See your security the way an attacker does.
LuminaProtect maps your external attack surface — everything your company and your vendors expose to the internet — then turns it into one clear, evidence-backed security score with a prioritized list of what to fix.
- Passive & outside-in
- No agents, nothing to install
- Evidence, not opinions
CISO-grade coverage for a fraction of the $20K+/yr enterprise tools charge — built for the companies that don't have a CISO.
Founders, SMBs & vCISOs are joining our first design-partner cohort — built by security engineers, not marketers.
Security score
+12 since last fix
Versioned & auditable. Only confidence-gated findings move the grade.
- Vulnerabilities74
- Attack surface88
- Email identity96
- Trust & reputation91
- Supply chain69
Top fix · Upgrade Apache Http Server 2.4.49 (CVE-2021-41773)
Confirmed · Critical Severity · Actively Exploited
Every finding backed by a real captured observation.
A unified platform that delivers a continuously updated, auditable, CISO-grade view of your security.
- Passive scanning engines
- 8Passive scanning engines
- Risk pillars, one score
- 5Risk pillars, one score
- Critical external risk areas
- 9Critical external risk areas
- Agents to install
- 0Agents to install
Most companies carry security without a security department
SMBs, solo founders, and the vCISOs who protect them are stuck between tools that are too expensive, too noisy, or impossible to explain.
Enterprise tools, enterprise prices
Real external monitoring has meant $20K+/year and a security team to run it — out of reach for the businesses that need it most.
Scanners that drown you in noise
Tools that blindly flood your network return thousands of “maybe” findings. Nobody has time to triage a wall of false positives.
A grade you can't defend
Black-box security ratings give you a letter with no proof. You can't show a customer, auditor, or insurer why it says what it says.
And the pressure keeps rising
- 31%
- of breaches now start with a software vulnerability — the top way attackers break inVerizon 2026 DBIR
- 4.8M
- unfilled cybersecurity roles worldwide — most SMBs have no one watching their perimeterISC2 Workforce Study
- 24/7
- your internet-facing surface keeps changing — point-in-time checks go stale the moment they finishWhy continuous, outside-in monitoring matters
A precise pipeline — broader coverage, without the flood
No blind network flooding, no thousands of raw findings. A proprietary, production-safe engine reads your live surface with a light touch — more coverage and more accurate results, in minutes. Speed comes from correlation, never from skipping checks.
- 01
Map
Discover your footprint like an attacker
Point it at a domain. LuminaProtect passively maps your entire internet-facing surface — your own assets and your vendors' — with no agents and nothing to install.
- 02
Correlate
Confirm real risk, then de-duplicate it
Targeted, version-aware checks confirm what's real. Then we correlate signals across sources — where rule-based scanners fire the same issue 2–3 times, we resolve it into one confirmed finding — and gate on confidence, so only real risk counts.
- 03
Score & fix
One score, ranked plain-English fixes
You get a single versioned score plus a prioritized to-do list — each item backed by captured evidence. Re-run any time and watch a fix turn the score green.
Every finding ships with its evidence
- 1Surface & exposure mapComplete
- 2Version confirmationHigh confidence
- 3Prioritized risk driversRanked
- 4Report-ready proofAuditable
Five risk pillars. Eight engines. One score.
Eight specialized engines work together to deliver broad, continuous visibility across the critical areas of external cyber risk — then roll up into a single grade.
Vulnerabilities
CVE / KEV / EPSS scoring, end-of-life detection, and risky software versions you actually run.
Example finding · Known-exploited component, confirmed by the version you're running.
Attack surface
Exposed ports and services, forgotten admin panels, DNS hygiene, and TLS / certificate health.
Example finding · A risky admin service is exposed on a public endpoint.
Email identity
SPF, DKIM, DMARC, MTA-STS, DANE, and MX TLS — your resistance to spoofing and impersonation.
Example finding · Your domain can be spoofed — DMARC enforcement is missing.
Trust & reputation
Threat-intel feeds, breach history, and abuse signals tied to your domains and infrastructure.
Example finding · Your domain surfaced on an abuse / breach feed.
Supply chain
Vulnerable client-side libraries and third-party scripts running on the pages your users trust.
Example finding · A vulnerable third-party script is loading on your site.
Your assets + your vendors
Scan and secure both your own internet-facing assets and the third-party vendors you depend on — first-party and supply-chain risk, scored side by side in one place.
Broader coverage, near-zero noise, real-time insight
A proprietary correlation engine turns broad, low-noise signal into one defensible score — more coverage and more accuracy than rule-based scanners, with far fewer false positives, and never at the cost of hammering your systems.
Correlation nobody else does
Rule-based scanners flag the same issue two or three times. We correlate signals across engines into one confirmed, de-duplicated finding — and gate on confidence, so only high-confidence results move your grade and false positives get cut.
Broad coverage, without the flood
8 specialized engines deliver continuous visibility across 9 critical areas of external risk — through a proprietary active-passive engine that runs a handful of targeted live checks. Higher accuracy, production-safe, results in minutes.
Evidence, not opinions
Every finding ties to a real captured observation — a versioned, auditable score with plain-English drivers you can defend to customers, auditors, and insurers.
