External assurance for operators and MSPs

Find the exposure.
Prove the response.

NetworkPilot turns authorized external scanning, continuous posture monitoring, CVE evidence, and remediation history into one defensible record—built for client conversations, cyber-insurance documentation, and the work between assessments.

01 Authorized assets02 Isolated workers03 Sealed evidence
9Runnable scan profiles
65,535TCP ports with isolated coverage
100Frequency-ranked UDP services
PDF + JSONIntegrity-sealed evidence formats
Operator console

One target. Clear answers.

Choose a diagnostic, enter a public domain, and get a readable result without the terminal archaeology.

Resolve records

DNS Lookup

EDGE READY

Inspect A, AAAA, MX, TXT, NS, CNAME, CAA, and SOA records.

Awaiting targetYour results will appear here.
One operating system for external risk

From authorization to verified remediation.

The useful part of a security assessment is not a single scan. It is the chain of custody around what was allowed, what was tested, what changed, and what the organization did next.

01

Authorize the asset

Prove a domain with DNS or record an accountable authorization attestation for a public IP.

02

Choose the right depth

Launch a focused scanner, a repeatable assessment pack, or isolated worker coverage.

03

Follow real execution

Watch authorization, resolution, collection, discoveries, and evidence sealing as they happen.

04

Prove the follow-through

Assign remediation, set a due date, retest the finding, and export the retained evidence.

Current scanner coverage

Focused profiles. Honest confidence.

Start with fast public-surface checks, move into isolated network discovery when the scope calls for it, and retain exactly what was performed or skipped. Ambiguous service evidence is reported as limited—not promoted into a guessed vulnerability.

Cloud profile
01 · Posture

Baseline posture

A broad, non-invasive review of DNS, HTTPS, response headers, and public hardening controls.

DNS · HTTPS · HEADERS
Cloud profile
02 · Recon

Domain recon

Capture recursive DNS answers, mail routing, SPF/DMARC posture, certificate policy, and public address inventory.

A · AAAA · NS · MX · TXT · CAA
Cloud profile
03 · Posture

SSL/TLS scanner

Validate certificate identity and lifetime, record negotiated TLS, and probe legacy TLS support on up to four public endpoints.

CERTIFICATE · TLS · CIPHER
Cloud profile
04 · Recon

Web surface

Review HTTPS redirects, browser protections, robots.txt, and RFC 9116 security-contact publication.

REDIRECTS · POLICY · SECURITY.TXT
Cloud profile
05 · Recon

Port scanner

Map TCP exposure with Quick, System Range, custom, or isolated full-range coverage on an authorized asset.

34 QUICK · 1–1024 SYSTEM · CUSTOM · FULL TCP
Isolated worker
06 · Vulnerability

Network Assurance

Full TCP discovery with safe TLS and HTTP protocol pivots, certificate-chain analysis, service evidence, and exact NVD correlation.

65,535 TCP · TLS/HTTP · SAFE SIGNATURES · NVD
Isolated worker
07 · Vulnerability

Critical CVE scanner

Correlate exact versioned CPE identifiers to high and critical NVD CVEs, with CISA known-exploited findings prioritized.

FULL TCP · CPE · NVD · CISA KEV
Isolated worker
08 · Recon

UDP Exposure

Probe the 100 most frequently exposed UDP services from a separately isolated, rate-limited worker and preserve open versus open-or-filtered evidence.

TOP 100 UDP · LIGHT SERVICE PROBES · STATE CONFIDENCE
Isolated worker
09 · Vulnerability

Safe Vulnerability Validation

Run a pinned, reviewed Nuclei template bundle against confirmed web services with redirects, OAST, fuzzing, code, headless, and credentialed checks disabled.

CURATED TEMPLATES · PINNED SERVICES · NO OAST/FUZZING
Assessment packs

Repeatable scope without repetitive setup.

Launch coordinated profiles against the same authorized domain and follow one unified activity timeline.

Surface Sweep

Build a broad external baseline across DNS, mail policy, TLS, web controls, and the quick TCP exposure map.

5 PROFILES · ONE LAUNCH · UNIFIED TIMELINE
Web Assurance

Recheck transport, certificate health, response protections, disclosure, and public policy files.

3 PROFILES · WEB POSTURE · REMEDIATION
After the scan

Built for the work that follows.

NetworkPilot keeps exposure history, customer boundaries, and remediation accountability in the same workspace as the technical evidence.

Continuous posture

Monitoring that sees more than ports.

Track DNS, mail policy, HTTPS availability, certificate health, browser protections, and TCP exposure. NetworkPilot records meaningful drift without turning ordinary timing noise into an incident.

DNS & mailTLS lifecycleWeb controlsPort drift
MSP operations

Every client stays in the right lane.

Separate client workspaces preserve role-scoped assets, scans, monitors, reports, and evidence. Invite administrators, analysts, and viewers without mixing customer data.

Client workspacesScoped rolesBranded reportsEmail notices
Remediation

Findings become accountable work.

Move findings from open to in progress, document accepted risk, assign ownership and due dates, then use a later scan to prove whether the condition is gone.

AssigneesDue datesRisk acceptanceVerified retests
Cyber-insurance and MSP evidence

A report that shows
what actually happened.

Every completed assessment can preserve the authorized target, scope, scanner version, methodology, observed addresses, findings, remediation guidance, and a canonical SHA-256 integrity fingerprint.

  • Insurer-ready PDF and machine-readable JSONClear evidence for renewals, client reviews, and retained technical records.
  • NIST CSF and CIS contribution mappingUseful framework context with explicit boundaries—never a blanket compliance claim.
  • Role-scoped and brandable deliveryMSP workspaces retain the correct client boundary and can carry provider branding.
ASSESSMENT EVIDENCESEALED
POSTURE82/ 100
COVERAGEConclusiveperformed / skipped ledger
Authorized scopeRecorded
Findings & remediationRetained
Integrity fingerprintSHA-256
Export formatsPDF / JSON
INTEGRITY8f1c…4d97verified at export
Security model

Defensive intelligence.
Deliberately constrained.

NetworkPilot helps owners understand their public attack surface while reducing the chance that the platform itself becomes an abuse tool.

  • Pinned public resolutionPrivate and reserved destinations are rejected, and scans connect to the validated public address.
  • Signed, bounded worker scopeDeeper jobs use short-lived signed manifests, rate limits, cancellation, and one pinned public address.
  • Safe validation policyCurated templates disable OAST, fuzzing, code, headless, credentials, and exploits. Credentialed and exploit activity is not offered.
ASSURANCE OVERVIEWEXAMPLE
82/ 100
CONCLUSIVE COVERAGE
Transport94
Exposure82
Web posture78

Ready when the renewal questionnaire arrives

Know your public risk.
Keep the evidence.