Know your Surface.
Before attackers do.
Attack Surface Management & Vulnerability Scanner (ASM) from Switzerland
RECON is the Swiss attack surface management platform: continuous asset discovery, risk scoring with EPSS and CISA KEV threat intelligence, AI-powered security analyst and full-featured vulnerability scanning, cloud-hosted, MSP-ready, with a gateway architecture for internal networks.
Find vulnerabilities. Before anyone else does.
RECON unites continuous vulnerability scanning, attack surface management and AI-powered analysis in one cloud-based platform.
Vulnerability Scanning
Comprehensive vulnerability detection for hosts, web applications, APIs and DNS. CVEs, web vulnerabilities, misconfigurations, exposed credentials and SSL/TLS weaknesses, all automated.
- checkCVE detection & web vulnerabilities
- checkSSL/TLS analysis & security header check
- checkHeadless browser for JavaScript applications
MSP Multi-Tenant Portal
Manage any number of tenants from one central platform. Aggregated KPIs, tenant-specific dashboards and white-label capabilities for your brand.
- checkFull tenant separation
- checkWhite-label: logo, colors, login branding
- checkJump-in navigation to every tenant
AI Security Analyst
Integrated chat-based AI assistant for vulnerability analysis. Ask questions in natural language and receive context-aware assessments of your findings, including real tool calls on your data (finding search, severity distribution, top-N rankings, trend analysis).
- checkProvider-agnostic (Claude, GPT, OpenWebUI/local)
- checkTool calls: query_findings, count, top-N
- checkTenant-isolated, MSP-wide analysis optional
Gateway Architecture
Lightweight gateway VMs for scans in the internal network. Available as preconfigured images for all common hypervisors. Results are transmitted to the cloud in encrypted form.
- checkKVM/Proxmox, VMware, Hyper-V
- checkHeartbeat monitoring & auto-updates
- checkInternal & external scan zones
Scheduled Scans
Automated scan schedules: daily, weekly, monthly or with custom intervals. Live status tracking via WebSocket and immediate notification on critical findings.
- checkManual, daily, weekly, monthly
- checkScan configuration profiles (70+ parameters)
- checkEmail alerts on critical vulnerabilities
Reporting & Export
Professional PDF reports and CSV exports for compliance reviews and management briefings. Filterable by severity, status, host and time range.
- checkPDF reports & CSV export
- checkSecurity score with trend indicator
- checkComplete audit trail
Brand Protection & Takedown
Automatic detection of phishing domains that imitate your brand name. Structured takedown workflow with evidence package export for abuse reports.
- checkDomain permutation monitoring around the clock
- checkDiff view between scan runs
- checkTakedown workflow with PDF evidence package & SHA-256
Cloud Inventory
Complete inventory of your AWS and Azure resources directly in the platform: VMs, storage buckets, databases, network components, IAM, Kubernetes clusters and more.
- checkAWS: 20+ resource types (EC2, S3, RDS, EKS...)
- checkAzure: 20+ resource types (VMs, AKS, Key Vault...)
- checkGCP integration in preparation
Even stronger combined
Combine RECON with Ironate NDR and UEBA and get a complete security suite, from the attack surface to detection on the network and the endpoint.
Not every vulnerability is equally critical.
RECON combines multiple threat intelligence sources with asset criticality and exposure into a risk score (0–100), so you fix what really matters first.
EPSS: Exploit Prediction Scoring
Daily updates of EPSS scores from First.org. EPSS predicts the probability that a CVE will actually be exploited within the next 30 days: data-driven, not just CVSS-based.
- checkDaily EPSS data feeds
- checkPrioritization by real exploit probability
CISA KEV: Known Exploited Vulnerabilities
Automatic flagging of CVEs listed in the CISA KEV catalog: vulnerabilities that are demonstrably being exploited by attackers in the wild. These findings immediately jump to the top of the prioritization.
- checkKEV flag on every affected finding
- checkAutomatic top prioritization in dashboards
Three dimensions, one number.
The RECON risk score combines technical severity with the criticality of the affected asset and its exposure, for a prioritization that is actually relevant to your business.
