Skip to main content

New: Continuous discovery is now on by default for every plan

Prism Prism — home

External attack surface management

Every asset you own, scored by how exploitable it actually is

Prism continuously discovers your external surface, attributes every host to an owner, and ranks exposures by real-world exploitability — packaged into a shareable report in minutes, not quarters.

No agents to deploy · Read-only by default

prism — scan
$ prism scan --org northwind --depth fullresolving seed domains .............. 41 foundenumerating subdomains ............. 1,284 hostsprobing certificate transparency ... 3,907 recordsfingerprinting services ............ 6,412 ports openattributing ownership .............. 6 clouds · 22 teamscorrelating CVEs ................... 214 matchedscoring exploitability ............. done in 3m 12s SEVERITY  ASSET                          FINDINGCRITICAL  api-staging.northwind.io:8080  unauth admin panelCRITICAL  vpn-legacy.northwind.io:443    CVE-2023-46805 · exploitedHIGH      mail-gw.northwind.io:443       CVE-2024-21762HIGH      s3-backups.northwind.io        public bucket listingMEDIUM    cdn-edge.northwind.io:80       dangling CNAMEMEDIUM    git.northwind.io:22            weak host keyLOW       docs.northwind.io:443          deprecated TLS suite unattributed hosts ................. 97 → routed to #sec-triage✓ 4,182 assets mapped · 37 exposures · report ready

Getting started

Map your surface in three commands

Install once, point Prism at a domain, and it does the rest — discovery, ownership attribution and exploitability scoring, all from a read-only vantage point outside your network.

Nothing to install on your side

Prism works entirely from outside your perimeter — the same vantage point an attacker has. Setup is a shell command and a domain.

  • No agent to deploy or maintain
  • No credentials handed over
  • No change window, no firewall rule

Works on macOS, Linux and WSL

Install the CLI

curl -fsSL https://prism.sh | sh

Point it at your org

prism init --org acme --seed acme.com

Run your first scan

prism scan --depth full

What Prism does

Continuous discovery

Seed a domain or an IP range and Prism keeps enumerating — subdomains, certificates, cloud tenancy, forgotten staging boxes. The inventory is never a snapshot.

Re-scanned every 4 hours

Ownership attribution

Every host resolves to a registrant, a hosting provider and an internal team. Findings route themselves, so nobody spends a morning working out whose box it is.

22 teams mapped automatically

Exploitability scoring

CVSS tells you what could go wrong in theory. Prism ranks by what is reachable, unauthenticated and actually exercisable from the open internet.

Reachability-weighted, not CVSS-only

Why teams standardise on Prism

Trusted at scale

A surface you can standardise on

Assets under continuous watch across 610 orgs
4.9M
Ports fingerprinted each month IPv4 + IPv6
1.2B
Platform uptime trailing 12 months
99.98%

Built for breadth

Stay fast when the estate isn't small

Discovery is incremental, so a 40-host startup and a 400,000-host conglomerate get the same first result in minutes. Nothing queues behind a nightly full sweep, and adding a subsidiary doesn't reset your baseline.

Scans are rate-shaped to stay well inside acceptable-use policy on every provider we touch — you will not get a call from your host about us.

Less glue

Focus on response, not tooling

Prism replaces the spreadsheet, the scanner export, the DNS side-quest and the Slack thread where someone asks whose box this is. One view, continuously updated, with the evidence attached to the finding.

Everything the UI does is available from the CLI and the API, so the workflow survives contact with your existing automation.

Assurance

Evidence you can hand to an auditor

  • SOC 2 Type II and ISO 27001 audited annually
  • Read-only by default — no write scopes requested
  • Regional data residency in EU, US and AU
  • Findings exportable to Jira, ServiceNow and CSV
  • FedRAMP Moderate authorisation in progress

The Prism console

Everything you need in one console

Five steps from first packet to closed ticket — all against one continuously updated picture of what you actually expose.

Step 01

Discovery that never goes stale

Seed one domain. Prism walks certificate transparency, passive DNS, cloud tenancy and registrar records until the picture stops changing — then keeps walking it every four hours.

  • Subdomain and dangling-CNAME enumeration
  • Shadow IT and forgotten staging boxes
  • IPv4 and IPv6 sweeps

Step 02

Ranked by what's actually reachable

A critical CVSS behind three firewalls matters less than an unauthenticated admin panel on the open internet. Prism scores reachability first and severity second.

