Resources

Reference material for the two platforms, plus the pages that answer the questions people ask before they book anything.

Start here

Free checks you can run now

Reference

Written for people evaluating either platform

Maphra is an autonomous External Attack Surface Management platform. It starts from nothing more than a domain name and works outward the way an attacker would: enumerating subdomains, resolving infrastructure, fingerprinting live services, and attributing each discovered asset back to the organisation that owns it. Discovered surface is then classified, analysed and prioritised, so a security team sees the handful of exposures that are genuinely reachable rather than an undifferentiated asset inventory. Maphra also watches the parts of the attack surface that sit outside the perimeter entirely — leaked credentials in breach corpora, look-alike domains, impersonating applications and brand abuse — because those are attack paths that no internal scanner can see. It runs continuously rather than as a quarterly exercise, and every finding carries the evidence that produced it.

AppSecD is an enterprise application security platform that consolidates the scanning disciplines a security team would otherwise buy separately. Static analysis runs across more than twenty languages through a farm of over fifteen analyzers with Semgrep as the primary engine. Secret detection runs against both the working tree and the full git history, because a credential deleted in the latest commit is still in the repository. Software composition analysis covers the major package ecosystems and adds typosquat, malicious-package and provenance checks on top of conventional CVE matching. Dynamic testing brings a further one hundred and fifty native checks alongside Nuclei, Dalfox, SQLMap and out-of-band interaction testing. Findings are not dumped as raw scanner output: they are deduplicated across scans, tracked through a lifecycle with ageing, SLA, assignment and maker-checker approval, and enriched by an AI layer that triages false positives, proposes fixes and assembles attack chains. It integrates with GitHub and GitLab, gates pull requests by policy, and runs shift-left inside the developer IDE.