See your external exposure, OT/ICS included
See your entire external attack surface the way an attacker does, monitored continuously. Domains, services, certificates, leaked data and look-alike domains, plus the OT/ICS protocols generic scanners miss, all in read-only.
110+
Finding types
15+
OT/ICS ports monitored
30 min
To full surface
Your EASM sees your website. Not your Siemens controller.
Generic scanners miss industrial assets entirely, which is exactly where the real exposure often hides.
Outcomes your team will feel.
One engine, three surfaces
Your perimeter, your vendors', and a prospect's before you sign. Same engine, three uses.
A grade you can explain
Per category, per axis and overall, with actual coverage shown next to it.
Read-only, including on OT
Industrial protocol detection that never disturbs the networks, maximum severity only when exposure is confirmed.
Key capabilities
Find your assets from your company name alone
Give a company name, not a list of domains: the engine finds your domains, subsidiaries and acquisitions on its own, then surfaces subdomains, IPs, services, certificates and technologies. This is the first complaint raised against platforms in large-account tenders, and it is solved here.
Five axes, 43 detection categories
Email and anti-spoofing, infrastructure and web, reputation and brand, leaks and disclosure, plus OT and ICS. One hundred and seventy-four detection templates built in, nine change types tracked, and signed webhooks to Slack and Teams. Every finding carries its evidence.
The scan tells you what it did not look at
Partial coverage is declared as such, never dressed up as a good grade. Very few products can do this, and none hands it back to the customer. It is what lets you know whether an A+ means "everything is clean" or "we could not see everything".
Official breach registries and leaked credentials
Declarations made to regulators are used by name: CNIL, ICO, OAIC, US attorneys general, SEC EDGAR and CanadaBreaches. A public, dated, legally clean source. Leaked credentials are detected without ever storing an email address in clear text, guaranteed by design.
Progress over time
Trend your exposure down and show the board a surface that shrinks month over month, with evidence.
Proactive exposure intel
Dark web breach exposure, leaked credentials and look-alike domains registered against your brand, caught before they are used against you.
Not 10,000 findings. An Action Feed of what matters.
Every new exposure, change and risk becomes one prioritized action in your feed, routed to the right owner and tracked to closure. Your team focuses only on what moves the needle, not on noise.
Three moments. Three uses.
- Case 1
Manufacturing OT (controller exposed after maintenance)
1,200-employee manufacturer, 8 sites, Siemens S7 and Allen-Bradley fleet. A contractor intervenes on the Trois-Rivières site PLC. Sets up a temporary VPN for remote access. Forgets to close it on departure. At 48h, the FortaRisks OT scanner detects a Siemens S7-1200 controller accessible from the Internet. Slack alert at 2:22 PM. Confirmation by OT team at 2:45 PM. VPN closed at 3:10 PM. No incident.
- Case 2
SaaS B2B (subdomain takeover)
80-employee SaaS publisher, 12 active marketing subdomains. A marketing campaign uses partner.acme.ca pointing to a Webflow page. Campaign ends. Webflow page deleted but DNS remains. At 6 hours, FortaRisks detects a possible takeover. Alert. DNS cleaned in 2 hours. Avoids a phishing attack exploiting a legitimate subdomain.
- Case 3
Regional bank (DMARC missing vs Loi 25)
Quebec cooperative bank, 600 employees. FortaRisks scan: DMARC at p=none, MTA-STS missing, BIMI missing, IP in Spamhaus DNSBL. Email Health score: C. Quantified recommendations: DMARC p=quarantine then p=reject deployment in 60 days, MTA-STS, DNSBL removal. Score climbs to A in 90 days. Avoids a phishing wave impersonating the brand.
What's included
Discovery & attribution
- Attribution from your company name alone
- Domains, subsidiaries and acquisitions found on their own
- 36 discovery and analysis connectors
- 5 scan axes, 43 detection categories
- 174 detection templates built in
- The scan declares what it did not look at
- Modbus
- Siemens S7
- Allen-Bradley
- Niagara Fox
- BACnet
- EtherNet/IP
- IEC-104
- DNP3
- OPC UA
- Read-only, never disturbing the networks
What we scan
- 110+ finding types, each with its evidence
- Email health: SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI
- Subdomain takeover (83 services)
- Ports, TLS, headers, WAF, exposed APIs
- Typosquatting, blocklists, reputation
- Leaked credentials, with no address stored in clear text
- Dark web monitoring: credentials and brand leaks
- Exposed databases and public source code
- CVE correlation with CVSS, EPSS and CISA KEV
Optional AI enrichment
AI speeds this module up, it does not replace it. Every capability described above works without it. Enrichment is enabled per workspace, and can be turned off without losing a feature.
In attack surface, AI targets explanation: turning a technical finding into a business consequence, grouping related exposures, drafting the paragraph for the board. Detection and the A+ to F grading stay deterministic and defensible.
Sovereignty: the platform is built and hosted in Canada, beyond the reach of the US CLOUD Act. For AI, you decide whether enrichment is enabled, on which data and within which scope; deployment options are defined with you, according to your residency and confidentiality requirements. No customer data is used to train a model.
EASM is not a silo. All modules use its signals.
EASM produces real exposure signals. Without them, other modules work in theory. With them, they decide based on what's actually exposed.
EASM → Posture & Compliance
An expected control (e.g., "TLS 1.2 minimum on all exposed services") can be objectively validated by EASM findings. No more declarative. No more questionnaire. The proof is observed.
EASM → CTI
Each detected exposed service (with its exact version via CPE) is automatically correlated to active CVEs. An Apache HTTP 2.4.49 exposed becomes immediately a critical finding if KEV applies.
EASM → TPRM
The 110+ finding types are applied to third-party perimeters. The OT/ICS scanner is applied to industrial suppliers. No additional ingestion cost.
EASM → Risk Engine
EASM provides the "actual exposure" component of the risk score. Without EASM, the AI can't distinguish a theoretical risk from a tomorrow-morning exploitable risk.
Explore the other modules.
30 minutes to know what to fix first.
A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.
Frequently asked questions
Is the OT/ICS scanner active or passive?
Active but read-only. We fingerprint the 8 supported protocols with no writes, no control commands and no state changes, with rate limiting tuned for OT networks. Ultra-sensitive IP ranges can be excluded.
Does it cover exposed cloud buckets?
Yes. Misconfigured S3, Azure Blob and GCS are detected, and subdomain takeover is checked across 83 services including S3, Azure, GitHub Pages, Netlify, Vercel and Webflow.
How do you avoid scanning a third party's assets?
Attribution starts from your company name and your domains, then every discovered asset carries ownership evidence you can review and correct. The same engine also serves, deliberately, to scan a vendor or a prospect: in that case the perimeter is explicit and, on the vendor side, validated by them.
Are findings actionable or just informational?
Every finding is documented with a technical explanation, proof, severity and a step-by-step fix, with references. Critical findings can be exported to your ITSM.