Agentless & Remote Architecture
See.Tech is built as a fully remote SaaS platform. No installations, no agents, no disruption. Its modular architecture can run APIs, GUIs, and custom scripts to meet enterprise integration needs.
Features
See.Tech gives organisations full visibility of their external cyber risk fast. Our agentless SaaS platform uncovers vulnerabilities, misconfigurations, and exposure across your digital footprint in hours, not weeks.
Platform
Eight capabilities that together give you an outside-in view of your organisation. Everything below this section is live in the platform today, not planned, not in beta.
See.Tech is built as a fully remote SaaS platform. No installations, no agents, no disruption. Its modular architecture can run APIs, GUIs, and custom scripts to meet enterprise integration needs.
Your attack surface extends beyond your firewall. See.Tech continuously scans public-facing assets using non-intrusive, automated methods to detect exposed services, weak configurations, and potential entry points.
Turn raw findings into clarity. See.Tech calculates an actionable exposure score that reflects your organisation's real-time risk posture, backed by prioritised recommendations.
Visualise your security posture at a glance. Interactive dashboards and exportable reports make it easy to interpret complex data across domains, vendors, and business units.
Your risk doesn't stop at your perimeter. See.Tech extends visibility across your supply chain and digital identity, helping you assess third-party exposure and identify brand misuse.
Stay ahead of breaches with continuous monitoring of underground forums and illicit marketplaces. See.Tech alerts you to leaked credentials and compromised data.
See.Tech's modular design allows you to add custom scripts, bespoke reporting views, or additional scanning modules with ease. All without disrupting your existing security workflows.
Our white-label option allows MSSPs, consultants, and service providers to offer See.Tech's capabilities under their brand, complete with custom branding, domain, and reporting formats.
Live now: Discovery & monitoring
An assessment is only as good as the asset list behind it. See.Tech builds that list for you, and keeps checking it between scans. We call this External Asset Discovery, and it covers subdomains, shadow assets, ghost assets, orphaned DNS records and certificates, the things elsewhere called shadow IT, digital footprint, or attack surface inventory. One capability, one name.
Enumerates subdomains automatically using passive DNS, certificate transparency logs, and wordlists. The asset inventory is surfaced before any credits are consumed, so you see the scope before you commit to it.
Identifies orphaned DNS records, forgotten subdomains, and stale IP ranges. Certificates, DNS records, and ghost assets are listed in one inventory view and ranked by exploitability.
Renders your DNS records as an interactive topology inside the Inventory section, a visual map of the attack surface rather than a table of hostnames.
Tracks expiry dates across every SSL/TLS certificate found, with proactive alerts at 60, 30, and 7 days. An expired certificate on a forgotten host is one of the most common ways a good posture quietly degrades.
Monitors your external-facing environment continuously between scheduled scans and flags material changes with a timestamp and a severity. Notifications can be muted per environment from Settings.
Configure weekly or monthly rescans and leave them running. Credits are deducted at runtime and a summary notification lands when the scan completes.
Live now: Threat intelligence
Reputation and web security assessment are both built in-house, so the data and the logic belong to See.Tech rather than to a third-party API that can change or disappear.
Monitors dark web sources and breach databases for credentials tied to your domains, so exposed accounts surface before they are used against you.
A fully in-house reputation engine with no third-party dependency. Checks blacklists, phishing databases, and reputation feeds, and detects typosquatting and lookalike domains registered against your brand.
Header, SSL, redirect, and configuration analysis built in-house rather than brokered through an external API. Which is also what makes it viable on free-tier scans.
Resolves company name and enriched organisational data for any domain scanned on the platform, so a hostname becomes an identifiable business rather than a string.
FlareIO dark web monitoring integrated into the Cyber News tab. Query by domain to surface threat intelligence targeted at your organisation specifically.
Compares your exposure score against an anonymised peer cohort by industry and region, shown as a percentile band. "Are we normal for our sector?" is usually the second question a board asks.
Live now: AI, reporting & assurance
The AI layer is live and governed by the same role-based access control as the rest of the platform. It can only ever see what the person asking is entitled to see.
A natural-language assistant embedded in the platform, built on Azure AI Foundry. Interrogate findings and scan results by conversation, with chat history and context retained across a session. RBAC-governed throughout.
A monthly, board-ready risk summary in plain English: what changed, what the current risk actually means, and where leadership should focus. Delivered as a PDF.
Every scan produces both a downloadable technical report and an executive summary suitable for board-level review. Two audiences, one assessment, no manual rewriting.
Shows how your risk score and posture compare against industry peers, directly on the platform dashboard.