CVSS score, EPSS probability, KEV status
Classification per asset: Low / Medium / High / Critical
Public-facing vs. internal, service reachability, DNS visibility
800,000+ scan templates, signed & pinned
RECON uses a hardened scan template engine with 3,000+ curated and proprietary Ironate templates. Templates are delivered through the signed Ironate distribution: no direct sourcing from public repositories, no supply chain risk.
Find phishing domains before your customers come to harm.
Attackers register new domains every day that imitate your brand name, as a basis for phishing campaigns, credential theft and CEO fraud. RECON detects these domains automatically around the clock and guides you through the entire takedown process.
Continuous domain monitoring
Permutations, homoglyphs, TLD variants: RECON monitors all common variants of your brand name and alerts you on new matches.
Diff view between scan runs
See at a glance what has changed on a phishing domain since the last scan: new content, changed DNS records, new certificates.
Structured takedown workflow
Status steps from detection to resolution, automatic evidence package PDF with cryptographic hash, prepared letter for abuse reports.
What RECON checks on phishing domains
Your cloud attack surface. Fully visible.
Shadow IT and forgotten cloud resources are a main entry point for attackers. RECON automatically inventories your entire AWS and Azure environment, without an agent, directly via the cloud APIs.
Amazon Web Services
Microsoft Azure
GCP integration in preparation
19 GCP services (Compute, Cloud Storage, GKE, IAM, Secret Manager, Cloud Armor and more)
SaaS inventory planned
M365, Google Workspace, Salesforce, Okta: users, permissions, configurations, security gaps
External threat exposure. Right in the platform.
RECON aggregates multiple external threat intelligence and OSINT sources and automatically shows whether your assets, domains or credentials appear in data leaks, internet scans, code repositories or paste services.
Internet Scan Correlation
Automatic matching of your IPs against internet scan data: exposed services and open ports from an attacker's perspective.
Data Leak Matching
Checks all tenant domains against known data leaks. Affected email domains are reported automatically.
Subdomain Enumeration & CT Logs
Continuous subdomain discovery via Certificate Transparency logs, passive DNS analysis and active permutation discovery.
Code Repository Leak Scan
Searches for accidentally pushed secrets, API keys and credentials related to your domains and IP ranges.
Paste Leak Monitoring
Monitoring of paste services for leaks concerning your organization, with role-appropriate visibility (MSP admin only).
External Host Discovery
Extension of the external attack surface via additional internet scan data: host recon and certificate histories as a further vantage point.
Show how an attacker reaches your most critical systems.
Most vulnerability scanners list vulnerabilities, but which of them does an attacker combine to advance from an exposed server to your crown jewel assets? Attack Path Analysis answers exactly that question.
RECON models your entire asset graph: connections between exposed services, vulnerabilities, container images and cloud resources. The result: prioritized attack paths with an overall risk score, displayed as an interactive hop chain from the internet to the crown jewel.
How Attack Path Analysis works
Internet-exposed service
A publicly reachable port with a known vulnerability
Lateral movement possible
The compromised host has connections to internal network segments
Privileged cloud resource reachable
An IAM role or Key Vault with excessive permissions
Crown jewel at risk
Production database, patient records or financial system within reach
RECON calculates all possible paths and prioritizes them by overall risk, so your team knows what needs to be patched first.
The compliance status of your cloud. Calculated automatically.
Instead of manual checklists, RECON automatically checks your cloud configuration against the most important compliance frameworks: daily, with score, drill-down and exportable report.
Cloud Benchmarks
Automatic checks of your cloud configuration against industry-standard CIS benchmarks:
- checkCIS AWS, ~50 controls (EC2, S3, IAM, security groups, EBS)
- checkCIS Azure, ~40 controls (VMs, storage, SQL, Key Vault, NSG)
- checkCIS GCP, ~35 controls (Compute, Cloud Storage, IAM, VPC)
- checkCIS Kubernetes, K8s misconfigurations from container scans
Regulatory Frameworks
Crosswalk mapping of the CIS controls to regulatory standards:
- checkNIST CSF v2.0, mapped to CIS rules
- checkPCI DSS v4.0, mapped to CIS rules
- checkISO 27001:2022, 93 controls + custom rules
- checkrevDSG CH-2023, Art. 7, 8, 22, 25 cloud controls
- checkGDPR Art. 32, security of processing
0–100
Score per framework with drilldown
Daily
Automatic recalculation
Export for audits & management
Exceptions
Per-control exceptions with expiry date
Who has access to what? In your SaaS world, too.
