# VeilScan VeilScan is an external attack surface monitoring platform for startups and SaaS companies. It runs a 50-node automated pipeline that scans internet-facing infrastructure — subdomains, open ports, cloud assets, TLS configuration, email security, and web application vulnerabilities — and validates every finding against real exploit evidence before reporting. No agents, no credentials, no internal network access required. ## Who it is for - SaaS founders and CTOs at companies with 5–200 employees who need security coverage without a dedicated AppSec hire - Fintech startups needing compliance-ready evidence for ISO 27001, SOC 2, PCI DSS, or GDPR audits - Engineering teams that need continuous monitoring between annual penetration tests - Non-technical founders who need board-readable risk reports they can share with investors - SMBs in the UK and South Asia without dedicated security staff ## What problems it solves - Unknown subdomains, cloud assets, and exposed services accumulating without visibility - Traditional scanner noise: thousands of unverified findings with no proof of exploitability - 11-month gap in security coverage between annual penetration tests - Missing compliance evidence for auditors requiring documented external security testing - No way to communicate technical risk to boards or investors in plain language ## How proof-based findings work Before a finding appears at Critical or High severity, the scan pipeline must produce a concrete artifact proving exploitability: a captured HTTP response containing real sensitive data (credentials, API keys, PII), a confirmed SQL injection trigger, a verified DNS takeover, or equivalent evidence. Anything that cannot be proven is automatically downgraded. This is enforced in the proof_validator node before any report generation. The result: a shorter list of fully actionable findings with a 0% Critical false positive rate. ## What the scanner checks 50-node pipeline: subdomain enumeration (subfinder, amass, CT logs, Wayback CDX), BGP/ASN recon, live hosts (httpx), open ports (nmap -sV + Shodan), tech fingerprinting (whatweb), 9,000+ nuclei templates, CVE enrichment (NVD), TLS/SSL, security headers, email security (SPF, DMARC, DKIM), cloud storage (46 checks), admin panel exposure, JavaScript secret mining and live key validation, PII scanning, subdomain takeover, SQL injection, XSS, SSRF, CSRF, CORS, command injection, IDOR, LFI, XXE, CRLF, LDAP, SMTP injection, shadow AI detection. ## Key URLs - Homepage: https://veilscan.net/ - Pricing: https://veilscan.net/pricing - Free scan: https://veilscan.net/free-scan - Features: https://veilscan.net/features - FAQ: https://veilscan.net/faq - Blog: https://veilscan.net/blog - Glossary: https://veilscan.net/glossary - Comparisons: https://veilscan.net/compare - What is EASM: https://veilscan.net/what-is-external-attack-surface-management - Full LLM context: https://veilscan.net/llms-full.txt