tfThreatFoundFree scan
Continuous exposure monitoring

You can’t fix the leak you were never told about.

ThreatFound watches the domains you own around the clock and alerts you the moment a leaked API key, an exposed .env, an open .git folder, or a subdomain takeover appears. Every alert is proven before it reaches you — we retrieve the file, parse it, and for secrets we confirm the key actually authenticates. No noise. Just “here’s what’s exposed, here’s the proof.”

https://

Continuous monitoring launches soon · no card · join the waitlist

29M secrets were leaked to public GitHub in 2025 — up 34% YoY · GitGuardian
How it works

From domain to proof in minutes.

01

Add a domain

Paste a domain you own. No agent, no SDK, no code change, no CI step.

02

Verify with one DNS record

Drop in a single TXT record to prove ownership — that authorizes us, and only for your own property. The first scan starts the moment it verifies.

03

Get paged with proof

We watch from the outside, the way an attacker does. When a verified exposure appears, you get the finding, the proof, and a diff of exactly what changed.

What we catch

Six checks, one rule: if we can’t prove it, we don’t page you.

Proven, not guessed

Every alert is a file we actually read — not a status code we saw.

Most scanners see an HTTP 200 and cry wolf. We retrieve the file and parse its structure. If we say your .env is exposed, it’s because we pulled real KEY=VALUE pairs out of it.

Live-key verification

We only page you for keys that actually still work.

When we find a leaked credential we run a read-only identity call to confirm it authenticates — AWS, Stripe, GitHub, Slack, OpenAI, GitLab today, and growing. Dead, rotated and demo keys are suppressed on sight.

Exposed files, parse-proven

.env, .git, database dumps and backups — confirmed readable, not merely reachable.

The active parse-prober fetches the candidate and validates it’s a real artifact (a real git index, a parseable dotenv, a genuine SQL dump). We show you the exposed variable names — never the values.

Subdomain takeover flags

Catch dangling DNS before someone claims your subdomain.

For every host we discover, we check whether its DNS points at a de-provisioned cloud resource (S3, Heroku, GitHub Pages, Netlify). Flagged as TAKEOVER RISK — VERIFY, because dangling-DNS is probabilistic and we won’t dilute the proof-first promise.

CT-powered discovery

We find the forgotten subdomains you don’t remember spinning up.

We watch Certificate Transparency logs to surface every host a cert was ever issued for on your verified domains — staging, legacy, shadow-IT — then scan each one. Every TLS cert is already public; we read it before an attacker does.

Month-over-month diff

See exactly what changed since last scan — not another full dump.

Every scan is diffed into a clean ledger: what’s NEW, what’s RESOLVED (we confirm the fix), what’s UNCHANGED. Your perimeter on a timeline — cadence set by plan.

Why not just Detectify or Intruder

Detectify starts at ~$300. We start at zero.

ThreatFoundDetectify / Intruder
Entry priceFree (1 domain); paid from $29/moIntruder from ~$99/mo; Detectify surface monitoring from ~$302/mo
Buy without a sales callYes — self-serve, card, live in minutesDetectify: quote required. Intruder: continuous ASM sits in higher tiers
OnboardingOne DNS TXT record, then the first scan runsAccount setup + asset scoping
False positivesSuppressed by default — alerts fire only after retrieve + parse, or live-key authFP reduction often a paid add-on / crowdsourced validation
Proof on each alertParsed file contents / authenticated-key result, on the alert itselfFindings lists; validation often needs added service
Built forSMB founders, indie devs, small agencies — no security team requiredSecurity teams with budget and headcount
Agency + white-labelYes — $99/mo, multi-client + white-label PDFEnterprise engagement / not indie-agency positioned

Competitor pricing/positioning from public pricing pages, 2026. We contrast, we don’t copy.

Pricing

Flat, per domain. No per-asset bill shock.

Start free forever on one domain. Upgrade when you want continuous watch and instant alerts. 20% off annual.

Watchtower

$0forever
1 domain

Monthly scan + change-diff

  • 1 verified domain
  • Monthly exposure scan
  • Proof-backed findings
  • Change-diff since last scan
Join the waitlist

Solo

$29/mo
1–3 domains

Daily + instant alerts

  • Up to 3 domains
  • Daily continuous monitoring
  • Instant email / webhook alerts
  • Full proof layer
Join the waitlist
Most popular

Pro

$49/mo
up to 5 domains

Hourly + multi-domain

  • Up to 5 domains
  • Hourly monitoring
  • Multi-domain dashboard
  • Live secret re-verification
Join the waitlist

Agency

$99/mo
~10 domains

Multi-client + white-label

  • Up to 10 domains
  • Multi-client workspace
  • White-label PDF reports
  • Everything in Pro
Join the waitlist
Questions

Straight answers.

What about false positives? I already ignore noisy scanners.

That’s exactly why ThreatFound exists. We don’t alert on a status code — we retrieve and parse the file, and for secrets we run a liveness check that confirms the key actually authenticates. Dead keys, demo keys and honeytokens are suppressed. Subdomain-takeover is the one category we flag as “risk — verify” rather than proven, because dangling-DNS detection is inherently probabilistic and we’re honest about that.

Is it legal and safe to scan my domain?

You can only add domains you prove you own with a DNS TXT record, so you’re authorizing us to look at your own property. File and subdomain checks are read-only. One honest nuance: when we find a leaked key we verify it with a read-only identity call to the provider — that’s an authentication attempt, an active step, not passive browsing. We keep it minimal and we’re transparent that it is active.

How is this different from a penetration test?

A pentest is a human, deep, point-in-time engagement — often thousands of dollars, once or twice a year. ThreatFound is continuous and automated: it watches the exposures that appear between pentests — the .env pushed Tuesday, the key leaked Thursday, the subdomain that went stale last month. Smoke detector, not annual fire inspection.

Do I need to install anything?

No. No agent, no SDK, no CI step, no code changes. You add a domain, verify it via DNS, and we work from the outside — the same vantage point an attacker has.

What happens to the sensitive data you find?

We store the minimum evidence needed to prove a finding — variable names and metadata, never secret values — encrypted, and you can request deletion anytime. We never sell, share, or publish your exposures. Finding a leak and then leaking it ourselves would defeat the entire point.

I’m a solo dev or tiny team. Is this overkill?

The opposite. Enterprises have security teams watching this; you have a free plan and a busy week. Solo builders and small agencies are exactly who leaks hurt most, and who no tool under ~$95/mo was built for. Start on Watchtower free — one domain, zero cost, real proof.

Early access

Be first when continuous monitoring opens.

Self-serve monitoring isn’t open to everyone yet. Join the waitlist and you’ll be first in line for proof-first exposure monitoring on the domains you own — leaked keys, exposed .env/.git, subdomain takeover.

No spam · we only monitor domains you own · unsubscribe anytime

Find out what’s already exposed.

Continuous, proof-first monitoring for the domains you own. Join the waitlist and you’ll be first in line when it opens.