Cohort One is open — twelve organisations Apply

External attack surface management

Find it.
Prove it's yours.

Ambit takes a single identifier — a ticker, an LEI, a domain — resolves every entity your organisation controls, and inventories every class of internet-facing asset belonging to any of them — networks, domains, applications, cloud, mobile, code and control systems. Each conclusion arrives with the evidence that produced it, and the reasons it was not something weaker.

Seed → control closure → attribution Evidence-derived, recomputable Passive by default
Seed resolution — illustrative

Accepts a ticker · LEI · CIK · domain · legal name

payments-eu..example
Candidate asset · web application · TLS 443
Accumulated LLR 0.0 · Confidence
Owns · Confirmed

Illustrative record. Entity names and registry identifiers are redacted here exactly as they are in any Ambit output shown outside a tenant, and every domain used on this site sits under a reserved documentation namespace that cannot be registered by anyone. Owned by the customer, operated by a payments vendor, hosted on shared CDN infrastructure — attributed as three separate relations, because collapsing them is how address-based signals become false positives.

Redacted — never rendered, never in the page source

The hard half

Discovery is a weekend. Attribution is the product.

Pulling forty thousand hostnames out of Certificate Transparency for a large conglomerate is not difficult. Deciding which six thousand are actually yours — rather than a marketing agency's, a CDN's shared infrastructure, or a company with a similar name in another jurisdiction — is the entire problem. Every tool in this category fails in one of two directions.

Failure mode one — too loose

The customer drowns and stops looking

A surface padded with a competitor's assets and a reseller's parked domains is not a surface. It is a queue. Teams learn within a fortnight that the tool is usually wrong, and the finding that mattered is buried under nine hundred that did not.

Failure mode two — too tight

It misses the reason you bought it

Tighten the thresholds and the false positives disappear, along with the marketing site a business unit stood up outside procurement, and the subsidiary acquired eleven months ago whose netblocks nobody has ever inventoried. That shadow estate was the point.

“We shrink the review queue by finding better evidence, never by loosening thresholds. Handing the customer homework is the fastest way to lose them.”

Nothing in Ambit is stored as a bare fact. Every conclusion is derived from append-only evidence and can be recomputed from scratch. That is what makes “why do you think this is ours?” a question with an answer — and what lets a single weight change re-score the entire graph without sending one additional packet.

Correlated evidence collapses

Five subdomains on one certificate is one certificate

Evidence carries a correlation key, and only the strongest member of each group counts. Without this, one weak signal repeated reaches arbitrary confidence — the standard way these systems manufacture certainty they have not earned.

Definitive evidence vetoes

A registry record is not a louder hint

A registrar record that refutes ownership overrules any quantity of circumstantial support rather than being out-voted by it. Refutation wins ties, because the failure that costs you the customer is the false positive.

Expansion

Discovery is a fixpoint, not a pipeline

A certificate reveals a domain. The domain reveals an identity tenant. The tenant reveals eleven more domains, and one of them carries a copyright footer naming a subsidiary that was not in the annual report — which re-seeds the corporate graph and starts the whole thing over. Ambit runs until nothing new appears above threshold, then reports what changed each day after that.

RE-SEED · UNTIL NOTHING NEW APPEARS SEED One identifier CONTROL Entity closure DISCOVERY Candidates SCORE Band Ticker · LEI · CIK Domain · legal name Filings · registries Consolidation edges CT · DNS · RDAP · BGP Cloud · SaaS · packages
Connectors emit typed candidates with evidence. They never decide anything — the scorer does, once, in one place, against weights you can inspect.

Scope

Control defines your surface. Not ownership.

If you hold 51% of a company that holds 57% of another, your economic interest in the third is 29.07% — and you control it outright. Its exposed assets are your incident. Tools that walk ownership percentages arrive at the wrong set, and tools that walk one pass down the tree miss control held jointly across two intermediates.

