How to evaluate an EASM vendor

Including the questions where we come off worse. Start with those.

Where we are the wrong choice

Established vendors in this category offer things we do not, and are not pretending to build:

  • A takedown team with registrar relationships
  • Analyst hours and managed triage
  • Years of threat-actor and malware research
  • Closed-forum and dark-web collection

If those are what you need, buy one of them. Nothing below changes that.

Questions worth asking anyone

QuestionTypical vendorNano EASM
Can you try it before talking to anyone?Usually a form, then a callScan on the homepage, no account
Is the free scan instant?Active tests need signed authorisation firstPassive, so it runs immediately
Does every finding carry evidence?Varies; often a severity and a titleReproducible request where the check can produce one; screenshots from Professional up
Is the detection methodology published?Rarely, and often under NDAFinding categories published in full
Can findings reach your own tooling?Usually an API, sometimes webhooksREST, webhooks, SIEM stream, MCP
Is there an AI-client integration?Not typically offeredMCP server, read-only
Can you learn the price without a call?Often notPlans are published

Who this is not for

If you need someone to take phishing sites down for you, brief you on threat actors, or work a queue on your behalf, we are not that. If you need to know what of yours is reachable from the internet, and to prove it, that is the whole product.

Scan a domain