Platform
Every Module. One Index. One Place to Act.
The Deepinfo Platform is a Continuous Threat Exposure Management platform built as modules, each reading a different part of the internet, from the hosts you expose to the credentials that have already leaked. All of them run on Deepinfo’s own internet index, with one engine, one scoring scale and one API.
- Under everything, cut and larger than the street: Deepinfo’s own index of registrations, DNS and certificates, collected, resolved and kept with history. Deep Search & Insights opens it to your team. What stands on the street stands on it.
- Asset discovery: a gate in your garden wall that nobody listed, vpn-legacy.acme.example at 203.0.113.24, not in inventory.
- Continuous scanning: a window on api.acme.example that was shut at the last scan: 8443/tcp newly open, high.
- Risk detection: your shop window, shop.acme.example: PHP 7.4 · end of life, high.
- Risk scoring: a staging cabin on your roof, staging.acme.example: Apache httpd 2.4.49, CVE-2021-41773, CVSS 9.8, listed in CISA KEV, critical.
- Threat intelligence: on the pavement, an employee laptop outside your fleet: its saved sso.acme.example login, in an infostealer log.
- Brand protection: across the road, a shopfront that is not yours, acme-login.example, a lookalike caught by a contains rule.
- Third parties: the vendor’s building, drawn dashed: remote.payroll.example, 3389/tcp newly open, critical.
- One place to act, under all of it: one scoring scale, one issue lifecycle, shared notifications, scheduled reports, one REST API.
What Each Module Reads.
EASM, BRP and TPRM read the visible internet: your hosts, the domains built to imitate you, your vendors. CTI reads what has already leaked. Deep Search & Insights opens the index under all of them to your team.
External Attack Surface Management
Discovers the domains, subdomains and IPs tied to your organization, scans each one layer by layer, from WHOIS and DNS to open ports and web data, and ranks what it finds with CVSS, EPSS and CISA KEV. Each issue stays on record until a rescan confirms the fix.
Cyber Threat Intelligence
Reads breach data, infostealer logs and dark web sources for your domains, employees and customers, and profiles the threat actors that target your region and industry. Each finding points to an account, a device or a person your team can act on.
Brand Risk Protection
Matches domains across the index against your brand keywords: exact, inside a longer name, one typo away, or spelled with characters from other alphabets that read as your own. Each lookalike your team approves is then monitored across DNS, MX, SSL and HTTP, with a risk score timeline.
Third-Party Risk Management
Runs the EASM engine on a portfolio for each third party, with its discovery, scanning and scoring. A vendor’s score and yours sit on one scale.
Deep Search & Insights
Opens the index to your analysts and developers: domain search and reverse lookups, WHOIS and DNS history, vulnerability search and live lookups. It is the data the other modules run on.
Collected, Resolved and Kept With History.
Deepinfo collects its own registration, DNS and certificate data, resolves it and keeps it with history. Discovery in EASM and TPRM and lookalike matching in BRP all query it, DSI opens it to your team, and Deepinfo Data Feeds and API Services deliver it on its own.
Registered domains across every TLD, with registration, WHOIS history and daily deltas.
Domain Search · Feeds · WHOIS
Subdomains discovered and resolved to the IP addresses they point to.
Every observed DNS record, kept with its history, so infrastructure can be traced back in time.
DNS Lookup · DNS History · Reverse IP · Reverse MX · Reverse NS
Certificates collected and indexed. The names a certificate covers often reveal hosts nobody announced.
Discover, Monitor, Prioritize, Act.
-
01
Discover
EASM and TPRM start from a seed domain and propose related assets for your team to approve. BRP matches domains in the index against your brand keywords.
-
02
Monitor
Approved assets are scanned continuously, and each layer keeps its history. CTI reads breach data, infostealer logs and dark web sources for your domains and people.
-
03
Prioritize
CVEs are ranked with CVSS, EPSS and CISA KEV together. Assets and domains get a security score with a timeline, and monitored lookalikes get a risk score.
-
04
Act
Each issue stays on record until a rescan verifies the fix. Notifications, reports and the API carry the work to whoever owns it.
The Capabilities of Each Module.
Each module page covers its capabilities together, and each capability has its own page with the mechanism behind it.
- Asset DiscoveryEASM
- Continuous ScanningEASM
- Risk DetectionEASM
- RemediationEASM
- Risk ScoringEASM
- Dark Web SearchCTI
- Dark Web Mentions MonitoringCTI
- Employee Email Breach MonitoringCTI
- Compromised Employee Device MonitoringCTI
- Compromised Client Credential MonitoringCTI
- Compromised Payment Credential MonitoringCTI
- Executive Threat MonitoringCTI
- Threat Actor IntelligenceCTI
- Data Breach IndexCTI
- IOC FeedsCTI
- Cybersecurity NewsCTI
- Cyber Threat ScoreCTI
- Fraudulent Domain MonitoringBRP
- Social Media MonitoringBRP
- App Store MonitoringBRP
- Search Engine MonitoringBRP
- Managed TakedownBRP
- Vendor DiscoveryTPRM
- Continuous MonitoringTPRM
- Vendor Risk AssessmentsTPRM
- Vendor Risk ScoringTPRM
- Compliance TrackingTPRM
- Domain IntelligenceDSI
- Domain SearchDSI
- Vulnerability IntelligenceDSI
- Vulnerability SearchDSI
- Instant LookupsDSI
Questions About the Platform
What is Continuous Threat Exposure Management?
Continuous Threat Exposure Management (CTEM) is a program model, described by Gartner, that replaces periodic assessments with an ongoing cycle of scoping, discovery, prioritization, validation and mobilization.
The Deepinfo Platform covers discovery, prioritization and mobilization across your surface, your brand, your third parties and data that has already leaked. Validation, such as breach and attack simulation, is a different category of tool.
Do we have to buy every module?
No. A quote covers the modules you use, and others can be added as your program grows. See pricing for what shapes the number.
Does the platform need an agent or access to our network?
No. It works from the outside in, reading what anyone on the internet can see: DNS, certificates, WHOIS, open ports and web responses. Internal networks and systems behind a login stay out of its view by design, as the methodology explains.
Where does the data come from?
The index is Deepinfo’s own, built from the open internet: passive DNS, certificate transparency logs, public WHOIS and IP WHOIS records, and crawling of publicly reachable web pages. Cyber Threat Intelligence adds breach data, infostealer logs and dark web sources.
How does the platform relate to Data & API?
They share one dataset. The platform wraps it in workflows: discovery, scanning, scoring, issue states, notifications and reports. Deepinfo Data Feeds and Deepinfo API Services deliver the data itself, as bulk files and endpoints, for teams that build their own pipelines.
See Data & API for the feeds and endpoints.
Is Third-Party Risk Management a separate engine?
No. Each third party becomes a portfolio that the EASM engine discovers, scans across the same layers and scores on the scale used for your surface. That is why a vendor’s score and yours can be compared directly.
Can we work with the platform from our own tools?
Yes. The platform API covers EASM, CTI, BRP, notifications and reports, with one apikey header and one filter syntax for search and bulk actions. See the API reference and the integrations page.
Is there a mobile app?
Yes. Deepinfo Mobile is a companion app for iOS and Android: asset overviews, issues by severity, inventory search and security news, signed in with your platform credentials.
Walk Through the Modules on Your Own Data.
Book a working demo with our team.