Always reflects today
Every scan reads the live surface and reflects today. Re-run any time and watch a fix turn the score green.
Your assets + your vendors
One workspace that grows with you: your own surface → your vendors → code, cloud, and graph. Land and expand.
CISO-grade at SMB economics
CISO-grade security intelligence at SMB-friendly pricing — not the $20K+/year enterprise cost.
Point tools show you problems. We show you priorities.
Most external-security tools hand you data and leave the hard part — deciding what's real and what to do — to you. LuminaProtect closes that gap.
Point scanners
Long lists of raw technical issues
The gap · Results fragment across tools and need an expert to triage.
With LuminaProtect · Correlated into a short, evidence-backed list of what actually matters — de-duplicated and confidence-gated.
Security ratings
A board-level letter grade
The gap · The number is opaque — hard to defend, harder to improve.
With LuminaProtect · A versioned score with plain-English drivers and the captured evidence behind every point.
Questionnaires
A point-in-time compliance answer
The gap · They go stale fast and rely on manual, unverified proof.
With LuminaProtect · Fresh outside-in evidence standing behind every answer — re-run any time to prove it's still true.
Broad coverage, correlated into one defensible scoreyou know what to fix first, and can prove it.
See what an attacker sees — before they do.
Claim a free outside-in posture review while founding-cohort spots last.
Two kinds of teams. Equal footing.
Whether you run security in-house or manage it for a portfolio of clients, LuminaProtect is built around how you actually work.
SMBs & solo founders
Carry real, enterprise-grade security without hiring a team. See exactly what you expose, what it means, and what to fix first — then prove your posture to customers and insurers.
- No security team or CISO required
- Fix-first, plain-English priorities
- Near-zero noise — only confirmed risk
- A defensible score to share with buyers & insurers
vCISOs & MSSPs
Multi-tenant and white-label from day one — designed for advisors who protect a portfolio. No more juggling a separate login per client, and every report ships under your own brand.
- Multi-tenant: manage every client from one login
- White-label, fully brandable PDF reports
- Portfolio-wide visibility & prioritization
- Land-and-expand across your whole book of clients
One platform that grows with you
Start with your own assets, add your vendors, then expand into code, cloud, and graph — same workspace, land and expand.
Answers before you ask
The essentials on how LuminaProtect works, what it touches, and who it's built for.
Do I need to install anything?
No. LuminaProtect is fully passive and outside-in — there are no agents, no code changes, and nothing to install. You point it at a domain and it maps your internet-facing footprint the way an attacker would.
Is it safe to run against production?
Yes. Instead of blindly flooding your network, our active-passive engine performs a handful of targeted, version-aware checks. It's production-safe, higher-accuracy, and returns results in minutes.
Do you need permission to scan my organization?
For your own domains, there's no special setup or authorization to arrange — LuminaProtect only observes what's already publicly visible on the internet, the same surface an attacker or search engine can see. It never logs in, touches internal systems, or runs intrusive tests. Vendors are assessed from those same publicly observable signals, so you can measure third-party risk without access to their environment.
What data do you collect and store?
Only publicly observable, internet-facing signals — no credentials, no internal access, and nothing installed on your systems. We securely retain the evidence behind each finding so your score stays auditable and defensible, and so you can see how your posture changes over time.
How is the security score calculated?
From five risk pillars scored by eight specialized engines. The methodology is versioned and auditable, every finding is backed by captured evidence, and only high-confidence results move the grade — so the score is one you can defend to customers, auditors, and insurers.
How is it different from a security rating?
Ratings hand you an opaque letter grade you can't dig into or easily improve. LuminaProtect gives you a versioned score with plain-English drivers and the captured evidence behind every point — correlated and de-duplicated, so you see priorities instead of a black-box number.
Can I monitor my third-party vendors too?
Yes. LuminaProtect scores both your own internet-facing assets and your vendors, so first-party and supply-chain risk live in one place. You start with your own surface and expand to vendors, code, and cloud as you grow.
Is it white-label for advisors?
Yes. LuminaProtect is multi-tenant and white-label ready, built for vCISOs and small MSSPs who protect a portfolio of clients under their own brand.
Does it replace a CISO?
No — it makes existing security effort go further. LuminaProtect gives teams without a dedicated security function (and the vCISOs who serve them) the attacker's-eye visibility and prioritized, evidence-backed actions a CISO would push for. It informs decisions; it doesn't replace judgment.
What stage is the product at?
Pre-launch and MVP-complete — a working, multi-tenant, heavily tested platform. We're now opening early access to a small group of design partners.
What does it cost, and how do I get started?
We're in pre-launch and opening early access to a small founding cohort of design partners, who help shape the roadmap and get hands-on pricing as we finalize plans. To start, request a free outside-in posture review — we'll map your public surface and walk you through what we find, with nothing to install.
Get a fresh, attacker's-eye view of your security.
We're hand-selecting 50 design partners — SMBs, founders, vCISOs, and MSSPs — to evaluate LuminaProtect before public launch, and to help shape it.
- A free outside-in posture review of your own domain
- Early access to the platform and a direct line to the founding team
- A real say in scoring, reports, findings, and onboarding
Spots are limited. Founders, SMBs & vCISOs are already claiming their cohort seats.