Eon Kartis Perimeter scanning. See yourself the way the outside does. Perimeter scan. See what outside world see.

// attack surface — register vs. what is really there

Eon Kartis takes a domain name and works outward until it has the estate: every host that resolves, every service on it that negotiates cryptography. Per host it records the cipher suites, the certificate chains and the protocol versions with known weaknesses, then holds the result against the register you upload. The hosts you never registered come back with the rest.

Who this is for

Organisations that:

What it does

Three verdicts

VerdictWhat it means
shadow Plausibly yours, and absent from the register. Somebody stood it up and nobody wrote it down.
rogue Impersonation, or a certificate mis-issued for your name. Not yours, but wearing your name.
drift A registered asset that has moved away from your own crypto policy.

How it works

Facts

scannedweb · mail (SMTP/IMAP/POP, STARTTLS and implicit) · SSH · OpenVPN · IKE/IPsec · QUIC · anything else presenting a certificate
also flaggedplaintext on a port where encryption was the expectation
discoveryWHOIS · CT logs · DNS · ASN · fingerprints
comparedagainst your own register and the estate's own majority behaviour
verdictsshadow · rogue · drift
registeruploaded as xlsx or csv, parsed server-side
positionoutside the network, no agent, no install
deploymentyour own Linux server

Plans

Two plans, both subscriptions, both running monthly. A single assessed run is the CBA; continuous monitoring with alerting is Eon Aethis. Kartis sits between them: the same estate, discovered and scanned again every month.

 BasicFull
Price€2,400 / yearband S €6,000 · band M €12,000 · larger on quote
Scope3 root domains, supplied by youS: 15 domains / 500 hosts · M: 50 domains / 2,000 hosts
Cadencemonthlymonthly + 12 on-demand runs a year
Depthdiscovery + TLS posture+ WAF, crypto posture, port-scan depth, organisation expansion

Which band you are in follows from a scoping run during the sales conversation, not from an estimate.

Kartis scan your estate from outside. Same way stranger see it.

It report what your perimeter really show: which cipher, which certificate chain, which protocol version you should have killed years ago.

What it do

Three verdict

How it work

Facts

scannedanything public-facing that negotiates crypto
servicesweb · mail (SMTP/IMAP/POP) · SSH · OpenVPN · IKE/IPsec · QUIC · other TLS services
discoveryWHOIS · CT logs · DNS · ASN · fingerprints
verdictsshadow · rogue · drift
registeruploaded as xlsx or csv, parsed server-side
positionoutside the network, no agent, no install
deploymentyour own Linux server

Plan

Two plan. Both run every month. One run, one time, human explain it? That is CBA. Watch all day, shout when thing break? That is Aethis. Kartis is map, every month.

Eon Kartis — external perimeter scanner for post-quantum readiness. Discovery, recon, scanning and scheduling run as separate processes over PostgreSQL and Redis pubsub. Scans every public-facing service that negotiates cryptography — HTTPS, mail (SMTP/submission/IMAP/POP, STARTTLS and implicit TLS), SSH, OpenVPN, IKE/IPsec, QUIC and any other service presenting a certificate — plus plaintext on ports where encryption is expected, from outside the target network; no agent is installed on the target.

Pipeline

discovery (WHOIS, CT logs, DNS recon, IP-ASN, tech fingerprint, optional AI correlation) → DNS resolution and per-host scan queue → scan (service detection, TLS/SSH/QUIC, VPN and mail-protocol probes, analyzers, PQC signals) → posture analysis against the uploaded register. Discovery and scanning are separate processes; work moves between them over Redis pubsub, one scan session per resolvable host.

Discovery sources

whoisregistrant and nameserver pivots
ct logsCertificate Transparency subdomain harvest
dnsbrute force, passive DNS, reverse lookups
ip-asnASN expansion, neighbouring prefixes
tech fingerprintHTTP and TLS fingerprint to related hosts
correlationoptional LLM pass over the harvest

Posture analysis

Analysis runs over stored reconnaissance data rather than re-probing. The observed estate is compared against the customer's central register and against the estate's own majority cluster; hosts carrying a medium-or-worse finding are promoted to the existing deep scan rather than to a second scanner.

shadowplausibly ours, absent from the register
rogueimpersonation, or a certificate mis-issued for our name
driftregistered asset deviating from crypto policy
register inputxlsx / csv, parsed server-side
executionasynchronous run, triage first, deep scan on promotion

Deployment

processesscan daemon + discovery daemon
statePostgreSQL
queueRedis pubsub
authbearer token, hashed at rest, revocable
targetLinux x86 server, container images supplied

Plans

basic (basis)€2,400/yr · 3 root domains, customer-supplied · monthly · discovery + TLS posture
full S (volledig)€6,000/yr · 15 domains / 500 hosts · monthly + 12 on-demand · full depth
full M (volledig)€12,000/yr · 50 domains / 2,000 hosts · monthly + 12 on-demand · full depth
full L (volledig)above that: quote, band set by a scoping run
full depthWAF detection, crypto posture (shadow/rogue/drift), port-scan depth, AI org expansion with reverse-WHOIS
cadencemonthly map plus a flat new-since-last-run list; continuous monitoring and alerting are Aethis
tier valuesbasis · volledig — the portal's own keys, posted unchanged
requestPOST /api/kartis-signup.php — tier, name, email, organisation, domains, message, consent
storagenone: a request is mailed, not stored
one-offnot sold here: a single assessed run is the CBA

Documentation

Full reference at docs.eoncore.eu/eon-kartis/. Every page there is also Markdown: append index.md to its URL. All products in one file: docs.eoncore.eu/llms-full.txt.