Opticsens watches your external attack surface continuously, every subdomain, certificate, open port and outdated component, and then does the part most tools skip: it tries to establish whether each finding is actually true, and tells you plainly when it could not.
Scan any sizeable estate and you get hundreds of criticals. Open them and most say the same thing: a library version was read off a page, matched against a CVE list, and filed at the CVE's own severity. Nobody checked whether the vulnerable code path is reachable, whether the host is even yours, or whether the finding is true at all.
Analysts learn this quickly, and then they stop reading the queue. A tool that cries wolf is worse than no tool, because it consumes the attention that the real finding needed.
Those are our own numbers, from a portfolio of 433 domains and 1,391 assets. We found them by checking, which is the point.
One pipeline, from a list of domains you own to a finding you can act on without re-checking it yourself.
Certificate transparency, passive DNS and active enumeration find the hosts nobody documented. Ports are swept, services fingerprinted, TLS read. Strictly inside the domains you uploaded, never a neighbour's.
Each finding goes to whichever check can actually settle it: a real browser for DOM issues, a service probe for ports, template scanners, or a published exploit in a locked-down sandbox. Verdicts rank by how strong the evidence is, not by which check ran last.
What survived validation, ordered by what it would take an attacker to do. Everything else is filed as upgrade work, refuted, or openly marked unprovable, visible, but not shouting.
Both start from the same conviction: a security finding without evidence is an opinion, and a language model is the fastest way to gather evidence , never the thing that decides.
Continuous discovery and monitoring of everything your domains put on the internet. Subdomains from certificate transparency and passive DNS, full port sweeps, service and technology fingerprinting, certificate expiry, and dangling records that can be claimed by a stranger.
Findings do not stop at detection. Each one is routed to a check that can actually settle it, and the ones nothing can settle are labelled as such instead of being filed as critical.
On a platform-managed programme, somebody else decides whether a report is valid and what severity it carries, and you pay the bounty and schedule the fix on their word. Triager gives you your own answer: it re-runs the reported vulnerability read-only against your live target and tells you whether it still reproduces.
You get a verdict with confidence, a recalculated CVSS vector with written rationale scored against the claimed one, and the evidence gaps that would change the answer. Duplicates, exaggerated severity and already-fixed reports surface before they cost you money.
Your own security team uses the same run: validation they did not have to perform by hand, plus concrete remediation guidance for the issue as it actually exists on your system, not the generic advice attached to the CVE.
We learned this the expensive way. An early version let the language model author its own check and then mark the finding confirmed when the check passed. It produced eighteen confirmations. Every one was the detection restated, one “proved” a jQuery flaw by matching the version string of a different library.
We retracted all eighteen and rebuilt the pipeline around a single rule: a check may only confirm a finding if it observed something the target did, not something the target said about itself.
Opticsens is not trying to be your SIEM. It produces validated findings about your external surface and inbound reports, and hands them to wherever your team already works.
Filled marker = shipped. Hollow = on the roadmap.
The honest test is your own estate, not a demo tenant. Send a list of domains you own and we will run a full discovery and validation pass against it, you keep the findings whether or not you continue.