External attack surface management
Ambit takes a single identifier — a ticker, an LEI, a domain — resolves every entity your organisation controls, and inventories every class of internet-facing asset belonging to any of them — networks, domains, applications, cloud, mobile, code and control systems. Each conclusion arrives with the evidence that produced it, and the reasons it was not something weaker.
Accepts a ticker · LEI · CIK · domain · legal name
Illustrative record. Entity names and registry identifiers are redacted here exactly as they are in any Ambit output shown outside a tenant, and every domain used on this site sits under a reserved documentation namespace that cannot be registered by anyone. Owned by the customer, operated by a payments vendor, hosted on shared CDN infrastructure — attributed as three separate relations, because collapsing them is how address-based signals become false positives.
Redacted — never rendered, never in the page source
The hard half
Pulling forty thousand hostnames out of Certificate Transparency for a large conglomerate is not difficult. Deciding which six thousand are actually yours — rather than a marketing agency's, a CDN's shared infrastructure, or a company with a similar name in another jurisdiction — is the entire problem. Every tool in this category fails in one of two directions.
A surface padded with a competitor's assets and a reseller's parked domains is not a surface. It is a queue. Teams learn within a fortnight that the tool is usually wrong, and the finding that mattered is buried under nine hundred that did not.
Tighten the thresholds and the false positives disappear, along with the marketing site a business unit stood up outside procurement, and the subsidiary acquired eleven months ago whose netblocks nobody has ever inventoried. That shadow estate was the point.
“We shrink the review queue by finding better evidence, never by loosening thresholds. Handing the customer homework is the fastest way to lose them.”
Nothing in Ambit is stored as a bare fact. Every conclusion is derived from append-only evidence and can be recomputed from scratch. That is what makes “why do you think this is ours?” a question with an answer — and what lets a single weight change re-score the entire graph without sending one additional packet.
Evidence carries a correlation key, and only the strongest member of each group counts. Without this, one weak signal repeated reaches arbitrary confidence — the standard way these systems manufacture certainty they have not earned.
A registrar record that refutes ownership overrules any quantity of circumstantial support rather than being out-voted by it. Refutation wins ties, because the failure that costs you the customer is the false positive.
Expansion
A certificate reveals a domain. The domain reveals an identity tenant. The tenant reveals eleven more domains, and one of them carries a copyright footer naming a subsidiary that was not in the annual report — which re-seeds the corporate graph and starts the whole thing over. Ambit runs until nothing new appears above threshold, then reports what changed each day after that.
Scope
If you hold 51% of a company that holds 57% of another, your economic interest in the third is 29.07% — and you control it outright. Its exposed assets are your incident. Tools that walk ownership percentages arrive at the wrong set, and tools that walk one pass down the tree miss control held jointly across two intermediates.
Ambit computes the controlled set as a fixpoint over consolidation edges drawn from statutory filings and global identifier registries. A parent controlling two subsidiaries that hold 30% and 25% of a fourth company controls that fourth company — and admitting it can push a fifth over the line. Divestitures remove branches, because a scan that only ever adds entities eventually reports somebody else's attack surface as yours.
Scope of discovery
Not the subset one scanner happens to be good at, and not domains with a few extras bolted on. Ambit inventories every class of externally reachable asset belonging to any entity in your controlled tree — sanctioned or not, current or forgotten, whether or not anyone still employed remembers standing it up.
Total inventory is the north star. We will not guarantee it — we measure the distance to it.
Some assets are genuinely undiscoverable from outside an organisation, and a vendor who tells you otherwise is describing a sales position rather than a technical one. Ambit is built to close that distance across every class above: maximum achievable coverage, a stated confidence for every asset attributed, and an explicit inventory of where the engine could not see. Coverage you can audit beats coverage you are asked to trust.
Owned or operated — attributed separately, never collapsed. A payment page you own, a vendor operates and a cloud provider hosts is three relationships, with three remediation paths and three different people to call. Ambit records all three against the same asset rather than picking one and hoping.
Honest scope
Total inventory is the north star, and a north star is a bearing rather than a destination. Nobody can promise it honestly — so instead of quietly reporting a smaller number and calling it complete, Ambit tells you where it stopped being able to see.
What Ambit delivers is maximum achievable coverage, a confidence per asset, and an explicit statement of where it could not see. Four entities in your tree with zero discovered assets is implausible, and saying so is more useful than quietly reporting a smaller number. This is the section auditors read first.
Build order
Ambit is built in typed stages, each one a class of surface rather than a feature list. The foundation and entity resolution are running. Which surface comes next is a decision we would rather make with a room full of security leaders than alone.
Conduct
Entity resolution and the early discovery stages read public filings, registries and transparency logs. Nothing is sent to your infrastructure. Light verification arrives later and full scanning is gated on written authorisation for the specific scope.
Every third-party service the engine contacts is registered in source with a purpose, and enforced by a test that fails the build otherwise. “Grep the codebase” is not an answer in a security review, and we do not intend to give it as one.
Certificate logs, zone data and routing records are shared infrastructure — every scan improves them for everyone. Anything derived from your authorised verification, and your entity graph, is tenant-isolated. The dividing line is provenance, and it is decided before a schema is written.
WHOIS and registration records carry personal data. We retain the minimum required to support an attribution, redact credentials in the audit trail by default, and never log personal data harvested from banners or registries.
Cohort One · design partners
Ambit is in active development and is not generally available. Before it is, we want it tested against corporate structures complicated enough to break it. Cohort One is deliberately small — a partner who cannot get an hour of our engineering time is not a partner, and there are only so many hours.
We are selecting for structural complexity, not headcount. A four-hundred-person group with entities in nine jurisdictions and three unintegrated acquisitions is a far more valuable partner than a large, tidy, single-entity business.
It goes to the people building the engine. You will hear back within five business days, whether or not there is a place in Cohort One — and if there is not, we will tell you which cohort we think fits.
AMB-C1-0000