Know what you expose to the internet, without touching it.
surfer builds an inventory of likely internet-facing web applications, APIs, webhooks and MCP endpoints for your organisation's domains. It uses public passive data only: Certificate Transparency logs and ordinary DNS lookups. It never contacts your hosts.
Sign in with Google What surfer does
Access is by invitation. If you are not a member of an organisation, sign-in will be refused.
Passive by design
No port scans, no probing, no vulnerability checks. Nothing is ever sent to a discovered host or IP.
Evidence you can judge
Each candidate shows why it was listed: certificate sightings, DNS answers, CNAME targets and name patterns, with a confidence score.
Find the forgotten
Spot stale certificates, dangling CNAMEs and non-production hosts so they can be decommissioned or restricted.
Accountable
Every submitted domain is attested and audit-logged per organisation, with quotas and abuse review.