Topscan.me – a new security platform with a new approach to scanning

Topscan.me – a new security platform with a new approach to scanning

Topscan.me is a security scanning platform for companies where security is somebody's second job, usually a CTO or a DevOps lead. It covers what is normally bought from three vendors: code analysis, scanning of running web applications and monitoring of the external perimeter, all in one workspace with a deadline on every finding. What distinguishes it is a handful of decisions about how scanning should behave, described below.

What it covers

- Code. GitHub or GitLab repositories, self-managed included, connected with a read-only token: risky patterns, exposed secrets, vulnerable dependencies. The clone is deleted when the scan ends; only the finding and a snippet of the affected lines remain.

- Running web applications. External scanning, with an optional deep mode that crawls the app and runs active OWASP Top 10 tests.

- The perimeter. Open ports, service versions, known vulnerabilities, certificates, and any host that appears where none was before, rescanned on a schedule.

- AWS. Discovery of EC2 and Route 53 resources through keys the customer issues. Nothing is installed on the customer's servers.

Discovery first, scanning only with consent

Adding a domain triggers discovery: Certificate Transparency logs, DNS, and one ordinary HTTP request per host, the same request a browser sends. No ports are touched. Within five to ten minutes the result is a map of what faces the internet.

Nothing else runs until the user confirms a target. Port scans and active checks are limited to confirmed hosts, and confirming a target is how the user asserts authorisation to scan it. The documentation is direct about why: in some jurisdictions an unauthorised port scan is a criminal matter. Hosts discovered and then dismissed are never scanned and use no licence.

One finding per vulnerability, status per host

The same vulnerability on five hosts is one entry in the issue list, so the list stays as long as the problem is. Status, though, is kept per host and port. Mark a finding as a false positive on one host and the other four keep their deadline. When status is stored on the vulnerability itself, as a lot of tools do, one click can quietly hide a real problem on forty other machines. Topscan keys status to target, issue type, port and protocol, and a triage mode expands any grouped entry into its individual occurrences.

A score built on deadlines, not counts

Every finding gets a deadline from the day it was first detected: 7 days for critical, 30 for high, 60 for medium, 90 for low. The Security Score starts at 100 and loses points only when a finding passes its deadline. A workspace that scans more and finds more does not score worse for having looked. Snoozing pauses the clock and resumes it where it stopped. A deferred fix stays visible. A separate, cumulative SLA compliance rate covers the whole history of the workspace for auditors.

Evidence on every finding

Each finding carries what produced it: hostname, status code, response banner or certificate date, and the time of the check, so it can be verified in seconds without trusting the label. The engines are open source and named: naabu for ports, OpenVAS for infrastructure vulnerabilities, Nuclei for web checks, OWASP ZAP for the deep stage. The engine is not the product; the inventory, the deadlines, the evidence and the history are.

Pricing without a sales call

- Two plans, $129 and $269 a month; 14-day trial of the full plan, no card.

- Per target: $4 an infrastructure host, $45 a web application, $9 a repository, the same add-on rate on every plan.

- Users unlimited, scans never billed, read-only seats for auditors free.

- AWS discovery and Slack and Jira routing are on the higher plan.

Getting started

Discovery produces the first perimeter map within five to ten minutes of starting the trial, before anything is scanned.

Discussion 0 comments · 1 points · darius88 · 2h
Open on HN
Loading the discussion…

Domain filters

Stories from these domains are hidden from every list. Subdomains match too: blocking substack.com also hides danluu.substack.com.

    New collection

    Delete this collection?

    About YAVCHN

    YAVCHN is a reader for Hacker News and Lobsters, with articles and discussions in separate windows or Classic pages.

    Created by Paul Parks and built with PUDL.

