External assurance product

Continuously monitor approved public-facing assets for exposure.

Guardian External Vulnerability Monitoring identifies supported vulnerability and exposure findings across the approved external asset scope and connects them to accountable remediation through Guardian.

Product position

Optional external monitoring product

This product expands beyond the baseline website-vulnerability monitoring included in Guardian Core. It is licensed by approved domains, public IPs, hosts, services or another agreed target model.

01

Customer-safe delivery

Customers work through Guardian rather than being forced into disconnected technical consoles.

02

Governed scope

Entitlements, targets, users, data sources, schedules and service commitments are recorded in the applicable package schedule.

03

Accountable outcomes

Material findings can be linked to risks, owners, due dates, All Actions, evidence and remediation review.

Product capabilities

What the product provides through Guardian.

AS

Approved asset scope

Public IPs, domains, hosts and services are explicitly authorised and mapped to the customer.

EM

Exposure monitoring

Supported external vulnerability and exposure checks run at the agreed cadence.

CF

Customer-safe findings

Technical findings are normalised with severity, status and practical remediation context.

PR

Prioritisation

Material exposure is connected to customer context, risk and urgency.

RV

Remediation verification

Resolution and evidence can be reviewed through subsequent monitoring and approved validation.

RP

Reporting

External posture and remediation progress contribute to Guardian assurance reporting.

Operating model

How the capability is delivered.

Monitoring is limited to approved customer-controlled targets and agreed safe-testing policies.

Guardian provides the findings, risk, action, evidence and reporting workflow while the selected assessment technology performs the approved checks.

Providers can manage authorised customer scopes without relying on fuzzy target attribution.

Commercial and service boundaries

What must be confirmed before activation.

Target quantity, scan policy, cadence, authentication, exclusions, verification and support must be recorded in the package schedule.

External monitoring is not a substitute for manual penetration testing and does not imply exploitation of customer systems.

Unsupported, inaccessible or third-party-controlled targets require separate approval or may be excluded.

Product selection

Map the product to the customer operating model.

We will confirm the package relationship, covered scope, licensing unit, service level, reporting and any separately scoped engineering or professional services.

Guardian External Vulnerability Monitoring | Damocles Security