# Guardiandeck

*/Startups/Guardiandeck*

## Startup Overview

This attack surface management system continuously maps and scores public-facing digital assets. It discovers rogue subdomains, exposed databases, and unsecured APIs across distributed cloud environments, delivering an immediate, live inventory of external vulnerabilities without requiring endpoint installation.

Security and IT operations teams struggle to defend perimeters when developers spin up shadow infrastructure or abandon legacy endpoints. Traditional vulnerability scanners rely on installed agents and manual configuration, leaving critical blind spots where unmanaged or forgotten infrastructure meets the public internet.

Unlike Tenable ASM and Qualys VMDR, which often depend on complex agent configurations, or manual penetration testing that only yields point-in-time snapshots, this system deploys instantly and without agents. It natively integrates with automated remediation workflows, immediately triggering patch deployments, ticket creation, or network isolation the moment a critical asset is scored as vulnerable.

## Startup Founding Hypothesis

**Approach**: that continuously maps and scores public-facing digital assets
**Competitors**:
- [Tenable ASM](/Competitors/Tenable_ASM)
- [Qualys VMDR](/Competitors/Qualys_VMDR)
- [Manual Penetration Testing](/Competitors/Manual_Penetration_Testing)
**Differentiator2x2**: agentless to deploy and natively integrated with automated remediation workflows

## Startup Solution Coordinate

**Solution**: [Edge Asset Scanner](/Software/Edge_Asset_Scanner)

## Startup Position2x2

```mermaid
quadrantChart
    title Guardiandeck vs Competitors
    x-axis High-Friction Setup --> Agentless Deployment
    y-axis Siloed Alerting --> Automated Remediation
    quadrant-1 Automated & Agentless
    quadrant-2 Automated & Agent-Heavy
    quadrant-3 Manual & Agent-Heavy
    quadrant-4 Manual & Agentless
    Guardiandeck: [0.90, 0.85]
    Tenable ASM: [0.85, 0.40]
    Qualys VMDR: [0.20, 0.60]
    Manual Penetration Testing: [0.10, 0.10]
```

## Startup Offer

**Proof**:
- Targeting 100% automated discovery of orphaned subdomains and shadow IT for mid-market organizations.
- Aiming to reduce mean-time-to-remediation (MTTR) by triggering automated IT tickets immediately upon exposure detection.
- Designed to map a 1,000-node public perimeter in under two hours without requiring locally installed agents.
**Tiers**:
- Name: Standard Discovery · Price: ~$300–$500/mo · Inclusions: Agentless asset mapping for up to 500 public IPs and domains, daily exposure scoring, and CSV reporting for shadow IT.
- Name: Remediation Pro · Price: ~$800–$1,200/mo · Inclusions: Mapping for up to 2,500 external assets, hourly perimeter scans, and webhook triggers designed to automatically route exposure alerts to standard IT ticketing systems.
- Name: Enterprise Perimeter · Price: ~$15k–$25k/yr · Inclusions: Discovery for up to 10,000 public-facing assets, continuous real-time mapping, and dedicated endpoints for custom remediation playbook integrations.
**Guarantee**: If Guardiandeck fails to automatically discover a live, public-facing asset associated with your registered root domains within the first 14 days, we will refund your initial subscription payment in full.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: 'We already use a vulnerability scanner.' Rebuttal: Scanners only check the IP ranges you explicitly give them; Guardiandeck maps the forgotten, orphaned, and shadow IT assets you didn't know were exposed.
- Objection: 'Automated remediation will break our production environment.' Rebuttal: Guardiandeck does not execute patches directly; it connects to your existing ticketing workflows to queue structured, human-approved remediation tasks.
- Objection: 'Agentless scanning won't see deep enough into our internal network.' Rebuttal: Guardiandeck is explicitly built for Attack Surface Management, mapping the exact external exposures attackers see from the outside rather than auditing internal architecture.
**Pricing Architecture**: Tiered
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and commanding, favoring stark facts over marketing embellishment.
**Tagline**: Map and secure your entire external attack surface without agents.
**Icon Concept**: Searchlight
**Palette Intent**: electric-signal
**Visual Identity**: The interface pairs deep terminal black with sharp chartreuse alerts, using monospaced typography to evoke a tactical threat-hunting environment.
**Archetype Reference**: the-hero

## Startup Buyer Chain

**Chain**: Guardiandeck → Security Operations Center (SOC) → Enterprise Organization
**Gtm Motion**: Acquires security teams by offering a limited, self-serve external attack surface discovery scan that identifies immediate public exposures. Expands accounts by upgrading users from point-in-time scanning to continuous monitoring subscriptions that connect directly to their IT service management workflows.
**Agent Channel**: Designed to publish a structured API specification to the LangChain tool registry and OpenAI integration directory, allowing autonomous threat-hunting agents to programmatically query an organization's asset map and vulnerability scores.
**Primary Channel**: Inbound search queries for "agentless attack surface management" combined with intended listings in cloud infrastructure marketplaces like AWS Marketplace and Azure Marketplace where security architects evaluate new tooling.