Ambit computes the controlled set as a fixpoint over consolidation edges drawn from statutory filings and global identifier registries. A parent controlling two subsidiaries that hold 30% and 25% of a fourth company controls that fourth company — and admitting it can push a fifth over the line. Divestitures remove branches, because a scan that only ever adds entities eventually reports somebody else's attack surface as yours.

51% 100% 57% 30% plc B.V. NL · in scope Inc DE · in scope Ltd 29.07% held · controlled
Held jointly across two intermediates. A single-pass traversal finds neither the arithmetic nor the branch beneath it.

Scope of discovery

Everything the organisation put on the internet. Owned or operated.

Not the subset one scanner happens to be good at, and not domains with a few extras bolted on. Ambit inventories every class of externally reachable asset belonging to any entity in your controlled tree — sanctioned or not, current or forgotten, whether or not anyone still employed remembers standing it up.

IP spaceRegistry allocations, delegated ranges, cloud-assigned space, netblocks nobody has inventoried since the acquisition
ASNs and routingAutonomous systems, live BGP announcements, routing registry objects, upstream and peering relationships
DomainsRegistrations across every registrar and jurisdiction, subdomains, parked estate, lapsed names still resolving
CertificatesFull transparency-log history, issuance patterns, wildcards, expired and misissued certificates still trusted somewhere
Web applicationsOrigins, login portals, admin interfaces, staging environments, marketing sites stood up outside procurement
APIs and endpointsDocumented and undocumented, including endpoints extracted from client-side code and mobile binaries
Mobile applicationsStore listings under every publisher account, bidirectional app-site association proof, embedded backends
Cloud accountsProvider accounts and subscriptions, exposed storage, orphaned infrastructure left running after a project closed
SaaS and identity tenantsIdentity tenants, federated domains, sanctioned platforms and the shadow subscriptions bought on a card
Email and messagingMail exchangers, sender authentication posture across every domain you own, and the lookalikes you do not
Data storesInternet-reachable databases, caches, search clusters, object storage and backup targets
Code repositoriesOrganisation accounts, public repositories, and internal references leaked into them
Package namespacesRegistry scopes and published packages across ecosystems, plus the typosquat exposure around them
OT and ICSInternet-exposed control systems, historians, and the remote access paths reaching into them
Registrations and brandRegistrar and DNS provider accounts, trademarks, social handles, and impersonating registrations

Total inventory is the north star. We will not guarantee it — we measure the distance to it.

Some assets are genuinely undiscoverable from outside an organisation, and a vendor who tells you otherwise is describing a sales position rather than a technical one. Ambit is built to close that distance across every class above: maximum achievable coverage, a stated confidence for every asset attributed, and an explicit inventory of where the engine could not see. Coverage you can audit beats coverage you are asked to trust.

Owned or operated — attributed separately, never collapsed. A payment page you own, a vendor operates and a cloud provider hosts is three relationships, with three remediation paths and three different people to call. Ambit records all three against the same asset rather than picking one and hoping.

Honest scope

Every report ships with an inventory of its own blind spots

Total inventory is the north star, and a north star is a bearing rather than a destination. Nobody can promise it honestly — so instead of quietly reporting a smaller number and calling it complete, Ambit tells you where it stopped being able to see.

What Ambit delivers is maximum achievable coverage, a confidence per asset, and an explicit statement of where it could not see. Four entities in your tree with zero discovered assets is implausible, and saying so is more useful than quietly reporting a smaller number. This is the section auditors read first.

Known gaps — appended to every scan
  • NetblocksNo OT or ICS visibility for two subsidiaries: their address space could not be identified in any regional registry.
  • RegistryFour entities in the controlled set returned zero discovered assets. Implausible for their size — treat as unresolved, not as clean.
  • SourceThree intermediate parents named in filings match no enumerated row by name. Excluded from the closure rather than guessed at.
  • JurisdictionTwo jurisdictions publish no machine-readable beneficial ownership register. Corporate tree below them is filing-derived only.

