Skip to content

EXPOSURE SONAR

Find what you expose.
Fix it before someone uses it.

Most breaches start with something left open. The Sonar looks at your company from the outside, the way an attacker does: website, email, databases, admin accounts. It tells you what is open, how to close it in plain steps, and confirms when it is really closed. Nothing to install.

11checks today, across website, email, databases and admin accounts
0software to install. Everything is checked from the outside
Read-onlythe same requests a browser or a mail server would send
Verifieda finding is fixed only when a later check confirms it

01 · DIAGNOSE

What is open,
in the order it matters.

Each finding is written for the person who runs the company, not for a security team. Serious first, weak signals kept apart, and nothing marked fixed on trust.

Findings that need action5 open · 1 verified fixed
Configuration file with secrets exposedstaging.acme.example/.envCriticalOpen
Source code history exposed (.git folder)shop.acme.exampleHighFixing
Admin account without two-step verificationGoogle Workspace · 2 accountsHighOpen
Database reachable from the internetdb.acme.example:5432HighOpen
Email from your domain can be forgedacme.exampleMediumOpen
Forgotten subdomain foundold-portal.acme.exampleLowVerified fixed
Last checked today, 09:41Sample workspace

02 · FIX

Every finding comes
with the fix.

What it is, where it is, why it matters, what it is not, what you need before you start, the steps, a way back, and a message you can hand to whoever manages your IT. Then you press one button and the Sonar checks again.

MediumEmail from your domain can be forgedacme.example

Anyone can send email that appears to come from acme.example. There is no published rule telling other mail servers what to do with a message that claims to be from you but is not.

Marked fixed only when a later check confirms itSample finding

03 · GUARANTEE

Cannot close it today?
Stand guard on it.

Where a fix has to wait, the Sonar offers a tripwire: a decoy placed exactly where the exposure is. If anyone tries to use it, you know within seconds. The two halves of Vantuz meet here.

Tripwires from findings3 armed
AWS credential tripwirePlaced where the exposed .env file wasArmed
Database credential tripwireIn the backup path that was reachableArmed
URL beaconInside the folder that listed its contentsArmed

WHAT IT CHECKS

Eleven checks today. More every month.

Each one answers a question an attacker asks in the first five minutes. Titles are the ones you will see in the product.

Your website

  • Configuration file with secrets exposed
  • Source code history exposed (.git folder)
  • Website lists its folders publicly

Your email

  • Email from your domain can be forged

Databases and cloud

  • Database reachable from the internet
  • Database open to the internet (AWS RDS)

Admin accounts

  • Admin account without two-step verification
  • Two-step verification not required
  • Old sign-in methods still allowed
  • Former employee's account still active

What you forgot

  • Forgotten subdomain found, from public certificate logs

Next

Expired certificates, exposed admin panels, leaked credentials in public code, and cloud storage open to the world. Each check ships with its fix and its title in plain English.

04 · COVERAGE

What was checked,
and what could not be seen.

A clean report is only worth something if you know what it covered. The Sonar groups findings by what each check could actually see, so a domain you have not proven or an account you have not connected is never mistaken for a clean one.

Coverage3 seen · 2 not seen
Google WorkspaceConnected · 14 accounts checkedSeen
Microsoft 365Not connected · 4 checks could not runNot seen
acme.exampleProven · 3 hosts checked from the outsideSeen
shop.acme.exampleProven · reachable, 3 checks ranSeen
AWSNot connected · RDS check could not runNot seen

SAFE BY DESIGN

Looking from the outside without ever knocking anything over.

The Sonar is built so that the worst it can do to your systems is nothing at all.

Only what you prove is yours

The Sonar checks a domain only after you prove you control it. It never scans the internet at large.

Read-only, always

It sends the same requests a browser or a mail server would. It never attempts to exploit anything, and it never reads your mail, files or chat.

Slow on purpose

Checks run at a deliberately low rate so they never look like an attack to your own systems.

Fixed means verified

A finding is marked fixed only when a later check confirms it from the outside, never by a click.

Honest about blind spots

The coverage report says what was checked and what could not be seen, so silence is never mistaken for safety.

Every check logged

What ran, when, against what, and what it saw. Yours to export.

SEE IT LIVE

Watch it catch an attack.
Then decide.

Thirty minutes, your environment. We plant a tripwire, trigger it on purpose,
and you watch the whole response happen. No slides.

Start free
Prefer a conversation? hello@vantuz.co

COMMON QUESTIONS

Before you
switch it on.

Something else on your mind?
Is this a vulnerability scanner?

No. A scanner throws thousands of tests at your systems and returns a list a security team has to interpret. The Sonar asks a small number of questions an attacker would ask first, and answers each one in plain English with the fix attached.

What do I need to set up?

Prove you own a domain by adding one DNS record, and optionally connect Google Workspace or Microsoft 365 read-only. There is nothing to install.

Can it break anything?

No. Every request is read-only, sent at a low rate, to hosts under domains you proved are yours. It never attempts to exploit a finding.

How often does it check?

Continuously in the background at a slow pace, and on demand when you press "I fixed it, check again".

Is the Sonar included in my plan?

Yes, while it is in early access it is included in every plan for the domains you prove. Pricing per domain will be announced before it changes.