For security teams

Attack surface management without the enterprise contract.

The enterprise EASM suites do continuous discovery well — for six figures and a sales cycle. Bastion does the part that matters for a lean security team: CT-log subdomain discovery, lookalike-domain watching, a change feed with evidence inline, and an MCP server so your agents and tooling can drive it. Self-serve, from $25/month.

No card required to start. Plans from $25/month; first scan in about a minute.

Built around how security teams actually work

Discovery you didn't have to seed

Subdomain enumeration from certificate transparency logs, continuously — including dangling CNAMEs pointing at claimable services. The inventory grows as the estate does, not when someone updates a list.

A change feed, not a snapshot

Every scan diffs against the last: hardened SPF, new subdomain, a port that started answering, a header that vanished. The evidence is inline, so triage doesn't start with re-running the check.

Triage that sticks

Findings carry severity and evidence; accepted risk gets a review date, noise gets muted. What's left is a digest short enough that people keep reading it — which is the actual failure mode of most scanners.

Lookalike domains watched passively

Typosquats and homoglyph registrations — the raw material for phishing and invoice fraud — tracked with public DNS and CT data only.

Automation-first by design

The whole product as MCP tools

A hosted MCP server (OAuth 2.1, no API keys) exposes scans, findings, the change feed, triage and reports to Claude, ChatGPT, Codex or anything else that speaks MCP. Setup guide →

Webhooks into your pipeline

Critical changes can hit a webhook the moment they're found — into your SOAR, your ticketing, or a queue you own.

Hand-off prompts for remediation

Any scan exports as a severity-ordered prompt for a coding agent, with evidence and a verification command per finding — and an honest flagged list for fixes that live at the registrar or in a console instead of a repo.

Scope you can defend

Scanning runs only against domains ownership-verified via DNS TXT. Deliberately: the platform cannot be pointed at infrastructure you don't control.

Common questions

How does Bastion compare to enterprise EASM platforms?

The discovery core is the same idea — continuous external enumeration and change detection. What Bastion doesn't have: seat-based enterprise pricing, deployment projects, or a sales cycle. What the big suites don't have: self-serve setup in minutes and a price a team can expense. Comparisons with specific tools are in the articles.

Is the check depth enough for a security team?

The modules cover TLS and chain validity, HTTP security headers, DNS and email authentication (SPF/DMARC/CAA), CT-log subdomain discovery, service fingerprinting and a TCP connect sweep of common ports. It's passive by design — it complements your pentest and internal scanning; it doesn't replace them.

Can we drive it entirely from our own tooling?

Close to it: the MCP server covers the workflow end to end — start scans, read findings and changes, triage, generate reports — and webhooks push changes outward. A human-facing console is still there for the parts you want eyes on.

Stand up external monitoring this afternoon.

Verify a domain, wire the webhook, and the change feed starts filling itself.

Start your 7-day trial

No card required to start. Cancel any time.