Your website
- Configuration file with secrets exposed
- Source code history exposed (.git folder)
- Website lists its folders publicly
EXPOSURE SONAR
Most breaches start with something left open. The Sonar looks at your company from the outside, the way an attacker does: website, email, databases, admin accounts. It tells you what is open, how to close it in plain steps, and confirms when it is really closed. Nothing to install.
01 · DIAGNOSE
Each finding is written for the person who runs the company, not for a security team. Serious first, weak signals kept apart, and nothing marked fixed on trust.
02 · FIX
What it is, where it is, why it matters, what it is not, what you need before you start, the steps, a way back, and a message you can hand to whoever manages your IT. Then you press one button and the Sonar checks again.
Anyone can send email that appears to come from acme.example. There is no published rule telling other mail servers what to do with a message that claims to be from you but is not.
A setting on the domain itself, not on any computer or mailbox. You change it once, wherever your DNS is managed.
The most common way a small company loses money to fraud is an invoice that appears to come from a real supplier, or an instruction that appears to come from the owner.
It does not mean anyone has attacked you. A door is unlocked; nobody has come through it yet.
You need access to wherever your domain's DNS is managed, usually the company you bought the domain from.
Numbered, one screen at a time, with the exact value to paste.
How to undo the change if mail stops flowing.
A message you can forward as it is, with everything they need.
03 · GUARANTEE
Where a fix has to wait, the Sonar offers a tripwire: a decoy placed exactly where the exposure is. If anyone tries to use it, you know within seconds. The two halves of Vantuz meet here.
WHAT IT CHECKS
Each one answers a question an attacker asks in the first five minutes. Titles are the ones you will see in the product.
Expired certificates, exposed admin panels, leaked credentials in public code, and cloud storage open to the world. Each check ships with its fix and its title in plain English.
04 · COVERAGE
A clean report is only worth something if you know what it covered. The Sonar groups findings by what each check could actually see, so a domain you have not proven or an account you have not connected is never mistaken for a clean one.
SAFE BY DESIGN
The Sonar is built so that the worst it can do to your systems is nothing at all.
The Sonar checks a domain only after you prove you control it. It never scans the internet at large.
It sends the same requests a browser or a mail server would. It never attempts to exploit anything, and it never reads your mail, files or chat.
Checks run at a deliberately low rate so they never look like an attack to your own systems.
A finding is marked fixed only when a later check confirms it from the outside, never by a click.
The coverage report says what was checked and what could not be seen, so silence is never mistaken for safety.
What ran, when, against what, and what it saw. Yours to export.
SEE IT LIVE
Thirty minutes, your environment. We plant a tripwire, trigger it on purpose,
and you watch the whole response happen. No slides.
No. A scanner throws thousands of tests at your systems and returns a list a security team has to interpret. The Sonar asks a small number of questions an attacker would ask first, and answers each one in plain English with the fix attached.
Prove you own a domain by adding one DNS record, and optionally connect Google Workspace or Microsoft 365 read-only. There is nothing to install.
No. Every request is read-only, sent at a low rate, to hosts under domains you proved are yours. It never attempts to exploit a finding.
Continuously in the background at a slow pace, and on demand when you press "I fixed it, check again".
Yes, while it is in early access it is included in every plan for the domains you prove. Pricing per domain will be announced before it changes.