For security teams
Attack surface management without the enterprise contract.
The enterprise EASM suites do continuous discovery well — for six figures and a sales cycle. Bastion does the part that matters for a lean security team: CT-log subdomain discovery, lookalike-domain watching, a change feed with evidence inline, and an MCP server so your agents and tooling can drive it. Self-serve, from $25/month.
No card required to start. Plans from $25/month; first scan in about a minute.
Built around how security teams actually work
Discovery you didn't have to seed
Subdomain enumeration from certificate transparency logs, continuously — including dangling CNAMEs pointing at claimable services. The inventory grows as the estate does, not when someone updates a list.
A change feed, not a snapshot
Every scan diffs against the last: hardened SPF, new subdomain, a port that started answering, a header that vanished. The evidence is inline, so triage doesn't start with re-running the check.
Triage that sticks
Findings carry severity and evidence; accepted risk gets a review date, noise gets muted. What's left is a digest short enough that people keep reading it — which is the actual failure mode of most scanners.
Lookalike domains watched passively
Typosquats and homoglyph registrations — the raw material for phishing and invoice fraud — tracked with public DNS and CT data only.
Automation-first by design
The whole product as MCP tools
A hosted MCP server (OAuth 2.1, no API keys) exposes scans, findings, the change feed, triage and reports to Claude, ChatGPT, Codex or anything else that speaks MCP. Setup guide →
Webhooks into your pipeline
Critical changes can hit a webhook the moment they're found — into your SOAR, your ticketing, or a queue you own.
Hand-off prompts for remediation
Any scan exports as a severity-ordered prompt for a coding agent, with evidence and a verification command per finding — and an honest flagged list for fixes that live at the registrar or in a console instead of a repo.
Scope you can defend
Scanning runs only against domains ownership-verified via DNS TXT. Deliberately: the platform cannot be pointed at infrastructure you don't control.
Common questions
How does Bastion compare to enterprise EASM platforms?
The discovery core is the same idea — continuous external enumeration and change detection. What Bastion doesn't have: seat-based enterprise pricing, deployment projects, or a sales cycle. What the big suites don't have: self-serve setup in minutes and a price a team can expense. Comparisons with specific tools are in the articles.
Is the check depth enough for a security team?
The modules cover TLS and chain validity, HTTP security headers, DNS and email authentication (SPF/DMARC/CAA), CT-log subdomain discovery, service fingerprinting and a TCP connect sweep of common ports. It's passive by design — it complements your pentest and internal scanning; it doesn't replace them.
Can we drive it entirely from our own tooling?
Close to it: the MCP server covers the workflow end to end — start scans, read findings and changes, triage, generate reports — and webhooks push changes outward. A human-facing console is still there for the parts you want eyes on.
Stand up external monitoring this afternoon.
Verify a domain, wire the webhook, and the change feed starts filling itself.
Start your 7-day trialNo card required to start. Cancel any time.