Forgotten admin accounts, missing MFA, excessive OAuth permissions: RECON inventories your SaaS landscape and makes security gaps in identities and configurations visible.
Microsoft 365
Users (incl. MFA status), groups, devices (Intune), app registrations, conditional access policies, mailbox settings, directory roles, Defender alerts.
Google Workspace
Users, groups, mobile devices, OAuth apps and their permissions, role assignments, Alert Center notifications.
Salesforce
User accounts, profiles, connected apps and their OAuth permissions, permission sets: making security gaps in CRM access visible.
Okta
Users, groups, connected apps and policies: checking identity provider configurations for security gaps.
What Black Kite, Tenable and Qualys cannot do.
Most competitors are either built for single companies (no MSP), work with OSINT only instead of authorized scans, or force US cloud dependency.
| Feature | RECON | Black Kite | Tenable | Qualys |
|---|---|---|---|---|
| MSP-native multi-tenant model | check_circle | cancel | help | help |
| Authorized internal scans (not OSINT-only) | check_circle | cancel | check_circle | check_circle |
| Brand protection & takedown workflow | check_circle | help | cancel | cancel |
| Cloud inventory (AWS + Azure native) | check_circle | cancel | check_circle | check_circle |
| AI security analyst (provider-agnostic) | check_circle | help | help | help |
| White-label for MSPs | check_circle | cancel | cancel | cancel |
| CH/EU data residency (no US CLOUD Act) | check_circle | cancel | cancel | cancel |
| GDPR Art. 17 & 20 built in natively | check_circle | help | help | help |
| Pricing model | CHF 0.50–3.00 per asset/mo. | USD 5-figure/year (minimum commit) | USD 5-figure/year (minimum commit) | USD 5-figure/year (minimum commit) |
help = limited or additional module required
Built for Managed Service Providers
Manage dozens or hundreds of customers from one platform, with full tenant separation, white-labeling and asset-based billing.
MSP Dashboard
Aggregated overview across all tenants:
- •Overall KPIs: tenants, assets, critical vulnerabilities, scan success rate
- •Client health matrix with color-coded status per tenant
- •Real-time audit timeline across all security events
- •System health widget for gateway and platform status
Tenant Management
Full control over every tenant:
- •Create, edit and deactivate tenants
- •Tenant-specific users with role assignment (Admin, Analyst)
- •Individual theme customization: logo, colors, login text
- •Billing configuration per tenant
White-Label
Present RECON under your own brand:
- •Your own logo and color scheme per tenant
- •Individual login screen with your branding
- •Branded PDF reports for your customers
- •Tenant-specific email notifications
RBAC & Audit Trail
Role-based access control and complete logging:
- •3 roles: MSP Admin, Tenant Admin, Analyst
- •Complete audit trail of all actions
- •IP tracking and session management
- •JWT authentication with refresh tokens
What RECON detects
Comprehensive vulnerability detection across all layers of your infrastructure.
Network & Hosts
Live- checkCVE detection on network services
- checkOpen ports & exposed services
- checkDefault credentials & misconfigurations
- checkSSL/TLS certificates & cipher suites
Web Applications
Live- checkWeb vulnerabilities (XSS, SQLi, SSRF, etc.)
