External security posture & evidence

Security you can show, not just say.

Origin continuously checks your domains and APIs from the outside, explains what matters in plain English, and turns every scan into signed evidence you can hand to customers, assessors and insurers.

No card required · Scans only run on domains you verify
Origin
DashboardProjectsFindingsAudit
0
Critical
1
High
2
Medium
14
Assets
Open findings — worst first
HighTLS certificate uses deprecated signatureapi.acme…
MediumMissing DMARC recordacme…
LowServer version disclosed in headersdocs.acme…
Evidence pack
acme-software.co.uk · 11 June 2026
Signed ✓
Scope14 verified assets
Open findings1 high · 2 medium
HMAC-SHA256 · 9f4e2c81aa07d3…44b1 — verifiable offline

Verified domains only

Scans never run against anything you haven't proven you own. Re-checked at every job start.

Signed evidence

Every pack carries a tamper-evident manifest your reviewer can verify independently.

Append-only audit

Every scan, suppression and export is on the record. Nothing can be quietly edited.

UK data residency

Your data stays in London (AWS eu-west-2). A straight answer for your due-diligence form.

How it works

From domain to defensible evidence in four steps.

01

Verify

Add a DNS record to prove you own the domain. That's the whole setup — no agents, no code changes.

02

Discover

Origin maps your external surface: subdomains, services and APIs — including the ones you forgot about.

03

Check

Safe, rate-limited external checks of TLS, DNS posture, headers, exposed services and your web & API surface — on a schedule.

04

Prove

Findings become prioritised work; scans become signed evidence packs you can forward the day someone asks.

Findings written for humans, anchored to evidence.

One deduplicated list, worst first. Every finding pairs a plain-English explanation and remediation steps with the verbatim evidence it came from — so your engineer, your account manager and your assessor all read the same truth.

  • Severity-ranked and deduplicated across scanners
  • A “for leadership” paragraph on every finding
  • Assign owners, accept or suppress — with reasons, on the record
HighOpen
TLS certificate uses a deprecated signature algorithm
api.acme-software.co.uk · last seen 2 hours ago
What this means

Your API’s certificate is signed with SHA-1, which browsers and clients no longer trust. Customers connecting to your API may see security warnings or hard failures.

Evidence
subject=CN=api.acme-software.co.uk sig_alg=sha1WithRSAEncryption notAfter=2026-09-14

Monitoring, not a one-off test.

Schedule weekly or monthly scans and Origin keeps watch: new subdomains join the inventory, regressions get caught, and your evidence trail grows on its own.

  • Recurring schedules with rate limits you control
  • Webhook alerts for completed scans and new criticals
  • History that shows posture improving, quarter on quarter
Schedules — acme-software.co.uk
Weekly baseline✓ succeeded · Mon 08:00
Weekly API scan✓ succeeded · Mon 08:40
Discovery sweep+2 assets · Tue 02:00
Monthly deep scannext: 1 Jul
The same truth, three ways

Your engineer, your MD and your assessor — one finding, written for each.

Samengineer
HighOpen · assigned
TLS cert uses deprecated signature algorithm
api.acme-software.co.uk · nuclei
Remediation

Reissue the certificate with SHA-256. If using ACME/Let’s Encrypt, renew with current defaults; confirm the chain with the re-scan button.

Evidence
sig_alg=sha1WithRSAEncryption notAfter=2026-09-14
Exact asset, exact evidence, concrete fix.
Mayamanaging director
For leadership · business impact: customer-facing
One security item needs attention this sprint

Our API’s security certificate uses outdated technology that modern systems are starting to refuse. If unaddressed, customer integrations could fail with security warnings. The fix is routine for the engineering team — no customer action needed, no data was exposed.

Status

Assigned to Sam · expected to resolve this week · will appear as “resolved” in the next evidence pack.

Plain English, business impact, no jargon.
Alexexternal assessor
Evidence pack
Q2 2026 · acme-software.co.uk
Signed ✓
Finding #142high · open → assigned
First seen9 Jun 2026, scan #17
Raw evidenceincluded, verbatim
Audit trailcomplete, append-only
read-only viewer seat · manifest 9f4e2c81…44b1
Verifiable, dated, nothing editable after the fact.
All three views are generated from the same deterministic finding — AI writes the words, never the facts.
An honest tool

What we won’t claim.

This is not a penetration test.

Automated external checks are affordable, repeatable and useful — and they are not a substitute for skilled manual testing. We'll never pretend otherwise, and your evidence packs say exactly what was checked.

AI never invents findings.

Deterministic scanners find; AI explains. Every AI-written sentence sits next to the raw evidence it came from, and anything that can’t be traced to evidence is dropped, not shown.

We don't scan what isn't yours.

Ownership is verified before any scan, and re-verified every time one starts. Safe-by-default rate limits mean we never hammer your production systems — or anyone else’s.

Pricing

Plain pricing, in pounds.

Every plan starts with a 14-day trial. No card required.

Solo

For a founder watching one product's exposure.
£79 /month
  • 1 verified domain + its subdomains
  • Weekly scheduled scans
  • Plain-English findings & remediation
  • Signed evidence packs
Start trial

Team

For a digital business that gets asked for proof.
£129 /month
  • 3 domains + API scanning (OpenAPI)
  • Daily-to-weekly schedules, webhooks
  • Owner assignment & triage workflow
  • Audit log, team roles, viewer seats for assessors
Start trial

Partner

For consultancies and MSPs running client estates.
£249 /month, from
  • Multi-workspace client management
  • Brandable evidence packs
  • Everything in Team, per client
  • Priority support
Talk to us

The next time someone asks “are you secure?” — send the pack.

Verify a domain and run your first scan this afternoon.