Someone is already looking at what your business exposes online.
Professional mapping of subdomains, technologies, and risky configurations — the same work an in-house security team would do, delivered in under 48 hours.
A clear map of your real exposure
No agents to install, no access to your internal systems. Just what's already publicly visible — and for that same reason, the first thing an attacker would see.
Exposed subdomains
Complete enumeration of active subdomains, including forgotten staging or test environments.
Technologies and versions
Identification of software, frameworks, and outdated versions that represent known risk.
Prioritized report
PDF with findings ranked by severity and concrete recommendations for your technical team.
Clear pricing, no fine print
Start with a free snapshot. Order the full report when you want the complete picture.
Authorization notice
By requesting a snapshot or purchasing a plan, you confirm that you own the domain or are an authorized representative of its owner, and you authorize its assessment. The Snapshot, the Perimeter Report and Monitoring use only passive reconnaissance of information that is already public (DNS records, certificate logs, publicly visible web pages and headers); nothing on your systems is modified. Email Hardening is the one exception: it changes your DNS email records, only after your written authorization and the access you grant. See our Terms.
Start here · Free
Exposure Snapshot
One page for one domain: whether your SPF, DKIM and DMARC actually stop spoofing, your TLS status, how many findings we see by severity, and one of them explained. Requested from a business email address.
Additional domains $150 each.
Order report3-month minimum, or $2,490/year (2 months free).
Start monitoringRequires your written authorization and DNS access.
Order hardeningReal findings, not just theory
Active security researcher in public bug bounty programs.
Deutsche Telekom · OAuth
Incorrect redirect URI configuration in their infrastructure, reported and validated.
Deutsche Telekom · Stored XSS
Persistent scripting vulnerability identified and responsibly disclosed.
guthacker13
Active profile with a track record of verified reports in public bug bounty programs.
Findings are mentioned in line with the disclosure rules of the programs involved. Company names belong to their owners; Shadow Perimeter is independent and is not affiliated with or endorsed by them.
Before you start
Do you need access to my systems?
Not for the Snapshot, the Perimeter Report or Monitoring: they use only information that's already public and never touch your internal infrastructure. Email Hardening needs DNS access, which you grant in writing.
Will you modify anything on my site or my data?
Not in the Snapshot, the Perimeter Report or Monitoring: they are purely passive and nothing on your systems is altered. Email Hardening does change your DNS email records, only with your written authorization, and we keep a record of the original values so changes can be reversed.
What format do I receive the report in?
A clear PDF, with findings prioritized by severity and actionable recommendations for your team.
Can I cancel the monthly plan?
Yes. Monitoring has a 3-month minimum; after that you can cancel anytime — no penalty.
Get your free exposure snapshot
Send your primary domain from your business email. Your one-page snapshot arrives within 2 business days.
or email directly at ceo@shadowperimeter.com