- checkSecurity header analysis
- checkHeadless browser for SPA/JS frameworks
- checkAuthenticated scans with custom headers
Infrastructure & DNS
Live- checkDNS configuration errors & misconfigurations
- checkExposed credentials & secrets
- checkOut-of-band interaction detection
- checkProxy support for DMZ scans
Port Scan & TLS Audit
Planned- scheduleActive port discovery (public & internal via gateway)
- scheduleTLS cipher, certificate & version audit
- scheduleWeekly scans, daily TLS refresh
- scheduleDual path: public IPs & private networks
Container & K8s Images
Planned- scheduleContainer image CVE scanning
- scheduleKubernetes misconfiguration checks
- scheduleSBOM generation (CycloneDX/SPDX)
- scheduleAuto-discovery from EKS/AKS/GKE clusters
Dangling Resource Detection
Planned- scheduleSubdomain takeover detection (13 check patterns)
- scheduleDangling CNAME detection (provider-specific)
- scheduleDaily automatic sweep
- scheduleInstant alert on new takeover risk
Intelligent Finding Management
Deduplication
Automatic consolidation of identical findings across all scans
Occurrence Counting
First seen, last seen and frequency per finding
Status Workflow
Open → Fixed → False Positive → Accepted Risk
Whitelist Management
Exception rules with expiry date and comment
Full-Text Search
Across all findings, templates and hosts
Bulk Export
CSV & PDF with configurable filters
Your security posture at a glance
0-100 points with trend indicator and historical progression
Donut chart with Info, Low, Medium, High, Critical
90-day history of vulnerability development
Asset type breakdown: domains, IPs, URLs, ranges
Seamless in your SecOps workflow
RECON integrates directly with ticketing, ChatOps, SIEM and identity providers, with signed webhooks, a flexible alert engine and enterprise authentication.
Signed Webhooks & ChatOps
Outbound webhooks with ready-made payload formats for Slack, Microsoft Teams, Jira, ServiceNow or generic JSON endpoints. Every payload is HMAC-SHA256 signed, for verified delivery without spoofing risk.
- checkSlack, Teams, Jira, ServiceNow, generic
- checkHMAC-SHA256 signature per request
- checkJira 2-way sync: finding ↔ ticket linked
- checkAsync delivery with retry logic
Alert Rule Engine
Flexible rule engine with AND/OR conditions on severity, status, host patterns, CVE ID or template tag. MSP default rules are inherited by all tenants; tenants can add their own rules.
- checkAND/OR conditions across multiple fields
- checkMSP defaults + tenant-specific overrides
- checkTriggers on finding creation, status change, scan completion
Enterprise Single Sign-On
OIDC and SAML login with Microsoft Entra (Azure AD), Keycloak, Google Workspace and other IdPs. An SSO-only flag prevents password logins for federated accounts: one less attack vector.
- checkOIDC & SAML via Authlib
- checkPer-tenant approval queue for new SSO users
- checkSSO-only flag against password takeover
TOTP-based MFA
Multi-factor authentication per RFC 6238 (TOTP) with all common authenticator apps: Microsoft Authenticator, Google Authenticator, Authy, 1Password. Backup codes for lost-device scenarios included.
- checkTOTP per RFC 6238
- checkBackup codes & recovery flow
- checkEnforcement configurable per tenant
Automated PDF reports by email
Configure a report schedule per tenant (weekly, monthly or disabled). RECON generates branded PDF reports automatically and sends them via SMTP to defined recipients: ideal for management reviews and compliance evidence.
Your data. Your sovereignty. Swiss law.
RECON is built from the ground up for the revised Swiss Data Protection Act (revDSG) and GDPR. Encrypted storage, transparent retention periods and built-in data subject rights, without external tools or add-on modules.
Encryption at Rest
Sensitive configuration data (SMTP passwords, API tokens, SSO secrets) is stored encrypted, with a separate encryption key.
Automatic Retention Sweep
RECON automatically deletes data after a configurable retention period (default 12 months): FADP/GDPR compliant, without manual intervention.
GDPR Export (Art. 20)
Data subjects can retrieve their data in a machine-readable format via a built-in self-service endpoint, without a support ticket.
Right to Erasure (Art. 17)
Deletion at tenant or user level with FK cascade cleanup: no orphaned findings, logs or assets left behind in the DB.
