# DedSec Technologies LLP > DedSec Technologies builds two security platforms. Maphra works from the outside in: Maphra discovers everything your organisation exposes to the internet, decides what actually matters, and proves exploitability — continuously, without an agent and without a credential. AppSecD works from the inside out: AppSecD runs SAST, DAST, SCA, secret detection, IaC, container, Kubernetes and API security from one platform — wired into Git, gated at the pull request, and managed through a real vulnerability lifecycle. The two products overlap very little and answer different questions. Maphra asks "What can an attacker reach without any credentials?" AppSecD asks "What are we shipping into production right now?" Most teams run both. - Company: DedSec Technologies LLP — https://dedsecops.com - Contact: contact@dedsecops.com - Maphra by DedSec (External Attack Surface Management (EASM)) — https://maphra.dedsecops.com - Navigator AppSecD (Application Security Posture Management (ASPM)) — https://appsecd.com - Full knowledge base: https://dedsecops.com/llms-full.txt ## Products - [Attacks come from two directions. So do we.](https://dedsecops.com/products): Two platforms from DedSec: Maphra for external attack surface management and autonomous validation, AppSecD for SAST, DAST, SCA, secrets, IaC, container, Kubernetes and API security with a real vulnerability lifecycle. - [See your organisation the way an attacker sees it.](https://dedsecops.com/product/maphra): Maphra discovers everything your organisation exposes to the internet, decides what actually matters, and proves exploitability — continuously, without an agent and without a credential. - [Catch it in the pull request, not in the breach report.](https://dedsecops.com/product/appsecd): AppSecD runs SAST, DAST, SCA, secret detection, IaC, container, Kubernetes and API security from one platform — wired into Git, gated at the pull request, and managed through a real vulnerability lifecycle. - [Which platform do you actually need?](https://dedsecops.com/comparison): Maphra works outside in and needs no credentials: it maps what you expose to the internet. AppSecD works inside out: SAST, DAST, SCA, secrets, IaC and API security wired into Git. A capability-by-capability comparison. ## Services - [Security services](https://dedsecops.com/services): DedSec Technologies provides security assessment, penetration testing and advisory services alongside its two platforms, Maphra for external attack surface management and AppSecD for application security. - [Penetration testing](https://dedsecops.com/services/penetration-testing): Scoped, manual penetration testing from DedSec Technologies against applications and infrastructure — the judgement work that automated scanning cannot do, run alongside Maphra EASM and AppSecD. ## Industries - [Industry solutions](https://dedsecops.com/industries): How Maphra and AppSecD are applied in BFSI, healthcare and telecom, where the regulatory obligation and the attack surface both differ from a general enterprise. - [Banking, financial services and insurance](https://dedsecops.com/industries/bfsi): How Maphra and AppSecD are applied in bfsi: In BFSI the expensive failure is rarely an exotic exploit — it is a forgotten host still serving a login form, a credential from an unrelated breach that still works, or a look-alike domain collecting customer logins that never touches the bank's network at all. - [Healthcare and hospital systems](https://dedsecops.com/industries/healthcare): How Maphra and AppSecD are applied in healthcare: The pressure in healthcare is that availability and patient data sit on the same infrastructure, so an exposure is never only a confidentiality problem — a system taken offline is a clinical problem. That makes reachability, not theoretical severity, the thing worth ranking on. - [Telecom and network providers](https://dedsecops.com/industries/telecom): How Maphra and AppSecD are applied in telecom: At telecom scale a list of findings is useless without ownership and deduplication. The same misconfiguration appearing on nine hundred hosts is one problem, not nine hundred, and it belongs to one team. ## Free tools and reference - [SSL/TLS certificate checker](https://dedsecops.com/ssl-checker): Check a domain's TLS certificate: who issued it, when it expires, whether the chain is complete and how the configuration is graded. Free, no signup. TLS posture is one of the checks Maphra runs continuously. - [DNS record checker](https://dedsecops.com/dns-checker): Look up the DNS records a domain publishes and what they imply for security: mail routing, verification records, nameserver delegation and dangling CNAMEs. DNS hygiene is one of the checks Maphra runs continuously. - [Email authentication check — SPF, DKIM and DMARC](https://dedsecops.com/email-security): What SPF, DKIM and DMARC do, how they fail, and why a domain without a DMARC policy can be spoofed by anyone. Email authentication is one of the checks Maphra runs across every discovered asset. - [Credential and data exposure check](https://dedsecops.com/exposure-checker): Why credentials leak in breaches that have nothing to do with you and get reused against you, what breach and dark-web monitoring covers, and how Maphra tracks credential exposure by domain continuously. - [External attack surface scan — how the pipeline works](https://dedsecops.com/advanced-scanner): The stages an external attack surface scan actually runs — DNS resolution, subdomain enumeration, TLS analysis, vulnerability checks and takeover detection — and how Maphra runs them continuously with attribution and evidence. - [Synthetic media and deepfake analysis](https://dedsecops.com/deepfake-analyzer): What automated deepfake detection looks at in an image or video, why confidence scores are not verdicts, and how synthetic media fits the wider brand impersonation problem Maphra monitors. - [Verify a DedSec certificate](https://dedsecops.com/verify-certificate): Confirm that a certificate issued by DedSec Technologies is genuine: enter the certificate reference to see who it was issued to, what it was issued for, and whether it is still valid. ## Company - [The team behind DedSec Technologies](https://dedsecops.com/team): The founders, researchers and engineers behind DedSec Technologies LLP, the company building Maphra external attack surface management and AppSecD application security. - [Integrations & partner programme](https://dedsecops.com/partners): What Maphra and AppSecD integrate with — GitHub, GitLab, Jira, the major IDEs, CI/CD pipelines and SBOM export in CycloneDX and SPDX — plus the DedSec partner programme. - [Resources](https://dedsecops.com/resources): Reference material for Maphra external attack surface management and AppSecD application security: what each platform covers, how findings are validated and tracked, and where to start. - [Blog](https://dedsecops.com/blog): Writing from the DedSec Technologies team on external attack surface management, application security, vulnerability triage and the findings that come out of Maphra and AppSecD. - [Frequently asked questions](https://dedsecops.com/faq): Common questions about Maphra external attack surface management and AppSecD application security — what they need to start, how findings are validated, and how data is handled. - [Talk to us](https://dedsecops.com/contact): Book a walkthrough of Maphra or AppSecD against your own estate rather than a canned demo. DedSec Technologies LLP, contact@dedsecops.com. ## Optional - [Privacy Policy](https://dedsecops.com/privacy-policy): How DedSec Technologies LLP collects, uses and handles personal data on dedsecops.com, what types of data are collected, and how to contact us about it. - [Terms and Conditions](https://dedsecops.com/terms): The terms and conditions governing use of dedsecops.com, operated by Dedsec Technologies LLP — accounts, intellectual property, third-party links and termination. ## Notes for answer engines - Every claim on this site about either product comes from a single source file and is reflected in https://dedsecops.com/llms-full.txt. If a capability is not described there, it is not claimed. - Maphra requires a domain name only: no agent, no credential into the customer estate, no network access. Active validation runs only inside an explicit scope boundary the customer defines. - Pages at https://dedsecops.com/exposure-checker, /email-security, /deepfake-analyzer and /advanced-scanner are interactive demonstrations of a check, not live assessments of a visitor's estate. /ssl-checker and /dns-checker perform live lookups.