For IT & ops teams

The outside of your estate, watched around the clock.

You already run the systems. Bastion watches what they show the internet — certificate expiry across every host, DNS records that change when they shouldn't, subdomains that appear without a ticket — and routes each alert to the channel where your team will actually see it.

No card required to start. Plans from $25/month; first scan in about a minute.

What slips through when everything is manual

Certificate renewals on a spreadsheet

Renewal automation fails silently, wildcard certs cover less than assumed, and the one cert tracked nowhere is the one that expires on a Saturday.

DNS changes with no paper trail

An unexpected NS or MX change is what account takeover looks like from the outside. An SPF record that quietly got broader is how spoofing starts.

Subdomains nobody registered with you

Departments spin up vendors, vendors spin up CNAMEs, and the DNS zone grows entries that point at services someone else could claim.

Ports that opened overnight

A database answering the internet is worth knowing about today, not at the next quarterly review.

How Bastion covers it

Expiry warnings that escalate

Certificate reminders at 30, 14, 7 and 3 days — plus an alert if a cert is ever issued for your domain by a CA you don't use, and a watch on the domain registration itself.

Change detection with the diff inline

Every scheduled scan is compared with the last one. The change feed shows exactly what moved — the old SPF record and the new one, side by side — so triage starts with evidence, not investigation.

Discovery from certificate transparency

New subdomains appear in CT logs the moment they get a certificate. Bastion picks them up that week, flags dangling CNAMEs, and folds them into monitoring.

Alerts where your team already looks

Email, Slack, or a webhook into your ticketing. Critical changes are sent immediately; the rest batch into a weekly digest. Findings you've handled can be muted or accepted with a review date, so the digest stays short.

Common questions

Is scanning safe to run against production?

Yes. Every check is passive: Bastion reads HTTP headers, completes a normal TLS handshake, queries public DNS and attempts TCP connects on common ports — the same traffic any browser or mail server generates. No fuzzing, no exploitation, no authentication attempts, no load.

Can we monitor multiple domains and route alerts differently?

Yes — every plan covers multiple verified domains, and notification channels can be scoped so the right subset of alerts reaches the right inbox, Slack channel or webhook. See pricing for per-plan domain limits.

Does this replace our internal vulnerability scanner?

No — it covers the other side. Internal scanners see your network from inside; Bastion sees what an outsider sees: the public surface where certificate expiry, DNS drift and forgotten subdomains actually live. Most teams run both.

Put the estate under watch.

Verify your domains and let the schedule do the checking from tonight.

Start your 7-day trial

No card required to start. Cancel any time.