Six months ago I started noticing something that bothered me. Attackers can map a company's entire internet exposure in under an hour using free tools. Subdomains, open ports, expired certificates, misconfigured email security, leaked credentials — all publicly visible. Yet most small businesses have zero visibility into any of this. The tools that solve this problem — Tenable, CrowdStrike Falcon Surface, Cortex Xpanse — cost $25,000 to $100,000 per year. They require dedicated security teams to operate. They're built for enterprises with 10,000 employees, not the 50-person company trying to figure out if their domain is secure. So I built ThreatPort. You enter a domain. It runs a 9-phase automated scan: - Subdomain enumeration across 28 intelligence sources - Port scanning across 134+ critical ports - CVE matching against NVD and CISA's Known Exploited Vulnerabilities catalog - IP reputation via 19 threat intel feeds - Email security: SPF, DMARC, DKIM analysis - Typosquatting detection (~40 lookalike domain variants) - MITRE ATT&CK mapping and IOC generation - Dark web credential monitoring The output is a security score from 0 to 100 with prioritized remediation steps written for IT managers, not security researchers. No agents. No complex setup. $50/month. **What I learned building this:** Getting the technical stack right was the easy part. The hard part was figuring out who actually buys this. My first assumption was IT managers at small companies. That's still true, but the buying trigger isn't "I want better security." It's "something happened" — a phishing attempt, a compliance audit, a client asking for a security report. The free scan on the landing page converts better than anything else I've tried. People run it on their own domain, see their score, and sign up. No sales call needed. The hardest thing right now: getting discovered. The product works. Distribution is the problem. If you're in security, IT, or SaaS — I'd love your feedback. What would make you switch from whatever you're using now? Try the free scan: threatport.com
This is a strong security wedge because the trigger you found is exactly right. Most small businesses do not wake up wanting “attack surface management.” They care when a phishing attempt, client security review, compliance question, or exposed domain risk suddenly makes the problem visible.
The free scan is probably the right front door because it turns an abstract security fear into a concrete score. That is much easier to sell than another dashboard.
The part I would pressure-test early is the brand layer. ThreatPort is clear, but it still feels fairly descriptive for something that could become the default external exposure check for small and mid-sized companies. If the product expands beyond “scan my domain” into ongoing risk monitoring, remediation, client-ready security reports, and compliance visibility, the current name may start carrying less weight than the product deserves.
Before more scans, reports, docs, and customer memory lock in around it, I would seriously consider whether the product needs a sharper security brand shell.
Vroth .com would fit this direction well because it feels hard-edge, technical, and serious enough for external attack surface, threat exposure, remediation, and security monitoring without boxing the product into one narrow feature.