Eon Kartis Perimeter scanning. See yourself the way the outside does. Perimeter scan. See what outside world see.
Eon Kartis takes a domain name and works outward until it has the estate: every host that resolves, every service on it that negotiates cryptography. Per host it records the cipher suites, the certificate chains and the protocol versions with known weaknesses, then holds the result against the register you upload. The hosts you never registered come back with the rest.
Who this is for
Organisations that:
- Keep a central register of systems and suspect it is no longer complete.
- Have to show a regulator or an auditor where they stand on post-quantum readiness.
- Want to know whether something is presenting a certificate in their name that they never issued.
What it does
- Finds what you own. Registrant and nameserver pivots, Certificate Transparency logs, DNS reconnaissance, ASN expansion into neighbouring prefixes, and HTTP and TLS fingerprints that lead to related hosts.
- Scans what it finds. Every resolvable host gets its own scan, and every service on it that negotiates cryptography: web, mail over SMTP, submission, IMAP and POP with STARTTLS or implicit TLS, SSH, OpenVPN, IKE and IPsec, QUIC, and anything else presenting a certificate. Cipher suites, certificate chains, protocol versions with known weaknesses — and plaintext on a port where encryption was the expectation.
- Measures readiness. Findings are assessed against the post-quantum cryptography readiness baseline, not against a generic vulnerability list.
- Names the gap. The observed estate is held against your register and against the estate's own majority behaviour. Every finding lands under one of three verdicts.
Three verdicts
| Verdict | What it means |
|---|---|
shadow |
Plausibly yours, and absent from the register. Somebody stood it up and nobody wrote it down. |
rogue |
Impersonation, or a certificate mis-issued for your name. Not yours, but wearing your name. |
drift |
A registered asset that has moved away from your own crypto policy. |
How it works
- 1 · Discover. The discovery daemon works outward from the names you give it, storing every host it finds and where it came from.
- 2 · Resolve and queue. Each discovered host is resolved and turned into its own scan job, so one oversized target list cannot swamp the run.
- 3 · Scan. Workers pull jobs and probe each host on its own, recording services, findings and post-quantum signals separately.
- 4 · Compare. You upload your register as a spreadsheet. Cheap checks over the stored data triage the whole estate first; only hosts carrying a medium-or-worse finding are promoted to a deep scan.
Facts
Plans
Two plans, both subscriptions, both running monthly. A single assessed run is the CBA; continuous monitoring with alerting is Eon Aethis. Kartis sits between them: the same estate, discovered and scanned again every month.
Basic
€2,400per year
Three root domains you name yourself, scanned every month: discovery plus TLS posture, and a flat list of what is new since the previous run.
Request Basic →Full
from€6,000per year
Full depth on a larger estate: WAF detection, crypto posture with the three verdicts, port-scan depth, and organisation expansion over reverse-WHOIS. Monthly, plus twelve on-demand runs a year.
Request Full →| Basic | Full | |
|---|---|---|
| Price | €2,400 / year | band S €6,000 · band M €12,000 · larger on quote |
| Scope | 3 root domains, supplied by you | S: 15 domains / 500 hosts · M: 50 domains / 2,000 hosts |
| Cadence | monthly | monthly + 12 on-demand runs a year |
| Depth | discovery + TLS posture | + WAF, crypto posture, port-scan depth, organisation expansion |
Which band you are in follows from a scoping run during the sales conversation, not from an estimate.
Kartis scan your estate from outside. Same way stranger see it.
It report what your perimeter really show: which cipher, which certificate chain, which protocol version you should have killed years ago.
What it do
- Find what you own. WHOIS pivot. Certificate Transparency log. DNS recon. ASN neighbour prefix. HTTP and TLS fingerprint that lead to more host.
- Scan what it find. Every host get own scan. Every service on host that use crypto: web, mail server (SMTP, IMAP, POP), SSH, OpenVPN, IKE/IPsec, QUIC, anything else that answer. Cipher, cert chain, dead protocol version. Also: port that talk plain when it should talk secret.
- Measure readiness. Judge against post-quantum readiness baseline. Not generic vuln list.
- Name the gap. Compare what it see against your register, and against what rest of your estate do.
Three verdict
- shadow — probably yours. Not in register. Someone build it, nobody write it down.
- rogue — not yours. Wear your name anyway.
- drift — in register, but wandered off your crypto policy.
How it work
- 1 · Discover. Start from name you give. Walk outward. Store every host and where it came from.
- 2 · Resolve. Resolve each host. One scan job per host. Big target list cannot swamp run.
- 3 · Scan. Worker pull job. Probe host alone. Record service, finding, post-quantum signal.
- 4 · Compare. You upload register. Cheap check triage whole estate. Only bad host go to deep scan.
Facts
Plan
Two plan. Both run every month. One run, one time, human explain it? That is CBA. Watch all day, shout when thing break? That is Aethis. Kartis is map, every month.
Basic
€2,400per year
Three root domain, you name them. Every month: find host, check TLS, tell you what is new since last time.
ask for basic →Full
from€6,000per year
Big estate, deep look. WAF. Crypto posture, three verdict. Port scan deep. Walk your org over reverse-WHOIS. Every month, plus twelve run when you ask.
ask for full →- Basic. €2,400 a year. 3 root domain. Monthly. Discovery and TLS posture.
- Full, band S. €6,000 a year. 15 domain, 500 host. Monthly plus 12 run on ask. Everything.
- Full, band M. €12,000 a year. 50 domain, 2,000 host. Same, bigger.
- Bigger than that. We quote. Band come from scoping run, not from guess.
Eon Kartis — external perimeter scanner for post-quantum readiness. Discovery, recon, scanning and scheduling run as separate processes over PostgreSQL and Redis pubsub. Scans every public-facing service that negotiates cryptography — HTTPS, mail (SMTP/submission/IMAP/POP, STARTTLS and implicit TLS), SSH, OpenVPN, IKE/IPsec, QUIC and any other service presenting a certificate — plus plaintext on ports where encryption is expected, from outside the target network; no agent is installed on the target.
Pipeline
discovery (WHOIS, CT logs, DNS recon, IP-ASN, tech fingerprint, optional AI correlation) → DNS resolution and per-host scan queue → scan (service detection, TLS/SSH/QUIC, VPN and mail-protocol probes, analyzers, PQC signals) → posture analysis against the uploaded register. Discovery and scanning are separate processes; work moves between them over Redis pubsub, one scan session per resolvable host.
Discovery sources
Posture analysis
Analysis runs over stored reconnaissance data rather than re-probing. The observed estate is compared against the customer's central register and against the estate's own majority cluster; hosts carrying a medium-or-worse finding are promoted to the existing deep scan rather than to a second scanner.
Deployment
Plans
Documentation
Full reference at docs.eoncore.eu/eon-kartis/. Every page there is also Markdown: append index.md to its URL. All products in one file: docs.eoncore.eu/llms-full.txt.