What is Perimeter
Perimeter is an external attack surface and vulnerability intelligence platform. It answers four questions about everything your organization exposes to the public internet:
- What do we actually have out there? Domains, subdomains, IP addresses, services and web applications — including the ones nobody remembered to tell you about.
- How is it configured? TLS, security headers, cookies, CORS, and email authentication posture.
- What is vulnerable? Public CVEs correlated against detected technology and versions, annotated with exploitation likelihood.
- Is it getting better or worse? Posture scoring over time, with every score tracing back to the evidence that produced it.
Passive by default
Perimeter is passive-first and OSINT-led. It builds your attack surface picture from public sources — DNS, Certificate Transparency logs, passive DNS, internet registries, and internet-wide scan data — rather than by probing your systems.
It does not deliver exploits, and it never performs authenticated or internal scanning. On an ordinary scan the only active checks are narrowly bounded: ordinary HTTPS requests and TLS handshakes, a favicon fetch, and a single CORS preflight using a non-routable origin.
Port checking and template scanning exist, but only on an Intrusive scan, and only for an organisation that has signed a scan authorization. They cannot run otherwise. See Security and acceptable use.
Explainable, not magical
Every finding, score and relationship traces back to a named collection step, a source, a timestamp and a stored evidence record. Scores always return the full factor breakdown — you can see exactly which findings cost you which points. If Perimeter cannot determine something, it says so explicitly rather than quietly leaving it out.
That extends to coverage. A scan reports what it actually assessed separately from whether it finished, so a scan that could only reach part of your estate never reads as a clean bill of health.
One record, full lifecycle
A finding keeps the same identifier for its entire life. Status changes, evidence snapshots, assignments and remediation history accumulate against that one record. Rescanning a fixed issue closes it rather than deleting it, so your history stays intact.
Who it's for
- Security teams who need an accurate, continuously updated inventory of external exposure and a way to drive remediation against it.
- Managers who need posture trends and SLA compliance without reading raw scan output.
- Remediators who should see only what they have been assigned, and nothing else.
- Enterprises and MSSPs managing a hierarchy of organizations and subsidiaries under one account.
What it is not
Perimeter is not a replacement for a SIEM, SOAR, CMDB or ticketing system. It measures and prioritises external exposure and tracks remediation state; it deliberately stops short of becoming a general-purpose workflow tool.
Try it without an account
The public scan accepts a single domain and reports a verdict for each of three families — email, web and TLS — along with the assets it observed and a preview of the top issues found.
It deliberately gives no score and no letter grade. A free look at what is publicly visible is not a posture assessment, and a single number would invite you to read it as one — a domain can pass most checks and still fail the handful that let anyone send mail as you. Each family therefore reports its own worst finding, and nothing dilutes it.
Results are ephemeral — nothing is stored — and it is rate-limited. It is a preview of the collection engine, not a substitute for a workspace.