About surfer

surfer is a defensive asset-inventory tool. Given the domains an organisation is authorised to inventory, it lists the hostnames that look like internet-facing web applications, APIs, webhooks and MCP endpoints, so that stale or unmanaged ones can be found, decommissioned, made private or IP-restricted.

The passive-only promise

surfer uses public passive data only. It never connects to the hosts it lists.

Results are candidates with evidence and a confidence score, not confirmed-live applications.

Accountable use

Before adding a domain, a user must confirm they are authorised to inventory it on behalf of their organisation. Every submission is audit-logged per organisation, and quotas, rate limits and abuse review apply.

How surfer identifies itself

Requests to the Certificate Transparency search services carry this User-Agent, which points back to this page:

surfer/<version> (+https://<this site>/about)

surfer sends nothing to your servers, so you will not see this User-Agent in your own web server logs.

Opt-out and contact

If you control a domain and do not want it inventoried, or you believe it was submitted by someone who is not authorised, write to abuse@northkeel.tech with the domain name. We will remove it from every organisation's inventory and block further submissions of it.