Features

Seven risk categories. One scan.

SurfaceLoop discovers your internet-facing assets and scans them across every category that matters — simultaneously, continuously, from the outside.

01

Open Ports & Services

Discover and monitor open TCP ports and exposed services across your external attack surface.

11.8% of UK SME domains exposed SSH directly to the internet. UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
The SurfaceLoop Ports & Services page -- asset, IP, port and service, with risk based on what the port is.
Ports & Services -- asset, IP, port and service, with risk based on what the port is.

02

Exposed Web Panels

Detect admin panels, management interfaces, and login pages exposed to the public internet.

37.8% had an exposed web admin panel or CVE-flagged software. UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
exposed-web-panels · example.com3 findings
CRIT

Jenkins dashboard accessible without authentication

staging.example.com:8080

CRIT

phpMyAdmin login page exposed to public internet

db.example.com

HIGH

Fortinet SSL VPN login page — version fingerprint visible

vpn.example.com

Example findings from a real report

03

TLS & Certificates

Monitor TLS configuration, certificate expiry, weak ciphers, and chain-of-trust issues.

15.7% of assets had a self-signed, expired or mismatched certificate. UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
The SurfaceLoop Certificates page -- expiry shown as a countdown, with issuer changes flagged.
Certificates -- expiry shown as a countdown, with issuer changes flagged.

04

Security Headers

Check HTTP security headers including CSP, HSTS, X-Frame-Options, and Permissions-Policy.

85.6% of domains were missing at least one recommended security header. UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
security-headers · example.com3 findings
HIGH

Missing Content-Security-Policy — no XSS protection

app.example.com

HIGH

Missing Strict-Transport-Security — vulnerable to SSL stripping

staging.example.com

MED

Referrer-Policy not set — leaking URL paths to third parties

app.example.com

Example findings from a real report

05

Known Vulnerabilities (CVEs)

Scan for known CVEs and exploitable vulnerabilities using thousands of detection templates.

174 occurrences of a critical WordPress RCE flaw (CVE-2020-28037). UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
cve-detection · example.com3 findings
CRIT

Palo Alto PAN-OS command injection — unauthenticated RCE via GlobalProtect

CVE-2024-3400 · 10

CRIT

FortiOS out-of-bounds write — remote code execution, actively exploited

CVE-2024-21762 · 9.8

HIGH

HTTP/2 Rapid Reset — denial of service via stream cancellation flood

CVE-2023-44487 · 7.5

Example findings from a real report

06

DNS & Email Spoofing

Validate SPF, DKIM, and DMARC configuration to prevent domain spoofing and phishing.

73.9% of domains had a spoofing-relevant gap in SPF, DKIM or DMARC. UK SME Exposure Snapshot (Sep 2026)
Read the full guide →
dns-email-security · example.com3 findings
CRIT

DMARC policy set to p=none — domain can be spoofed freely

example.com

HIGH

SPF record includes +all — permits any server to send as your domain

example.com

MED

DKIM selector 'default' uses 1024-bit key — upgrade to 2048-bit

example.com

Example findings from a real report

07

Subdomain Enumeration

Discover subdomains, shadow IT, forgotten services, and development environments exposed to the internet.

Read the full guide →
subdomain-discovery · example.com3 findings
CRIT

Subdomain points to decommissioned S3 bucket — takeover possible

legacy.example.com

HIGH

Development server with debug mode enabled — stack traces visible

test.example.com

HIGH

Monitoring dashboard accessible without VPN — internal metrics exposed

grafana.example.com

Example findings from a real report

Across every category

Capabilities that apply to all seven.

Continuous scanning

Automated rescans on your schedule. New exposures trigger alerts the moment they appear — not at the next quarterly review.

Severity prioritisation

Findings ranked by real-world exploitability. Critical exposures surface first so your team fixes what matters.

Change tracking

Every scan compared against the last. See what opened, what closed, and what changed — with full history.

Alert routing

Findings delivered where your team works. Email, Slack, webhooks — configured per severity level.

Zero deployment

Pure external scanning from the attacker's perspective. No agents, no firewall changes, no internal access.

API access

Full REST API for every scan result. Integrate findings into your existing security tooling and workflows.

See what's exposed on your attack surface

Add your domains. SurfaceLoop scans all seven categories and shows you what to fix first.