What is Perimeter

Perimeter is an external attack surface and vulnerability intelligence platform. It answers four questions about everything your organization exposes to the public internet:

Passive by default

Perimeter is passive-first and OSINT-led. It builds your attack surface picture from public sources — DNS, Certificate Transparency logs, passive DNS, internet registries, and internet-wide scan data — rather than by probing your systems.

It does not deliver exploits, and it never performs authenticated or internal scanning. On an ordinary scan the only active checks are narrowly bounded: ordinary HTTPS requests and TLS handshakes, a favicon fetch, and a single CORS preflight using a non-routable origin.

Port checking and template scanning exist, but only on an Intrusive scan, and only for an organisation that has signed a scan authorization. They cannot run otherwise. See Security and acceptable use.

Explainable, not magical

Every finding, score and relationship traces back to a named collection step, a source, a timestamp and a stored evidence record. Scores always return the full factor breakdown — you can see exactly which findings cost you which points. If Perimeter cannot determine something, it says so explicitly rather than quietly leaving it out.

That extends to coverage. A scan reports what it actually assessed separately from whether it finished, so a scan that could only reach part of your estate never reads as a clean bill of health.

One record, full lifecycle

A finding keeps the same identifier for its entire life. Status changes, evidence snapshots, assignments and remediation history accumulate against that one record. Rescanning a fixed issue closes it rather than deleting it, so your history stays intact.

Who it's for

What it is not

Perimeter is not a replacement for a SIEM, SOAR, CMDB or ticketing system. It measures and prioritises external exposure and tracks remediation state; it deliberately stops short of becoming a general-purpose workflow tool.

Try it without an account

The public scan accepts a single domain and reports a verdict for each of three families — email, web and TLS — along with the assets it observed and a preview of the top issues found.

It deliberately gives no score and no letter grade. A free look at what is publicly visible is not a posture assessment, and a single number would invite you to read it as one — a domain can pass most checks and still fail the handful that let anyone send mail as you. Each family therefore reports its own worst finding, and nothing dilutes it.

Results are ephemeral — nothing is stored — and it is rate-limited. It is a preview of the collection engine, not a substitute for a workspace.

Next steps