Live, agent-driven
for teams without a SOC

Continuous monitoring,
one short brief.
Your attack surface,
still being watched at 7am.

Your perimeter changes every day — a forgotten subdomain appears, a TLS certificate starts expiring, a cloud bucket quietly becomes world-listable after a Terraform drift. Forewatch runs a 24/7 AI monitoring agent across all of it; each morning at 7am you read one short brief with the deltas, what is most likely to be weaponised, and the smallest reasonable step back to green.

A clean day means nothing new appeared — not that the check was pointless.

Built for the 10-person team that does not have a SOC. We watch the rest while you sleep — and write it up every morning.

$430/movs enterprise $90k+/yr
55%of SMBs still lack adequate EASM
7amyour inbox, every weekday
Why nothing is also a brief

Why a daily check still matters
on a quiet day.

Your attack surface is not static. Every morning, fresh infrastructure, new DNS records, new certificates, and new SaaS integrations appear — without anyone on your team doing anything. Continuous monitoring is the only way to see what changed while no one was looking.

  1. 01

    Subdomains appear

    Acquisitions, contractor projects, and old marketing landing pages spin up new subdomains without anyone on your team tracking it.

  2. 02

    DNS records go stale

    A CNAME still pointing at a SaaS tenant you cancelled, an expired record still resolving, a registrar login quietly drifting — none of it surfaces without a fresh look.

  3. 03

    TLS certificates expire

    Renewal lag, missing intermediates, weak signature algorithms, and HSTS gaps. Quiet until a paying user hits a hard error and Chrome flags the page.

  4. 04

    Cloud bucket drift

    A Terraform change can flip an S3 / R2 / GCS / Azure blob world-listable overnight. New backup archives land there in the same window.

  5. 05

    New SaaS integrations

    An OAuth grant on a forgotten subdomain, an SSO provider added to a sidecar app, a webhook URL no one remembers wiring up. They grow without a ticket.

  6. 06

    Credentials leak and pivot

    Pastebins, stealer logs, GitHub history, employee pivots. A team mailbox in a fresh stealer batch means an SSO session is still live somewhere.

A clean brief does not mean nothing is happening — it means Forewatch re-scanned every one of those surfaces at 7am and the perimeter held. The same scan runs again tomorrow.

What counts as your attack surface

Four places the bad actors look
before they knock.

Your attack surface is every server, subdomain, cloud bucket, login page, vendor integration, and harvested credential an attacker can find online. Four of those surfaces account for the majority of the incidents you read about in the news.

01

Subdomains

A subdomain you spun up for a 2019 marketing campaign may still resolve to a public S3 bucket. Stale subdomains are the most common front door for a quiet takeover.

02

Cloud buckets

An S3, R2, GCS, or Azure blob that quietly became world-listable after a Terraform drift. May hold backup archives, customer exports, or stale credentials.

03

Stale DNS

Dangling CNAMEs to SaaS tenants you cancelled, expired records still resolving, hijackable registrar logins. Quiet, slow, and the attacker does not need a password to try.

04

Leaked credentials

Pastebins, stealer logs, GitHub history, employee pivots. A team mailbox showing up in a fresh stealer batch means an SSO session is probably still live.

Running today

Two detectors, no analyst required.

The current Forewatch agent covers the two highest-yield surfaces for small teams. Each detector is opinionated, ranked, and runs as one of many daily checks — the brief you read each morning is the headline, not the only one.

Each detector, plus the daily 7am brief, is the smallest reasonable step back to green.

Email spoofing

Live

Monitors your SPF, DKIM, and DMARC posture across every mail-sending subdomain. Flags missing or misconfigured records, monitors for new senders, and ranks the highest-yield fixes in the brief.

  • SPF record present, complete, and under the lookup limit
  • DKIM keys rotated recently and aligned to the From domain
  • DMARC policy at p=quarantine or p=reject (not p=none)

Cert & TLS

Live

Watches every certificate on every subdomain — expiry, renewal lag, chain completeness, and weak signature algorithms. Surfaces the certificates that will break a paying user first.

  • Expiry windows inside 30 / 14 / 7 days across every cert
  • Chain completeness and intermediate-cert trust
  • Weak signatures (SHA-1, RSA < 2048) and TLS < 1.2 endpoints
Why now

Built for the gap the enterprise tier forgot.

Now
$1.32B
2024 EASM market
Then
$6.87B
2030 projection, 27% CAGR
Under-served
55%
of SMBs lack adequate EASM
Live monitoring
24/7
AI agent, brief at 7am

Sources: ESG 2025 attack-surface survey · IDC EASM 2024–2030 forecast · internal customer pilots.

Next step

Point us at your domains.
Continuous from day 1.

Word-blind continuous monitoring from the first morning. No setup fee, no SOC, no contract — enroll your apex domain today and the first brief lands in your inbox at 7am. The next one is already scheduled.

A clean day means nothing new appeared — not that the check was pointless.