Continuous Threat Exposure Management
We index the internet. One platform for external security.
The domains you register, the certificates you issue and the passwords employees save all leave traces, and so do your vendors and the lookalikes built to copy you. Deepinfo indexes those traces continuously and shows your team which ones are exposures, before someone else reads them.
Among the 10,000+ organizations working from Deepinfo data
Map everything you own on the internet. Especially what you forgot.
Start from one domain. The platform discovers the subdomains, IP addresses, certificates, open ports and technologies behind it, then keeps scanning all of them. Findings arrive scored, with evidence your team can hand to an owner.
acme.example
-
www.acme.example198.51.100.10
- 443/tcp · TLS 1.3
- nginx 1.25
-
mail.acme.example198.51.100.12
- 25/tcp · SMTP
- MX · SPF record
-
api.acme.example198.51.100.40
- Certificate expires in 6 daysmedium
-
vpn-legacy.acme.example203.0.113.24
Not in inventory
- 3389/tcp · RDP opencritical
-
staging.acme.example203.0.113.7
- Apache httpd 2.4.49high
- CVE-2021-41773 · KEVcritical
-
shop.acme.example198.51.100.77
- PHP 7.4 · end of lifehigh
-
blog.acme.example192.0.2.15
- Login page · HTTP 200
Layer by layer
- WHOIS registrar · renews in 41 days
- IP WHOIS AS64500
- DNS A 198.51.100.10 · MX mail.acme.example
- SSL Medium*.acme.example · expires in 6 days
- Ports 443/tcp · TLS 1.3
- Web data nginx 1.25 · login page
- HTTP 200
In the platform
- All assets 1,562
- Domains 3 (selected)
- Subdomains 1,312
- IP addresses 247
Domains
-
grade B acme.
example (opened on its record)- grade A www.
acme. example - grade B shop.
acme. example - grade C vpn.
acme. example - grade A mail.
acme. example - 1,280 more
- grade A www.
-
grade A acme-eu.
example -
grade C acme-labs.
example
grade B acme.example
Last check 2 hours ago
- Overview (selected)
- Issues
- Subdomains
- Technologies
- Open ports
- Vulnerabilities
- Asset info
Info
IP addresses
- 203.0.113.10
- 203.0.113.11
- 203.0.113.12
- +5 more
Insights
- Issues
- 38
- Subdomains
- 1,284
- Technologies
- 23
- Open ports
- 46
- Vulnerabilities
- 7
Find the domains built to look like you.
A convincing phishing page needs a convincing address. The platform matches newly seen domains against your brand names, down to letters from other alphabets that the eye cannot tell apart. When one resolves, your team sees its DNS, certificate and HTTP evidence and can request a takedown.
Candidates are generated in your browser from the name you type. Nothing is sent, and a candidate is not a claim that the domain exists.
Your vendors’ exposures are yours too.
A questionnaire tells you what a supplier believes about itself. The platform scans each third party with the engine and layers it runs on your surface, and scores them all on one scale. When a vendor slips, you see it in the next scan, not the next annual review.
acme.example and its third parties
- Dpayroll-partner.example Score fell B → D · RDP exposed
- Acloud-hosting.example
- Acdn-provider.example
- Blogistics-co.example
- Claw-firm.example
- Ccall-center.example
- Bmarketing-agency.example
- Bsubsidiary-eu.example
- Acrm-saas.example
Under every module is an index we built.
Many platforms rent their view of the internet. We collect ours, resolve it and keep it with its history. That data powers each module, and your analysts and developers can query it directly.
-
01Collect
Collected and monitored
- Domain registrations and WHOIS
- DNS records
- SSL certificates
- Port scansTCP · UDP
- Web data and HTTP
- Breach data, infostealer logs, dark web sources
-
02Process
Resolved, enriched, matched, scored
- Resolve every record and keep its history
- Enrich every CVECVSS · EPSS · CISA KEV
- Match findings to your domains, people and brands
- Score and prioritize
-
03Present
What your team works from
- The modules EASMCTIBRPTPRMDSI
- Issues that move through their states
- Reports and notifications
- The REST API
Registered domains across every TLD, with registration, WHOIS history and daily deltas.
Domain Search · Feeds · WHOIS
Subdomains discovered and resolved to the IP addresses they point to.