A complete audit trail, every access logged
Every action (login, scan start, finding status change, user creation, settings change) is recorded with timestamp, user, IP address and session ID in an immutable audit log. Cross-tenant visibility for MSP admins, tenant-isolated for tenant admins.
All features. One fair price.
Vulnerability scanning, brand protection, cloud inventory, AI analyst and MSP portal, all included, no feature gating. At a fraction of the price of the big vendors.
| Number of assets | Price per asset / month |
|---|---|
| 1 – 49 assets | CHF 3.00 |
| 50 – 99 assets | CHF 2.00 |
| 100 – 299 assets | CHF 1.00 |
| 300 – 499 assets | CHF 0.70 |
| 500 – 999 assets | CHF 0.60 |
| 1,000+ assets | CHF 0.50 |
One asset = a domain, IP address, URL, IP range, cloud resource or brand watchlist entry.
Full feature set, vulnerability scanning, brand protection, cloud inventory, AI analyst, MSP portal, included from the very first asset.
REQUEST A QUOTE NOW arrow_forwardUp to 10× cheaper than Tenable, Qualys or Black Kite, without feature gating and without US cloud dependency. While competitors charge five-figure annual fees, with RECON you only pay for what you actually use.
Cloud-hosted, ready to use immediately
RECON runs entirely in the cloud. No local server operation, no maintenance, no infrastructure costs. For internal scans, simply deploy a gateway VM; the rest runs automatically.
What is Attack Surface Management (ASM)?
Attack Surface Management (ASM) is the continuous process of discovering, cataloging and monitoring all digital assets that a company exposes to the internet or to internal networks. This includes domains, IP addresses, web applications, APIs, cloud services and network devices.
RECON automates this process: the platform continuously scans your entire attack surface, detects vulnerabilities (CVEs, misconfigurations, exposed credentials) and prioritizes findings with AI-powered analysis. As an MSP platform, you manage any number of customers from one central portal.
As a cloud-hosted solution, RECON is ready to use immediately, without local installation. For scans in the internal network, preconfigured gateway VMs are available that communicate with the cloud platform in encrypted form.
Frequently asked questions
What is RECON?expand_more
RECON is a cloud-based vulnerability scanner and attack surface management tool by Ironate. It detects vulnerabilities in networks, web applications and infrastructure: automated, continuous and with AI-powered analysis.
Is RECON suitable for MSPs?expand_more
Yes. RECON was designed from the ground up as an MSP platform: full multi-tenancy, white-labeling, tenant-specific dashboards, centralized management and asset-based billing. You manage all customers from a single portal.
How does the gateway architecture work?expand_more
RECON gateways are lightweight VMs that are deployed in customer networks. They perform internal scans and transmit results to the cloud platform in encrypted form. Available as preconfigured images for KVM/Proxmox, VMware and Hyper-V.
How much does RECON cost?expand_more
RECON is billed per asset and month. The entry price is CHF 3.00/asset/month. From 50 assets the price drops to CHF 2.00, from 100 to CHF 1.00. High volumes from 1,000 assets start at CHF 0.50/asset/month. Full feature set from the very first asset, no feature gating.
Which vulnerabilities does RECON detect?expand_more
CVEs, web vulnerabilities, misconfigurations, exposed credentials, SSL/TLS weaknesses, missing security headers and much more, across hosts, web applications, APIs and DNS. The scan engine is updated continuously.
Is RECON hosted in the cloud?expand_more
Yes. The RECON platform runs entirely in the cloud, no local server operation required. For internal network scans, optional gateway VMs are deployed in the customer network and communicate with the cloud in encrypted form.
How quickly is RECON ready to use?expand_more
Immediately. Since RECON is cloud-hosted, you can start external scans right after creating your account. For internal scans you deploy a gateway VM; setup typically takes less than 30 minutes.
How does RECON prioritize vulnerabilities?expand_more
Each finding receives a risk score from 0–100, calculated from three factors: the technical severity (CVSS, EPSS exploit probability, CISA KEV status), the criticality of the affected asset (Low/Medium/High/Critical) and the exposure (public-facing vs. internal). This shows you at a glance what needs to be fixed first, not just by CVSS, but by actual business risk.
