Radar for your attack surface

See what attackers see — then fix what actually matters.

Continuous external attack-surface management and internal authenticated scanning in one tool, at an SMB price — with every finding ranked by real-world exploit likelihood and auto-mapped to your compliance controls.

Free tier is genuinely useful: real engines, real EPSS + CISA KEV prioritization, no credit card.

Fix 4, not 400

The handful that matter, surfaced automatically

Most scanners hand a non-expert a wall of 400 CVSS scores. Perimeter ranks by CVSS + EPSS (exploitation likelihood) + CISA KEV (confirmed in-the-wild) + your asset criticality — the prioritization layer Tenable and Qualys charge extra for, free here.

External ASM

Discover domains, subdomains, IPs, certs and exposed services from the internet. Detect subdomain takeover and attack-surface drift week over week.

Internal + container

Authenticated network scans (OpenVAS), OS-package and container CVEs, IaC misconfig, and SBOM/dependency CVEs (Trivy) via the Lookout agent.

Evidence, not a CSV

Every finding auto-maps to NIST CSF, SOC 2, PCI 11.3, ISO A.8.8 and CMMC RA.L2-3.11.x — a scan becomes audit evidence with a control reference and timestamp.

What changed on your attack surface this week?

A new dev subdomain pointing at an unclaimed S3 bucket. A wildcard cert 22 days from expiry. A KEV-listed RCE on your VPN appliance. Perimeter watches continuously and tells you the moment something new appears — then tracks it to closed with owners, SLAs, and rescan-to-verify.

One tool, the full triad — at the price of a single SKU

PerimeterIntruderDetectifyNessus Pro
External ASMYesYesYesAdd-on
Internal authenticated VMFree tier$499 ProNoYes
Container / SBOM scanningYesNoNoNo
EPSS + KEV prioritizationFreeYesPartialNo
Maps to compliance controlsNativeThinNoNo
Starting price$0$149/mo~€82/mo$4,390/yr

Pricing as published by each vendor; see our full comparison.