.
19 specialised modules cover externally observable configuration, exposure and attack-surface signals. Findings retain captured evidence and relevant CWE/OWASP mappings.
DNS catch-all profiling before enumeration. If *.domain resolves identically, subdomain findings are suppressed.
CDN/serverless detection from header signatures. Origin-hunting skipped when behind Cloudflare, Fastly, or Vercel.
AI cannot introduce findings. Every verdict must cite a specific HTTP response, DNS record, or TLS parameter.
If AI cross-verification is uncertain, findings are withheld — never promoted to confirmed.
Three steps from domain to actionable intelligence. No agents to install, no access to grant.
Type your domain and hit scan. We begin passive reconnaissance immediately — no login, no configuration, no access required.
Specialised modules assess TLS, DNS, headers, subdomains, version-matched CVEs, breach signals, supply chain and API exposure. Findings retain captured evidence.
A grade, higher-is-better Security Posture Score, measured changes and prioritised findings — with protected evidence and remediation guidance.
You shouldn't have to choose between depth and frequency. Or between accuracy and affordability.
| Manual Pentest | Basic Scanners | PerimAssure | |
|---|---|---|---|
| Cost per asset | £5,000–£15,000 | £40/mo | From £149/mo |
| Time to first report | 4–6 weeks | Minutes | Minutes |
| Testing frequency | Defined by engagement | Varies | Assure monthly · Assure+ daily |
| Depth of testing | Deep, manual and scoped | Usually broad and automated | Evidence-led external assessment |
| Finding verification | Specialist judgement | Varies | Captured evidence + review gates |
| CVE intelligence | Point-in-time | Often generic | Version-matched on scheduled scans |
| Attack surface mapping | Manual recon | Varies | 19 specialised modules |
| Breach intelligence | Not included | Not included | Dark web monitoring |
| Evidence transparency | Varies by tester | Minimal | Full raw evidence |
Start with one asset. Assure scans monthly; Assure+ scans daily. Both retain evidence, measured history and review controls. Cancel monthly renewal any time.
Monthly active testing with version-matched CVE intelligence and evidence-backed reporting.
Offensive-grade reconnaissance. Evidence-led verification. Breach intelligence. Analyst review controls.
Managed external assurance and remediation, scoped to your estate and operating model.
A specialist penetration test is a scoped point-in-time assessment and can include manual, authenticated and internal testing. PerimAssure complements it with scheduled external monitoring, evidence-led findings and change history between assessments. Assure scans monthly and Assure+ scans daily.
Every High and Critical candidate is checked against captured evidence and an adversarial refutation pass. Wildcard DNS and CDN-aware controls suppress common noise; uncertain candidates are held for analyst review rather than labelled as confirmed vulnerabilities.
No. PerimAssure is entirely external — we test what an attacker would see from the outside. No SSH access, no source code, no internal network access required. This is black-box testing from the internet, exactly like a real threat actor would approach your infrastructure.
When a versioned technology fingerprint is observed, PerimAssure compares it with current vulnerability intelligence during scheduled monitoring. Confirmed version matches are reported with the supporting evidence; unversioned signals are not converted into generic vulnerability claims.
Passive scans observe publicly available information only. Active scans send legitimate HTTP requests that may appear in logs, but they're designed to be safe and non-destructive. We never attempt exploitation. If you'd like to allowlist our scanner IP range, we provide it on request.
Monthly plans can be cancelled before the next renewal. Annual plans are prepaid 12-month commitments at a 10% discount; cancellation stops the next annual renewal but does not shorten or refund the current committed term except where required by law. Your scan history and reports remain accessible until the paid term ends.
PerimAssure checks internet-facing controls against current threat and vulnerability intelligence. It reports matches only when the observed evidence supports them, while coverage limits remain visible rather than being presented as clean results.
Don't have the bandwidth to remediate critical findings? Our security engineers review your specific issues and provide hands-on fixes — not generic advice. Pricing is per-issue, scoped after we review the finding. No retainer. No lock-in. Faster than hiring a consultant, cheaper than a pentest firm.
We'll review your critical findings and send a fixed-price proposal within 24 hours.
Or email remediation@perimassure.com directly
Run a free passive scan now. No login required. Most complete in one to two minutes; delayed scans are saved and recover automatically.