What the product does
The commercial unit can be an approved target, host, public IP, domain, service or another agreed asset model.
Guardian External Vulnerability Monitoring tracks approved public IPs, domains, hosts and services for supported vulnerability and exposure changes beyond the Core website allowance.
Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.
Guardian retains target, monitoring status, observation dates, finding identity, severity, evidence, action, exception and later review state. Credentials and raw execution payloads remain restricted.
The proposal identifies target unit, approved assets, profile, cadence, retention, reporting, support, provider relationship and any included validation or managed remediation coordination.
Targets, ownership, policy, cadence, exclusions and safe-testing methods must be approved. Third-party or unsupported targets are excluded unless separately authorised.
The commercial unit can be an approved target, host, public IP, domain, service or another agreed asset model.
The interface avoids raw scanner payloads while retaining enough context for remediation and traceability.
Formal penetration testing remains separate where human-led exploitation or attack-path validation is required.
A penetration test provides deep validation at a point in time. External monitoring provides ongoing awareness when a new host appears, a service changes, a certificate expires, a vulnerability persists or a previously resolved issue returns.
Guardian keeps target authority, customer ownership, findings, actions and later observation state together. The selected compatible assessment component performs the safe checks; Guardian provides the customer and provider workflow.
Know which public IPs, domains, hosts and services are approved and owned by the customer.
Surface new, persistent, returned or changed exposure using the agreed monitoring policy.
Track ownership, evidence and later monitoring state rather than closing a finding from a task update alone.
The commercial unit can be an approved target, host, public IP, domain, service or another agreed asset model.
Record customer-owned public IPs, domains, hosts, services, environment and business context.
Run supported non-destructive external checks at the agreed cadence and profile.
Identify new, returned, materially changed and no-longer-observed exposure where supported.
Present affected target, issue, severity, status, dates, evidence and remediation context.
Create owner-ready work for patching, removal, segmentation, hardening, upgrade or investigation.
Use later monitoring state or approved validation to review whether exposure was removed.
The interface avoids raw scanner payloads while retaining enough context for remediation and traceability.
Approved target, ownership, service context, latest check and current finding state.
New host, port, service, certificate or supported vulnerability condition requiring review.
Material issues that remain observed across checks and require remediation escalation.
Previously resolved or absent exposure that has been observed again.
Remediation, evidence, due date, exception and review state for each material issue.
Authorised customer target inventories, monitoring state and remediation through provider-scoped access.
Formal penetration testing remains separate where human-led exploitation or attack-path validation is required.
Confirm customer ownership, asset scope, contacts, exclusions and safe-testing policy.
Establish the approved external assets and supported current exposure state.
Run the agreed checks, track job health and investigate failed or unavailable monitoring.
Validate customer scope, duplicate targets, finding continuity and customer-readable evidence.
Track owners, due dates, exceptions, evidence and required deeper assessment.
Report approved assets, monitoring health, new and persistent exposure, overdue actions and resolution.
The product expands beyond the website-only allowance included in Guardian Core.
Monitor a defined set of public IPs, domains and remote-access services for a small business.
Track approved public cloud hosts and services that can change faster than annual review cycles.
Watch approved VPN, gateway and remote-management services for material exposure changes.
Manage exact customer-owned target inventories and monitoring without fuzzy attribution.
Maintain exposure awareness and remediation follow-up after a formal assessment.
Identify supported certificate, protocol or exposed-service conditions requiring operational attention.
These details remain explicit before activation, but are grouped into one operating view so buyers can review the responsibilities without working through four separate page sections.
Onboarding establishes target ownership before any monitoring is enabled. The customer provides public IPs, domains, hosts, services, ownership evidence, environment, business context, contacts, exclusions and any third-party restrictions. Damocles confirms which targets are suitable for the approved safe-testing profile. The baseline validates reachability, target identity, duplicate ownership, assessment behaviour, finding quality and customer mapping. Assets without confirmed authority are not silently included. Go-live records target quantity, cadence, assessment policy, finding workflow, support, reporting and the boundary to deeper active assessment, penetration testing and engineering.
The external-monitoring product can use approved assessment components without exposing them as the customer product. The assessment connector must preserve target authority, job status, timestamps, target identity, finding continuity, evidence and safe failure state. Guardian provides customer scope, action, risk, evidence and reporting. The selected component may change as long as target safety, finding identity, history, customer ownership and supportability remain intact. The commercial schedule identifies the implementation where relevant. New connector requests are reviewed for target controls, assessment policy, execution isolation, data quality, evidence, rate limits, supportability and commercial effort.
The monitoring record shows what was checked, what was observed and what happened next. Guardian retains target, monitoring status, observation dates, finding identity, severity, evidence, action, exception and later review state. Credentials and raw execution payloads remain restricted. A failed monitoring job, unreachable target or unsupported check is shown explicitly. Missing assessment data is not represented as a clean external posture. Reports distinguish new, persistent, returned, resolved-pending-review and closed findings where retained records support those states.
Commercial scope follows the approved external-asset quantity, cadence and managed follow-up. The proposal identifies target unit, approved assets, profile, cadence, retention, reporting, support, provider relationship and any included validation or managed remediation coordination. Additional targets, deeper assessment profiles, authentication, penetration testing, retesting and remediation engineering remain separate unless included. The customer owns target authority and remediation decisions. Damocles owns the monitoring and follow-up activities listed in the product schedule.
The exact answer is confirmed in the proposal and package schedule, but these points should be understood before activation.
The proposal defines whether the commercial unit is a public IP, domain, host, service or another approved asset model.
No. Coverage follows the authorised inventory and supported discovery or monitoring methods stated in the service.
Not as part of baseline external monitoring. Deeper active or manual testing requires separate authority and scope.
Yes through explicit provider relationships and exact customer target ownership.
Later monitoring state, approved evidence or a separate validation activity is used according to the finding.
It requires appropriate authority or may be excluded from active monitoring.
We will define the authorised target model, monitoring policy, cadence, connector, remediation workflow and verification approach.