PYLONMON
Attack-surface exposure monitoring

Know what the internet can see.
Hear the moment it changes.

Uptime monitors ask “is it up?” — Exposure asks “what is it showing?” Certificates and chains, DNS and mail records, blocklist reputation, and open ports — watched from outside, three times a day, with nothing to install. You get paged on change, not noise.

3 assets on the free plan · No agent, no credit card · Live in about five minutes

# add a domain — we scan its whole public surface:
shop.example.com — reputation ok · TLS ok · DNS ok · mail auth weak

# and page you the moment something changes:
tcp/3389 (Remote Desktop) newly open — critical
Certificate expires in 12 days
IP listed on Spamhaus ZEN

How exposure monitoring works

1 · WATCH

Public surface, from outside

Every asset gets the same checks three times a day: TLS certificate and chain, DNS and mail records, SPF/DMARC enforcement, and Spamhaus blocklist reputation. Public data only — nothing touches your servers.

2 · VERIFY

Prove it, unlock ports

Prove you control a host — a DNS TXT record, a well-known file, or one curl from the box — and open-port monitoring turns on: ~35 common ports, and a hard flag on anything that should never face the internet (RDP, SMB, bare databases).

3 · PAGE

Change-based alerts

The first scan is the baseline; after that you hear when something appears or clears — a port opening, a chain breaking, an IP landing on a blocklist. One open port never becomes three pages a day.

The signals, spelled out

From your first domain to the whole fleet

These are the same signals the big attack-surface platforms sell — the difference is you can be watching your first domains five minutes from now, free, and the same system carries all the way up: escalation ladders on every plan, on-call rotations on Team, and on Enterprise your BYO-AI agent receives every exposure alert as a structured envelope and investigates before you're awake. MSPs and platform teams run every client domain in one workspace with per-asset alert routing.

Why change-based beats scanning reports: a monthly PDF of everything that's open tells you what you already meant to expose. The finding that matters is the delta — the port that opened last night, the cert that stopped validating today, the SPF record someone "simplified." That's what pages you here.

Common questions

Do you scan my servers?

Not without proof. Certificates, DNS, mail auth and reputation are public records — those run on any domain you add. Port scanning sends traffic to the host, so it only runs on assets whose ownership you've verified, and it probes a fixed, bounded list — not an exhaustive sweep.

What can I watch?

Public domains, hostnames, and public IP addresses. Private ranges and internal-only names can't be seen from the internet — cover those with the agent and normal uptime monitors in the same account.

What does it cost?

The free plan includes 3 exposure assets with full alerting, alongside your uptime monitors. Paid plans raise the asset count and start at $9/mo. See pricing →

How is this different from my uptime monitor?

It's the other half. Uptime tells you when the site stops answering; Exposure tells you when what it's showing the world changes — an expiring chain, a hijacked record, a port that shouldn't exist. One account, one place that pages you, for both.

Watch your first 3 domains free →

Nothing to install. No credit card.