Uptime monitors ask “is it up?” — Exposure asks “what is it showing?” Certificates and chains, DNS and mail records, blocklist reputation, and open ports — watched from outside, three times a day, with nothing to install. You get paged on change, not noise.
3 assets on the free plan · No agent, no credit card · Live in about five minutes
# add a domain — we scan its whole public surface: shop.example.com — reputation ok · TLS ok · DNS ok · mail auth weak # and page you the moment something changes: tcp/3389 (Remote Desktop) newly open — critical Certificate expires in 12 days IP listed on Spamhaus ZEN
Every asset gets the same checks three times a day: TLS certificate and chain, DNS and mail records, SPF/DMARC enforcement, and Spamhaus blocklist reputation. Public data only — nothing touches your servers.
Prove you control a host — a DNS TXT record, a well-known file, or one curl from the box —
and open-port monitoring turns on: ~35 common ports, and a hard flag on anything that should never
face the internet (RDP, SMB, bare databases).
The first scan is the baseline; after that you hear when something appears or clears — a port opening, a chain breaking, an IP landing on a blocklist. One open port never becomes three pages a day.
-all)
rather than soft-failing.These are the same signals the big attack-surface platforms sell — the difference is you can be watching your first domains five minutes from now, free, and the same system carries all the way up: escalation ladders on every plan, on-call rotations on Team, and on Enterprise your BYO-AI agent receives every exposure alert as a structured envelope and investigates before you're awake. MSPs and platform teams run every client domain in one workspace with per-asset alert routing.
Not without proof. Certificates, DNS, mail auth and reputation are public records — those run on any domain you add. Port scanning sends traffic to the host, so it only runs on assets whose ownership you've verified, and it probes a fixed, bounded list — not an exhaustive sweep.
Public domains, hostnames, and public IP addresses. Private ranges and internal-only names can't be seen from the internet — cover those with the agent and normal uptime monitors in the same account.
The free plan includes 3 exposure assets with full alerting, alongside your uptime monitors. Paid plans raise the asset count and start at $9/mo. See pricing →
It's the other half. Uptime tells you when the site stops answering; Exposure tells you when what it's showing the world changes — an expiring chain, a hijacked record, a port that shouldn't exist. One account, one place that pages you, for both.
Nothing to install. No credit card.