How to evaluate an EASM vendor
Including the questions where we come off worse. Start with those.
Where we are the wrong choice
Established vendors in this category offer things we do not, and are not pretending to build:
- A takedown team with registrar relationships
- Analyst hours and managed triage
- Years of threat-actor and malware research
- Closed-forum and dark-web collection
If those are what you need, buy one of them. Nothing below changes that.
Questions worth asking anyone
| Question | Typical vendor | Nano EASM |
|---|---|---|
| Can you try it before talking to anyone? | Usually a form, then a call | Scan on the homepage, no account |
| Is the free scan instant? | Active tests need signed authorisation first | Passive, so it runs immediately |
| Does every finding carry evidence? | Varies; often a severity and a title | Reproducible request where the check can produce one; screenshots from Professional up |
| Is the detection methodology published? | Rarely, and often under NDA | Finding categories published in full |
| Can findings reach your own tooling? | Usually an API, sometimes webhooks | REST, webhooks, SIEM stream, MCP |
| Is there an AI-client integration? | Not typically offered | MCP server, read-only |
| Can you learn the price without a call? | Often not | Plans are published |
Who this is not for
If you need someone to take phishing sites down for you, brief you on threat actors, or work a queue on your behalf, we are not that. If you need to know what of yours is reachable from the internet, and to prove it, that is the whole product.
Scan a domain