Full scans, vulnerability assessments, executive reports, and breached-credential checks all require an authorisation acknowledgement, capturing username, date and time, IP address, endpoint, and browser version. Useful evidence when someone asks who authorised a scan.
The platform and its operations are certified against ISO 22301 (Business Continuity) and ISO 27001 (Information Security). Findings and reports reference applicable POPIA and GDPR obligations, and no data is stored beyond scan scope.
Live now: Platform, partners & workflow
Findings that stay inside a dashboard nobody opens are not findings. Everything here exists to get results in front of the right person, in the tool they already use.
Real-time notifications for critical and high findings by email, Slack, or Teams. Thresholds are configurable, and lower-severity findings can be batched into a digest instead of interrupting anyone.
Scan completions, new findings, alerts, and system updates surface inside the platform as well as out of it.
A fully documented REST API exposing the core capabilities, with API key management, rate-limit visibility, an interactive explorer, and webhook support. Build See.Tech into your own workflow rather than around it.
Full white-label support for MSP and MSSP partners, with per-client branding and portal access, so the platform arrives at your clients as your product.
Buy credits inside See.Tech via Stripe. Packages are managed by SuperAdmin, and Stripe reconciles into Xero, so purchasing does not require a conversation with anyone.
A built-in help form captures bugs and issues, routes them to the support team, and tracks every submission through to resolution.
And what comes next
See.Tech ships continuously, and more capability is in active development: CVE enrichment, AI remediation guidance, a unified risk engine, and free-tier assessments among it. We list features here once they are live in production, not when they are planned, so this page stays a description of the platform rather than a description of our intentions.
Where the boundary sits
Knowing what a tool does not do is how you work out where it fits. See.Tech sits outside your perimeter, alongside the tools that work inside it, not in place of them.
Not internal VM
Agent-based and credentialed tools such as Qualys, Tenable, and Microsoft Defender Vulnerability Management assess hosts you already control and already know about. See.Tech assesses what the internet can reach, including the assets nobody registered. They are complementary layers, and most organisations need both.
Not a pen test
Every assessment is external and non-invasive. Nothing is attacked, nothing is broken, and no production service is put at risk. If you need proof of exploitability you need a penetration test. And our findings are a well-evidenced place to point one.
Not agent-based
There is no endpoint agent, no internal scanner appliance, and no request for domain credentials or VPN access. That is what lets a first assessment run in hours, and what makes it straightforward to assess a supplier you have no technical relationship with.
Not a raw feed
Findings arrive scored by real-world severity, benchmarked against an industry peer cohort, and summarised for a board. Turning output into a decision is the product, not an exercise left to the reader.
Scans
Each scan is designed to uncover a different layer of your cybersecurity posture. Choose a single scan for quick insights or combine them for a full-spectrum view of your exposure. Credits never expire.
Get the complete picture. The Full Scan brings together all See.Tech assessments, from web and email security to DNS, SSL/TLS, vulnerability, and dark web breach checks. Into one comprehensive report.
The Web Security Scan analyses your website for vulnerabilities, hidden malware, and misconfigurations that could compromise visitors or data.
This scan applies See.Tech's intelligence to your suppliers and vendors, assessing their domains with the same depth and accuracy as your own.
The Email Security Scan inspects DMARC, SPF, and DKIM configurations, MX details, and potential spoofing risks to ensure your domain can't be easily impersonated.
This dark web scan searches for compromised email addresses associated with your domain, helping you identify vulnerable accounts and act before they are exploited.
Checks blacklists, phishing databases, and reputation engines to determine whether your domain or IP has been flagged as suspicious. Also detects typosquatting and impersonation attempts.
Analyses your certificates for validity, configuration strength, and expiry, ensuring your encryption is current and correctly implemented.
Maps all records tied to your domain, including A, MX, NS, TXT, and CNAME entries, detecting misconfigurations and unnecessary exposure.
A deep, non-intrusive assessment of your public IPs that mirrors attacker reconnaissance methods, complete with clear, actionable remediation guidance.
An executive-level summary that distils complex vulnerability findings into an accessible, high-level report. Ideal for board packs and compliance reviews.
Reviews your domain's overall security setup, flagging misconfigurations and offering recommendations. Perfect for ongoing monitoring or pre-audit checks.
A bundle is 10 credits from US$36. Credits never expire and work across every scan above.
Cost Calculator
Tick the scans you want. Credits are sold in bundles, so the estimate rounds up to whole bundles.
Credits never expire and can be used across any scan. Bundles are sold whole, so the estimate rounds up, any spare credits stay on your account.

Live Demo
A working instance loaded with real assessment data, open at demo.see.tech. Click through the dashboards, open a report, and see how findings are scored and prioritised. No account, no credit card, no scan credits spent.
Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.