External attack surface scan for client websites
Pentestr scans the public surface that attackers, clients, and security reviewers can see without logging in.
Agencies, MSPs, and dev teams responsible for public client websites.
Public exposure can change after deployments, DNS updates, hosting migrations, and rushed fixes.
A quick picture of visible risk with prioritized remediation.
Public exposure changes constantly
A website's public surface is not static. Infrastructure, dependencies, DNS, and hosting changes can introduce visible gaps after launch.
Focus on what can be seen from outside
Pentestr is intentionally external. It checks what is reachable without credentials, which makes it fast and safe for authorized client workflows.
Use it as a first line of defense
External scans catch common visible problems early and help teams decide when deeper manual testing is needed.
What Pentestr checks
Questions
What is an external attack surface scan?
It is a scan of publicly reachable website and domain exposure, such as TLS, headers, ports, WAF, DNS email records, and known issues.
Does it scan private data?
No. Pentestr focuses on public exposure and does not inspect authenticated private application content.