Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Monitoring · External attack surface

We regularly map what your business looks like from the internet: domains, subdomains, open ports, certificates and forgotten test environments. When something new appears or something changes, you are told.

  • Asset inventory
  • Exposure changes
  • Alert rules
  • Monthly report
01 / What this service includes

See what an attacker sees.

01

Asset discovery

Starting from the domains we verify as yours, we list subdomains, IPs and the services running on them. Old systems nobody remembers usually surface here.

02

Change tracking

Each scan is compared with the previous one. A newly opened port, a certificate nearing expiry or a subdomain that appeared overnight lands in the diff list.

03

Prioritised alerts

Not every change is an alert. Truly risky findings such as an admin screen, a database port or an open directory listing are surfaced first; the rest is gathered in the monthly report.

02 / How it works

Your surface as seen from outside

Behind a single domain sit five kinds of assets that we track regularly.

SubdomainsCertificatesOpen ports and servicesEmail recordsCloud storage buckets
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Asset inventory
  • 02Exposure changes
  • 03Alert rules
  • 04Monthly report
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Setup

    We set up tools, access and settings, document the setup and hand it over to you.

  3. 03

    Monitoring

    We watch the agreed indicators regularly and notify you when something deviates.

  4. 04

    Reporting

    We share what was done, the result and the next step in a plain report.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Regular scans of domains, subdomains, open ports and certificates.
  • An alert when something new appears or something changes.
  • A monthly report.

Not included

  • Logging in to your systems: only publicly visible information is used.
  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A list of domains and IP ranges that you confirm in writing are yours.
  • Who should receive the alerts.

What sets the price

  • Number of web assets monitored.

Payment and aftercare

  • A monthly subscription.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
Does this monitoring need access to my systems?

No. The work uses information anyone can see from outside, and nobody logs into your systems. Only the domains and IP ranges you confirm in writing as yours are included in the scope.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.