Every observed DNS record, kept with its history, so infrastructure can be traced back in time.
DNS Lookup · DNS History · Reverse IP · Reverse MX · Reverse NS
Certificates collected and indexed. The names a certificate covers often reveal hosts nobody announced.
Query it
One REST API over the whole index: lookups, reverse lookups, history, discovery and vulnerability search.
Request
curl "https://api.deepinfo.com/v1/lookup/dns?domain=deepinfo.com&type=A,MX" \
-H "apikey: $DEEPINFO_API_KEY"import os, requests
r = requests.get(
"https://api.deepinfo.com/v1/lookup/dns",
params={"domain": "deepinfo.com", "type": "A,MX"},
headers={"apikey": os.environ["DEEPINFO_API_KEY"]},
)
print(r.json())const r = await fetch(
'https://api.deepinfo.com/v1/lookup/dns?domain=deepinfo.com&type=A,MX',
{ headers: { apikey: process.env.DEEPINFO_API_KEY } }
)
console.log(await r.json())
Response
{
"fqdn": "deepinfo.com",
"requested_types": ["A", "MX"],
"responses": [
{
"type": "A",
"conn_status": "success",
"rcode": "NOERROR",
"values": ["104.26.10.21", "104.26.11.21", "…"],
"raw": "deepinfo.com. 300 IN A 104.26.11.21\n…",
"server": "8.8.8.8"
},
{
"type": "MX",
"conn_status": "success",
"rcode": "NOERROR",
"values": ["1 aspmx.l.google.com", "5 alt1.aspmx.l.google.com", "…"],
"…": "…"
}
],
"servers": ["8.8.8.8"],
"check_date": "2026-09-22T12:25:59Z"
}
Some of it is already out there.
Breach dumps, infostealer logs, dark web forums and markets. The platform reads them for your domains, your employees and your customers, and ties each finding to a device, an account or a person your team can act on.
HWID ---1
UserName j.
MachineName ACME-LT-2
OS Windows 11 Pro x64
Locale en-GB
[Passwords] 41 total3
URL https://sso.acme.example/login
USER j.@acme.example
PASS
URL https://vpn-legacy.acme.example
USER j.
PASS
[Cookies] 1,208 total · 36 sensitive4
[Autofill] 312 entries
[Tokens] 4
SamePassword 63%5
- 1
Hardware ID
Ties every credential to one physical device, so a single infection is counted once.
- 2
User and system
Machine name, OS and locale, enough to find the device in your own fleet.
- 3
Saved passwords
Every login the browser remembered, including the ones for your own domains.
- 4
Session cookies
Sensitive cookies can skip the password and the MFA prompt entirely.
- 5
Same-password rate
How often one password is reused across the sites in the log.
Some of what it watches
Employee email breaches
Which corporate addresses appear in which breaches, and what leaked with them.
Compromised employee devices
Infostealer infections on machines that hold your credentials and session cookies.
Compromised client credentials
Your customers’ logins to your services, found in stealer logs, with the service each one opens.
Dark web mentions
Your brands, domains and people named on forums, markets and leak sites.
Threat actor intelligence
Who targets your region and industry, with the CVEs and tools they use.
Every finding gets a score, an owner and a state.
Vulnerabilities are ranked with CVSS, EPSS and CISA KEV together, so the top of the list is what attackers are most likely to use. Each issue then moves from state to state until a rescan confirms it is gone. If the signal comes back, the issue reopens by itself.
The path
newly detectedunresolvedmarked as resolvedverified resolvedre-scan confirms
If the signal returns
verified resolved → reappeared → unresolved
Closed by decision, kept on record
risk acceptedignoredmarked as false positivenot applicable
Around each issue
Notifications
New, reappeared and changed findings, delivered instantly, hourly, daily, weekly or monthly.
Reports
From the executive summary to issue detail, as PDF, on demand or on a schedule.
Compliance mapping
Each issue classified against OWASP, PCI DSS, HIPAA, CWE, CAPEC and WASC.
In use
10,000+
organizations work from Deepinfo data, on the platform and through the API. Banks, airlines, telecom operators, defense manufacturers, public institutions and security vendors among them.
Customer storiesStart with your own record.
Rather see the platform with our team? Request a demo. Building on the data? Talk to the data team.