Platform

Every Module. One Index. One Place to Act.

The Deepinfo Platform is a Continuous Threat Exposure Management platform built as modules, each reading a different part of the internet, from the hosts you expose to the credentials that have already leaked. All of them run on Deepinfo’s own internet index, with one engine, one scoring scale and one API.

acme.example’s street, seen from the public internet. A street drawn in section over Deepinfo’s own index: your building, a vendor’s building and a lookalike across the road, with one finding of each kind the platform makes.
  1. Under everything, cut and larger than the street: Deepinfo’s own index of registrations, DNS and certificates, collected, resolved and kept with history. Deep Search & Insights opens it to your team. What stands on the street stands on it.
  2. Asset discovery: a gate in your garden wall that nobody listed, vpn-legacy.acme.example at 203.0.113.24, not in inventory.
  3. Continuous scanning: a window on api.acme.example that was shut at the last scan: 8443/tcp newly open, high.
  4. Risk detection: your shop window, shop.acme.example: PHP 7.4 · end of life, high.
  5. Risk scoring: a staging cabin on your roof, staging.acme.example: Apache httpd 2.4.49, CVE-2021-41773, CVSS 9.8, listed in CISA KEV, critical.
  6. Threat intelligence: on the pavement, an employee laptop outside your fleet: its saved sso.acme.example login, in an infostealer log.
  7. Brand protection: across the road, a shopfront that is not yours, acme-login.example, a lookalike caught by a contains rule.
  8. Third parties: the vendor’s building, drawn dashed: remote.payroll.example, 3389/tcp newly open, critical.
  9. One place to act, under all of it: one scoring scale, one issue lifecycle, shared notifications, scheduled reports, one REST API.

What Each Module Reads.

EASM, BRP and TPRM read the visible internet: your hosts, the domains built to imitate you, your vendors. CTI reads what has already leaked. Deep Search & Insights opens the index under all of them to your team.

The Modules Share Data. That’s the Platform.

A shared login does not make a platform. The modules read one index, and your surface and your vendors run through one scanning engine, so a vendor’s domain is scanned, scored and tracked the way one of yours is.

  • One internet index under all the modules
  • One engine and one score for your surface and your vendors
  • Shared decisions for EASM issues and CTI credentials: resolved, risk accepted, ignored, false positive
  • Notifications across EASM, CTI and BRP
  • Reports on demand or on a schedule
  • One REST API, one apikey header, one filter syntax
  • All assets 1,562
  • Domains 3 (selected)
  • Subdomains 1,312
  • IP addresses 247

Domains

  • grade A acme.example (opened on its record)
    • grade A www.acme.example
    • grade B shop.acme.example
    • grade C vpn.acme.example
    • grade A mail.acme.example
    • 1,280 more
  • grade A acme-eu.example
  • grade C acme-labs.example

grade A acme.example

Last check 2 hours ago

  • Overview (selected)
  • Issues
  • Subdomains
  • Technologies
  • Open ports
  • Vulnerabilities
  • Asset info

Info

IP addresses

  • 203.0.113.10
  • 203.0.113.11
  • 203.0.113.12
  • +5 more

Insights

Issues
38
Subdomains
1,284
Technologies
23
Open ports
46
Vulnerabilities
7

Collected, Resolved and Kept With History.

Deepinfo collects its own registration, DNS and certificate data, resolves it and keeps it with history. Discovery in EASM and TPRM and lookalike matching in BRP all query it, DSI opens it to your team, and Deepinfo Data Feeds and API Services deliver it on its own.

400M+ domains

Registered domains across every TLD, with registration, WHOIS history and daily deltas.

Domain Search · Feeds · WHOIS

2B+ subdomains

Subdomains discovered and resolved to the IP addresses they point to.

Subdomain Finder · Feeds

200B+ DNS records

Every observed DNS record, kept with its history, so infrastructure can be traced back in time.

DNS Lookup · DNS History · Reverse IP · Reverse MX · Reverse NS

30B+ SSL certificates

Certificates collected and indexed. The names a certificate covers often reveal hosts nobody announced.

SSL Lookup

Discover, Monitor, Prioritize, Act.

  1. 01

    Discover

    EASM and TPRM start from a seed domain and propose related assets for your team to approve. BRP matches domains in the index against your brand keywords.

  2. 02

    Monitor

    Approved assets are scanned continuously, and each layer keeps its history. CTI reads breach data, infostealer logs and dark web sources for your domains and people.

  3. 03

    Prioritize

    CVEs are ranked with CVSS, EPSS and CISA KEV together. Assets and domains get a security score with a timeline, and monitored lookalikes get a risk score.

  4. 04

    Act

    Each issue stays on record until a rescan verifies the fix. Notifications, reports and the API carry the work to whoever owns it.

Questions About the Platform

What is Continuous Threat Exposure Management?

Continuous Threat Exposure Management (CTEM) is a program model, described by Gartner, that replaces periodic assessments with an ongoing cycle of scoping, discovery, prioritization, validation and mobilization.

The Deepinfo Platform covers discovery, prioritization and mobilization across your surface, your brand, your third parties and data that has already leaked. Validation, such as breach and attack simulation, is a different category of tool.

Do we have to buy every module?

No. A quote covers the modules you use, and others can be added as your program grows. See pricing for what shapes the number.

Does the platform need an agent or access to our network?

No. It works from the outside in, reading what anyone on the internet can see: DNS, certificates, WHOIS, open ports and web responses. Internal networks and systems behind a login stay out of its view by design, as the methodology explains.

Where does the data come from?

The index is Deepinfo’s own, built from the open internet: passive DNS, certificate transparency logs, public WHOIS and IP WHOIS records, and crawling of publicly reachable web pages. Cyber Threat Intelligence adds breach data, infostealer logs and dark web sources.

How does the platform relate to Data & API?

They share one dataset. The platform wraps it in workflows: discovery, scanning, scoring, issue states, notifications and reports. Deepinfo Data Feeds and Deepinfo API Services deliver the data itself, as bulk files and endpoints, for teams that build their own pipelines.

See Data & API for the feeds and endpoints.

Is Third-Party Risk Management a separate engine?

No. Each third party becomes a portfolio that the EASM engine discovers, scans across the same layers and scores on the scale used for your surface. That is why a vendor’s score and yours can be compared directly.

Can we work with the platform from our own tools?

Yes. The platform API covers EASM, CTI, BRP, notifications and reports, with one apikey header and one filter syntax for search and bulk actions. See the API reference and the integrations page.

Is there a mobile app?

Yes. Deepinfo Mobile is a companion app for iOS and Android: asset overviews, issues by severity, inventory search and security news, signed in with your platform credentials.

Walk Through the Modules on Your Own Data.

Book a working demo with our team.