Skip to main content
HOME|COMMERCIAL SPECIFICATION
TRANSPARENT ENGINEERING PRICING

Predictable Surveillance Tiers

Zero per-scan overages. Fixed monthly pricing for automated attack surface reconnaissance, dangling DNS takeovers, and email hygiene.

TIER 01Monthly billing

Starter Plan

$49/ month

Essential automated perimeter defense for fast-moving engineering teams.

3 Root Domains fully monitored
Daily automated reconnaissance
42-Provider dangling CNAME radar
RFC-7208 SPF lookup barrier audit
Multi-tier SSL expiry tracking (30d/14d/7d)
Resend transactional email alerts
SELECT_STARTER →
TIER 02 // RECOMMENDEDPriority queue

Pro Plan

$129/ month

High-frequency surveillance and team collaboration for multi-cloud estates.

15 Root Domains fully monitored
Hourly scan cycle cadence
42-Provider dangling CNAME radar
RFC-7208 recursive include traversal
Slack Webhook & PagerDuty triggers
Unlimited engineering team seats
SELECT_PRO →
// SPECIFICATION BREAKDOWN

Detailed Feature Matrix

Feature / CapabilityStarter ($49/mo)Pro ($129/mo)
Monitored Apex Domains3 Domains15 Domains
Automated CadenceEvery 24 HoursHourly (24x / day)
Cloud Takeover SignaturesAll 42 SignaturesAll 42 Signatures
RFC-7208 10-Lookup Barrier AuditIncludedIncluded (Deep Traversal)
TLS Expiry Radar30d / 14d / 7d Alerts30d / 14d / 7d Alerts
On-Demand UI & API RescansUnlimitedUnlimited (Priority)
Outbox Incident DeliveryResend DKIM EmailResend + Slack + Webhooks
Engineering Seats3 SeatsUnlimited
// ARCHITECTURAL FAQ

Frequently Answered Questions

How does SubdomainWatch detect dangling DNS before an attacker exploits it?

Our engine executes active recursive resolution against 42 documented cloud provider signatures (AWS S3, GitHub Pages, Heroku, Azure, CloudFront, etc.). When a CNAME returns a canonical target that responds with an orphan token (such as NoSuchBucket or 404 Web Site not found), SubdomainWatch flags the finding and dispatches an instant transactional alert before an external actor can claim the resource.

Why is the RFC-7208 10-lookup barrier critical for our business email?

RFC 7208 Section 4.6.4 dictates that evaluating an SPF record must not perform more than 10 DNS queries across all mechanisms (include, a, mx, ptr, exists, redirect). If third-party SaaS services (SendGrid, Zendesk, Google Workspace) push your includes beyond 10 lookups, major mail transfer agents return a PermError, silently routing legitimate corporate email to spam or dropping it entirely.

Does SubdomainWatch require installing an agent or sensor on our servers?

No. SubdomainWatch is 100% external, non-invasive attack surface surveillance. We discover and audit your attack surface from the vantage point of an adversary on the public internet using authoritative DNS resolution, Certificate Transparency (CT) logs, and passive OSINT.

Can our engineering team trigger on-demand scans when pushing DNS changes?

Yes. In the Defense Console, you can trigger instant on-demand scans via the 'Re-scan Now' button, or call our API from your CI/CD pipeline (e.g. Terraform or GitHub Actions) to verify DNS propagation immediately.

What happens when an SSL/TLS certificate is flagged in the radar?

Our TLS Expiry Radar categorizes certificates into 30-day, 14-day, and 7-day alert thresholds. Incidents are automatically queued in the Defense Console and transactional alerts are dispatched via Resend email and Slack so your team can intervene before expiration blackouts affect users.

Can we cancel, upgrade, or change plans at any time?

Yes. All plans are billed on a flexible month-to-month basis with zero lock-in contracts. You can upgrade from Starter to Pro or cancel directly from your console at any time with one click.