You can’t fix the leak you were never told about.
ThreatFound watches the domains you own around the clock and alerts you the moment a leaked API key, an exposed .env, an open .git folder, or a subdomain takeover appears. Every alert is proven before it reaches you — we retrieve the file, parse it, and for secrets we confirm the key actually authenticates. No noise. Just “here’s what’s exposed, here’s the proof.”
Continuous monitoring launches soon · no card · join the waitlist
From domain to proof in minutes.
Add a domain
Paste a domain you own. No agent, no SDK, no code change, no CI step.
Verify with one DNS record
Drop in a single TXT record to prove ownership — that authorizes us, and only for your own property. The first scan starts the moment it verifies.
Get paged with proof
We watch from the outside, the way an attacker does. When a verified exposure appears, you get the finding, the proof, and a diff of exactly what changed.
Six checks, one rule: if we can’t prove it, we don’t page you.
Proven, not guessed
Every alert is a file we actually read — not a status code we saw.
Most scanners see an HTTP 200 and cry wolf. We retrieve the file and parse its structure. If we say your .env is exposed, it’s because we pulled real KEY=VALUE pairs out of it.
Live-key verification
We only page you for keys that actually still work.
When we find a leaked credential we run a read-only identity call to confirm it authenticates — AWS, Stripe, GitHub, Slack, OpenAI, GitLab today, and growing. Dead, rotated and demo keys are suppressed on sight.
Exposed files, parse-proven
.env, .git, database dumps and backups — confirmed readable, not merely reachable.
The active parse-prober fetches the candidate and validates it’s a real artifact (a real git index, a parseable dotenv, a genuine SQL dump). We show you the exposed variable names — never the values.
Subdomain takeover flags
Catch dangling DNS before someone claims your subdomain.
For every host we discover, we check whether its DNS points at a de-provisioned cloud resource (S3, Heroku, GitHub Pages, Netlify). Flagged as TAKEOVER RISK — VERIFY, because dangling-DNS is probabilistic and we won’t dilute the proof-first promise.
CT-powered discovery
We find the forgotten subdomains you don’t remember spinning up.
We watch Certificate Transparency logs to surface every host a cert was ever issued for on your verified domains — staging, legacy, shadow-IT — then scan each one. Every TLS cert is already public; we read it before an attacker does.
Month-over-month diff
See exactly what changed since last scan — not another full dump.
Every scan is diffed into a clean ledger: what’s NEW, what’s RESOLVED (we confirm the fix), what’s UNCHANGED. Your perimeter on a timeline — cadence set by plan.
Detectify starts at ~$300. We start at zero.
| ThreatFound | Detectify / Intruder | |
|---|---|---|
| Entry price | ✓Free (1 domain); paid from $29/mo | Intruder from ~$99/mo; Detectify surface monitoring from ~$302/mo |
| Buy without a sales call | ✓Yes — self-serve, card, live in minutes | Detectify: quote required. Intruder: continuous ASM sits in higher tiers |
| Onboarding | ✓One DNS TXT record, then the first scan runs | Account setup + asset scoping |
| False positives | ✓Suppressed by default — alerts fire only after retrieve + parse, or live-key auth | FP reduction often a paid add-on / crowdsourced validation |
| Proof on each alert | ✓Parsed file contents / authenticated-key result, on the alert itself | Findings lists; validation often needs added service |
| Built for | ✓SMB founders, indie devs, small agencies — no security team required | Security teams with budget and headcount |
| Agency + white-label | ✓Yes — $99/mo, multi-client + white-label PDF | Enterprise engagement / not indie-agency positioned |
Competitor pricing/positioning from public pricing pages, 2026. We contrast, we don’t copy.
Flat, per domain. No per-asset bill shock.
Start free forever on one domain. Upgrade when you want continuous watch and instant alerts. 20% off annual.
Watchtower
Monthly scan + change-diff
- ▹1 verified domain
- ▹Monthly exposure scan
- ▹Proof-backed findings
- ▹Change-diff since last scan
Solo
Daily + instant alerts
- ▹Up to 3 domains
- ▹Daily continuous monitoring
- ▹Instant email / webhook alerts
- ▹Full proof layer
Pro
Hourly + multi-domain
- ▹Up to 5 domains
- ▹Hourly monitoring
- ▹Multi-domain dashboard
- ▹Live secret re-verification
Agency
Multi-client + white-label
- ▹Up to 10 domains
- ▹Multi-client workspace
- ▹White-label PDF reports
- ▹Everything in Pro
Straight answers.
What about false positives? I already ignore noisy scanners.
That’s exactly why ThreatFound exists. We don’t alert on a status code — we retrieve and parse the file, and for secrets we run a liveness check that confirms the key actually authenticates. Dead keys, demo keys and honeytokens are suppressed. Subdomain-takeover is the one category we flag as “risk — verify” rather than proven, because dangling-DNS detection is inherently probabilistic and we’re honest about that.
Is it legal and safe to scan my domain?
You can only add domains you prove you own with a DNS TXT record, so you’re authorizing us to look at your own property. File and subdomain checks are read-only. One honest nuance: when we find a leaked key we verify it with a read-only identity call to the provider — that’s an authentication attempt, an active step, not passive browsing. We keep it minimal and we’re transparent that it is active.
How is this different from a penetration test?
A pentest is a human, deep, point-in-time engagement — often thousands of dollars, once or twice a year. ThreatFound is continuous and automated: it watches the exposures that appear between pentests — the .env pushed Tuesday, the key leaked Thursday, the subdomain that went stale last month. Smoke detector, not annual fire inspection.
Do I need to install anything?
No. No agent, no SDK, no CI step, no code changes. You add a domain, verify it via DNS, and we work from the outside — the same vantage point an attacker has.
What happens to the sensitive data you find?
We store the minimum evidence needed to prove a finding — variable names and metadata, never secret values — encrypted, and you can request deletion anytime. We never sell, share, or publish your exposures. Finding a leak and then leaking it ourselves would defeat the entire point.
I’m a solo dev or tiny team. Is this overkill?
The opposite. Enterprises have security teams watching this; you have a free plan and a busy week. Solo builders and small agencies are exactly who leaks hurt most, and who no tool under ~$95/mo was built for. Start on Watchtower free — one domain, zero cost, real proof.
Be first when continuous monitoring opens.
Self-serve monitoring isn’t open to everyone yet. Join the waitlist and you’ll be first in line for proof-first exposure monitoring on the domains you own — leaked keys, exposed .env/.git, subdomain takeover.
No spam · we only monitor domains you own · unsubscribe anytime
Find out what’s already exposed.
Continuous, proof-first monitoring for the domains you own. Join the waitlist and you’ll be first in line when it opens.