    YAVCHN source code on GitHub

    Privacy policy · Terms of use

    Help

    Keyboard

    j / k
    Move down and up the story list. The arrow keys scroll whatever has focus.
    Enter
    Read the marked story in the article reader.
    ]
    Read the next story in the same article-reader applet. Back returns to the previous story.
    p
    Pin or unpin the marked story, which keeps it in Pinned.
    n / N
    Move to the next or previous top-level comment in the window in front.
    c
    Collapse or expand that comment.
    f
    Hide or show the story list.
    Esc
    Close a menu or this help.
    Access key m
    Go to the menu bar. Most browsers take it with Alt on Windows and Linux, and Safari with Control and Option.
    ?
    Show this help.

    Windows

    Each story opens in a window holding its article above its discussion; drag the bar between them to share the room differently. A window can be moved by its title bar, resized from any edge, snapped to a half or a corner by dragging it there, maximised, or minimised to the bar at the foot of the page. Use Window > New reader window to open an empty reader, or Story > Open in new reader window to open another reader for the current article. Docked readers keep their articles when you select another story from the sidebar. Minimized readers can be restored and reused for their site. A window's Next story link reads on down the list in the same window.

    A link in a comment or an article to another Hacker News or Lobsters thread opens that thread in a window too. A link to a single HN comment opens the comment above its replies.

    While a story's window is in front, the Story and Discussion menus in the menu bar hold its commands: pinning, Next story, sorting, collapsing every thread, jumping to the first new comment. Each window also remembers where you were in its article and discussion, so a reload, or Back to a story that Next took you past, finds your place again. Closing a window forgets it.

    The whole arrangement lives in the address, so a bookmark or a shared link brings it back, and Back undoes the last change. Moving between Hacker News, Lobsters, their lists, Pinned and Find changes only the list, and leaves the windows open.

    The list

    The pin at the start of a row keeps the story in Pinned, and the cross at its end hides it. Pinned can be narrowed by words in the title, site or author, by source, and to the stories you haven't opened yet, and ordered by when you pinned them, by points or by comments; the filters are part of the address, so a filtered view can be bookmarked. Scroll past the end of the list to load more. Domain filters, in the View menu, hide every story from a site.

    Collections are named lists of stories. Story > Add to collection files the story in front into one or more of them, and the Collections feed shows them all or one at a time; the menu that chooses collections also creates, renames, and deletes them. A note is your own text on a story. Choose Add note in a story's toolbar to write one; it saves as you type. Rows with a note carry the note mark, and the Notes feed lists every noted story and searches the text of your notes.

    Browsing view

    View > Windowed and View > Classic select the browsing view and save your default in this browser. Window view reuses a reader for each feed. Classic view opens stories and applets as pages. Open as a page is a one-off action that does not change your saved default. Use the Windowed selector to return an article to a window. Direct page links always open as pages.

    Applets

    The Applets menu in the menu bar holds three tools, each a window of its own. Replies to me takes your Hacker News user name and lists the replies to your last thirty comments and stories, checking again every three minutes while it is open, and marking what is new since you last marked them read. Look up a user opens a profile on Hacker News or Lobsters, with their submissions and recent comments, as a commenter's name in any discussion does; the bar at the top of a profile looks up someone else in the same window, and Back returns to the one before. Who is hiring? filters the posts of HN's monthly hiring threads by the words you type.

    They read only what the sites publish to everyone, so none of them asks for a login, and your user name stays in this browser anonymously and is included in retained applet state when signed in.

    Find

    Find takes any link and lists every time it was submitted to Hacker News and Lobsters, so you can read each discussion of it.

    About

    YAVCHN never sees your Hacker News or Lobsters login. The discussion is fetched from each site's public API; to vote or reply, follow the link above the discussion, or the arrow beside a comment, to the source's own site. Without a YAVCHN account, your data stays in this browser. When signed in, pins, collections, notes, blocked domains, and retained reading state are stored with your account and synchronized across devices. Hidden stories and layout stay in this browser. The privacy policy has the details.

    Open source: github.com/paulmooreparks/yavchn. Built with PUDL.