  • Reachability-weighted scoring
  • Live CVE correlation
  • Exploit-availability signal

Step 03

Every host resolves to a human

Registrant, hosting provider, cloud account and owning team — resolved automatically, so a finding arrives with a name attached instead of starting a hunt.

  • Auto-attribution to internal teams
  • Unattributed queue surfaced, never buried
  • Routes straight to Jira or ServiceNow

Step 04

Triage in the open, together

Comment, assign and close without leaving the exposure. Every change syncs live, so the response is designed once rather than reconstructed from a Slack thread later.

  • Real-time collaboration
  • Full audit trail per finding
  • Evidence attached inline

Step 05

A report you can send, not rebuild

One link gives a stakeholder the whole picture — inventory, exposures, remediation plan and SLA status — without anyone exporting a slide.

  • Shareable live link
  • Point-in-time PDF snapshot
  • Scoped to an audience

Coverage

Cloud, on-prem, edge? No problem.

Prism doesn't care where a host lives. If it answers from the public internet, it's in scope — and if it stops answering, Prism notices that too.

Every provider, one inventory

AWS, Azure, GCP, Cloudflare, Fastly, bare metal in a cage somewhere — all normalised into a single asset list with consistent ownership and scoring.

18 providers fingerprinted

Deploy nothing

There is no agent, no collector VM and no credential to rotate. Prism sees what an attacker sees, from where an attacker stands.

Map your surface

Field note

Leave no asset unmapped

A client of ours did everything right. They scoped the engagement, inventoried the CMDB, ran every scanner and signed off the report. Every box ticked.

Then came the audit. A host nobody had listed was still answering on 8080 — a staging box stood up for a two-week test three years earlier and never torn down.

That's why continuous discovery is the default in Prism, not a paid tier. One more stone turned over, before someone else turns it.

0 2 4 6 8 10 1 3 5 7 9 Exposure score (reachability × exploitability) Business impact Unmapped 0 8 33
Highest-density bins of unmapped assets
Exposure scoreBusiness impactUnmapped assets
8.0–8.37.0–7.333
8.3–8.57.3–7.733
8.5–8.87.7–8.028
8.8–9.07.0–7.327
8.5–8.87.3–7.727
8.3–8.57.7–8.027
8.3–8.57.0–7.326
8.0–8.37.3–7.726
7.8–8.07.0–7.325
8.8–9.07.3–7.725
Illustrative — 3,146 assets across 40×24 bins, square-root shaded

FAQ

Questions, answered

Still stuck? Talk to an engineer — not a sales rep.

Anything that answers from the public internet and traces back to you. Prism starts from a seed — a domain, an IP range or a cloud account — then expands outward through certificate transparency logs, passive DNS, registrar records and cloud tenancy metadata until the picture stops growing. It never touches your internal network, because an attacker can't either.
No. Prism is read-only and entirely external — there is no agent to deploy, no collector VM to maintain and no credential to rotate. Optional cloud connectors improve ownership attribution if you want them, and those request read-only scopes you can revoke at any time.
CVSS describes how bad a vulnerability would be in the abstract. Prism scores what is actually reachable from the open internet: whether the service responds, whether it requires authentication, whether a working exploit exists in the wild, and whether the host sits in a production path. A 9.8 behind three firewalls ranks below an unauthenticated admin panel on a forgotten staging box — because that is the order an attacker would work in.
Scans are rate-shaped to stay well inside the acceptable-use policy of every provider we touch, and Prism identifies itself honestly in its user agent and reverse DNS. We publish our source ranges so you can allow-list them. In eight years we have not had a customer receive a complaint about our traffic.
Minutes. Discovery is incremental, so assets and exposures stream into the console as they are confirmed rather than landing in one batch at the end. A mid-sized estate typically reaches a stable inventory inside an hour; the first criticals usually surface well before that.
In the region you pick — EU, US or AU — and nowhere else. Findings are encrypted at rest and in transit, access is scoped per workspace with SSO and SCIM, and every read of your data is logged where you can audit it. We do not sell, share or aggregate customer surface data into any external dataset.

Start mapping

The exposure nobody else found.
The fix nobody else shipped.

Map your external attack surface in minutes. Free for the first 500 assets, no card, no call.