Phylax looks at a company from the outside, the way an attacker would, and shows in one place where it is exposed. This panel brings together the exposure score, the email and DNS traffic lights, the attack surface map and the Watcher feed. What you see here is the product vision, not a finished version.
In progress · product conceptPhylax already has two real tools that work today, a live checker that reviews a domain's exposure on the spot, and the domain Watcher service that monitors it continuously. This panel is the product version of those two pieces, a single dashboard where reconnaissance work turns into a number, a set of traffic lights and a timeline. All reconnaissance is passive and pre-authorized, without touching or stressing the client's systems. The mockups below use the fictional domain cliente-ejemplo.cl, the data is illustrative.
A single number between 0 and 100 that sums up how exposed the organization is, with a verdict in plain words so a non-technical reader can follow it. The score drops when there are open doors and rises when they close. It helps decide where to focus first.
The baseline is reasonable, but there are still gaps an attacker can use with little effort. Closing the three email ones lifts the score close to 85. None of them requires buying anything, just adjusting configuration.
Sample score and verdict, calculated on a fictional domain to show the panel's format.
Every email and domain control with its light in green, amber or red. This is where the risk almost nobody looks at lives, the misconfigured email that lets anyone impersonate the company and the headers that are missing. One glance is enough to know what is fine and what needs fixing.
Sample states on cliente-ejemplo.cl. The technical records are illustrative, to explain what each traffic light checks.
The list of subdomains a company exposes without always knowing it, rebuilt from the public Certificate Transparency logs, the open archive where every issued certificate leaves a trace. Often you find test environments or internal panels nobody remembers publishing. That is the surface an attacker maps first.
Sample subdomains on a fictional domain. The real source is Certificate Transparency, a public, read-only log.
The Watcher monitors the domain continuously and flags when something changes. A certificate about to expire, a subdomain that appears out of nowhere, an email policy that weakened. Each event lands on a timeline with its severity level, so you can act before it becomes a problem. The one service with a set price, USD 30 per month per domain.
The certificate for tienda.cliente-ejemplo.cl expires in 20 days.
A new subdomain appeared, dev.cliente-ejemplo.cl.
The DMARC policy dropped to p=none.
An admin panel that was open to the public was closed.
Sample alerts to show how the Watcher logs changes over time on a fictional domain.
They have a site, their own email and maybe a store, but nobody checks whether the configuration leaves gaps. The panel gives them a clear snapshot without needing an in-house technical team.
Where a domain impersonation means fraud or deceived customers. The email traffic lights point straight at the risk almost nobody watches until it happens.
Brands, institutions or suppliers that expose several subdomains and need continuous monitoring. The Watcher flags a change before it becomes news.
The Phylax panel is in progress. I want to test it with real companies that want to see their exposure and put it in order. Leave your contact and I will let you know when we open access.
Join the waitlist →