Build order

Cohort partners set the order of everything below the line

Ambit is built in typed stages, each one a class of surface rather than a feature list. The foundation and entity resolution are running. Which surface comes next is a decision we would rather make with a room full of security leaders than alone.

E0FoundationsEvidence model, control graph, scorer, connector contract, work queue, accuracy harnessRunning
E1Entity resolutionGlobal identifier registries, statutory subsidiary exhibits, company registers, trademarksIn progress
E2Attribution engineSource reliability priors, adjudication queue, per-asset explainabilityNext
E3Data lakeCertificate transparency ingestion, zone data, bulk RDAP, passive DNS and reverse WHOISPlanned
E4Domain and DNS surfacePlus light active verification — a TLS handshake, a resolution, a single requestPlanned
E5Network surfaceRegistry allocations, routing data, netblocks, and the continuous daily diffPlanned
E6Web and application fingerprintingFavicon and analytics pivots, endpoint extraction, content-policy graphPlanned
E7Cloud and SaaSIdentity tenant discovery, storage attribution, unsanctioned tenancyPlanned
E8Mobile, code and packagesApp store pivots, bidirectional app-site association proof, repository and registry scopesPlanned
E9Full active verificationGated on authorisation for the scope being scanned. Plus OT, ICS and data storesPlanned
E10Adaptive layerLearned weights, coverage-gap detection, hypothesis generation with deterministic verificationPlanned

Conduct

A tool that sends unsolicited traffic should be able to say exactly who it talks to

Passive by default

We read public records first

Entity resolution and the early discovery stages read public filings, registries and transparency logs. Nothing is sent to your infrastructure. Light verification arrives later and full scanning is gated on written authorisation for the specific scope.

Declared infrastructure

Every external host is enumerated

Every third-party service the engine contacts is registered in source with a purpose, and enforced by a test that fails the build otherwise. “Grep the codebase” is not an answer in a security review, and we do not intend to give it as one.

Data separation

Public observation and your findings are stored apart

Certificate logs, zone data and routing records are shared infrastructure — every scan improves them for everyone. Anything derived from your authorised verification, and your entity graph, is tenant-isolated. The dividing line is provenance, and it is decided before a schema is written.

Minimised retention

Registry records contain people

WHOIS and registration records carry personal data. We retain the minimum required to support an attribution, redact credentials in the audit trail by default, and never log personal data harvested from banners or registries.

Cohort One · design partners

We are taking twelve organisations into development with us

Ambit is in active development and is not generally available. Before it is, we want it tested against corporate structures complicated enough to break it. Cohort One is deliberately small — a partner who cannot get an hour of our engineering time is not a partner, and there are only so many hours.

We are selecting for structural complexity, not headcount. A four-hundred-person group with entities in nine jurisdictions and three unintegrated acquisitions is a far more valuable partner than a large, tidy, single-entity business.

What partners receive

  • Charter pricing, fixed for three years from general availability, at a substantial discount to list
  • Direct access to the engineers building the attribution model — not a success manager relaying tickets
  • Standing input on build order: the roadmap above is sequenced with cohort partners in the room
  • Your corporate structure used as ground truth, which means the engine is measured against your reality first
  • Full export of everything we attribute to you, in a format you own, whether or not you continue

What we ask in return

  • Roughly two hours a month with someone who knows your estate well enough to say “that is not ours”
  • Written authorisation before anything active is ever pointed at your scope, and the patience to define it properly
  • Permission to be told plainly when we are wrong, which is the only reason this programme exists
  • No obligation to buy, no obligation to reference us publicly, and no use of your name anywhere without written consent
Apply to Cohort One
Reviewed within five business days

Read by a person, not a scoring model. We reply either way. Nothing here is shared, sold, or used to seed a scan — we do not resolve your organisation without your written authorisation.

Application received

It goes to the people building the engine. You will hear back within five business days, whether or not there is a place in Cohort One — and if there is not, we will tell you which cohort we think fits.

AMB-C1-0000