Which integrations does RECON support?expand_more
RECON offers signed outbound webhooks (HMAC-SHA256) for Slack, Microsoft Teams, Jira (including 2-way sync for ticket linking), ServiceNow and generic JSON endpoints. For authentication, OIDC and SAML are supported via Authlib (Microsoft Entra, Keycloak, Google Workspace). A flexible alert rule engine with AND/OR conditions enables precise triggers on severity, status, host patterns or CVE ID. For critical findings, incidents can be created automatically in the connected ticketing or SOAR system.
Is RECON FADP/GDPR compliant?expand_more
Yes. RECON implements GDPR Art. 17 (right to erasure) with tenant-wide data deletion, Art. 20 (data portability) via a built-in self-service endpoint and automatic retention with a configurable retention period (default 12 months). Sensitive configuration data is stored encrypted. Every action is recorded in the audit log with user, IP address and timestamp.
How does the AI security analyst work?expand_more
The integrated AI analyst is provider-agnostic: you choose which AI model processes your data, including locally operated models without any cloud transmission. The assistant runs real queries on your scan data (finding search, severity distribution, top-N rankings, trend analyses) and delivers context-aware prioritization and remediation recommendations. Tenant isolation is guaranteed; MSP admins can optionally analyze across tenants.
What is HIBS and how does it protect my brand name?expand_more
HIBS (Host-Intelligence & Brand-Surveillance) is the brand protection component of RECON. It continuously monitors domain permutations, homoglyphs and TLD variants of your brand name. On new matches, DNS, HTTP/HTTPS, TLS certificates, screenshots and tech stack are checked automatically. For detected phishing domains, a structured takedown workflow starts with an evidence package PDF (SHA-256 secured) and prepared abuse notification letters.
What sets RECON apart from Black Kite or Tenable?expand_more
Black Kite works exclusively with OSINT: it performs no authorized scans in the customer network and therefore cannot see internal vulnerabilities. RECON combines authorized internal scans (via gateway VM) with external ASM and cloud inventory in one platform. Unlike Tenable and Qualys, RECON is MSP-native from the ground up: true multi-tenancy, white-label and tenant-specific billing are core features, not add-ons. CH/EU data residency without the US CLOUD Act is structurally impossible with any US vendor.
Will RECON inventory cloud resources?expand_more
Yes, AWS and Azure are already live in production, each with more than 20 resource types (VMs, storage, databases, Kubernetes, IAM, Key Vaults and more). GCP support follows as the third cloud provider. The inventory runs without an agent directly via the cloud APIs and shows your customers' entire cloud attack surface at a glance.
What is Attack Path Analysis and why does it matter?expand_more
Attack Path Analysis models how an attacker could advance through your infrastructure from an exposed service to your most critical assets (crown jewels). To do this, RECON connects hosts, vulnerabilities, ports, container images, DNS records and cloud resources into an asset graph and calculates prioritized attack paths with an overall risk score. This tells you which vulnerabilities actually enable a complete attack path, and what needs to be patched first. Feature in development, Phase D.
Which compliance frameworks are supported?expand_more
The planned compliance engine automatically checks your cloud configuration against CIS benchmarks (AWS, Azure, GCP, Kubernetes) and maps the results to regulatory frameworks: NIST CSF v2.0, PCI DSS v4.0, ISO 27001:2022, the revised Swiss Data Protection Act (revDSG CH-2023) and GDPR Art. 32. Each framework delivers a score (0–100), per-control drilldown, exception management with expiry dates and PDF export for audits.
Can RECON inventory SaaS platforms like M365 or Google Workspace?expand_more
Yes, planned for Phase D. RECON will inventory Microsoft 365 (users incl. MFA status, app registrations, conditional access policies, Defender alerts), Google Workspace (users, OAuth apps, Alert Center), Salesforce (users, connected apps, permissions) and Okta (users, groups, policies). The sweep runs automatically every 6 hours and reveals forgotten admin accounts, missing MFA and excessive OAuth permissions.