## Startup Customer Journey

```mermaid
flowchart LR; A[Cloud Marketplace Listing] --> B[External Discovery Scan]; B --> C[Exposure CSV Report]; C --> D[Continuous Monitoring Subscription]; D --> E[Ticketing Workflow Webhook]; E --> F[Threat-Hunting Agent API];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- A 14-day shadow IT discovery pilot targeting up to 500 public IPs, aiming to identify at least one live, public-facing asset previously unknown to the internal security team.
- A 30-day automated remediation pilot scoping 2,500 external assets, designed to prove that hourly perimeter scans successfully queue formatted IT tickets without executing unauthorized patches.
**Target Metrics**:
- Target: 100% automated discovery of orphaned subdomains and shadow IT infrastructure.
- Target: Sub-two-hour mapping completion for 1,000-node external perimeters.
- Aim: 50% reduction in mean-time-to-remediation for external exposures via direct webhook ticket generation.
**Target Case Studies**:
- A mid-market healthcare IT Director mapping unknown patient-facing subdomains to bring orphaned cloud infrastructure under active vulnerability management.
- An enterprise financial services CISO reducing exposure windows by automatically routing external perimeter alerts into standard IT ticketing workflows.
- A fast-growing software VP of Engineering establishing an immediate baseline for shadow IT by mapping a 1,000-node public perimeter in under two hours without agent deployment.
**Testimonial Targets**:
- Mid-market CISO expressing relief at gaining total visibility into shadow IT spun up by decentralized dev teams without having to negotiate agent installations.
- IT Operations Manager praising the webhook integrations for queueing structured, human-approved remediation tasks instead of dumping noisy PDF scanner reports.
- Director of Security affirming the 14-day guarantee by confirming the platform found a forgotten, exposed staging server within the first 48 hours.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Automated remediation workflows execute incorrectly and cause catastrophic production downtime for a customer. · Mitigation Status: in-progress
- Severity: high · Description: Enterprise firewalls and zero-trust architectures block external agentless scanners, preventing complete public-facing asset mapping. · Mitigation Status: in-progress
- Severity: moderate · Description: Incumbents like Tenable or Qualys bundle basic automated remediation into their existing enterprise suites, neutralizing the primary differentiator. · Mitigation Status: unmitigated
- Severity: low · Description: Cloud infrastructure providers introduce strict API rate limits that throttle the continuous asset discovery engine and delay scoring updates. · Mitigation Status: in-progress

## Startup Competitors

- [Tenable ASM](/Competitors/Tenable_ASM) — Incumbent
- [Qualys VMDR](/Competitors/Qualys_VMDR) — Incumbent
- [Manual Penetration Testing](/Competitors/Manual_Penetration_Testing) — Status Quo
- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — Enterprise Rival
- [CyCognito](/Competitors/CyCognito) — Direct Competitor

## Startup Solution Stack

- [Asset Scoring Service](/Services/Asset_Scoring_Service) — Service-as-Software
- [Remediation Execution Agent](/Agents/Remediation_Execution_Agent) — Agent
- [Asset Discovery Worker](/Agents/Asset_Discovery_Worker) — Agent
- [Edge Recon API](/Software/Edge_Recon_API) — Software
- [Vulnerability Detection Engine](/Software/Vulnerability_Detection_Engine) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the strategist who prevents breaches, not the one explaining shadow IT
- **Want**: to eliminate every blind spot across the public-facing attack surface
- **Identity**: the IT security lead at a mid-market organization
**Plan**:
- Step: Define domains · Detail: Provide your root domains to initiate the agentless mapping of your entire external perimeter.
- Step: Verify exposures · Detail: Review the continuous exposure scores for orphaned assets and shadow IT discovered by the engine.
- Step: Trigger remediation · Detail: Activate webhook alerts that route discovered vulnerabilities directly into your existing IT ticketing system.
**Guide**:
- **Empathy**: Does your asset discovery still miss orphaned subdomains and unmanaged cloud instances?
**Problem**:
- **Villain**: Shadow IT sprawl
- **External**: Publicly exposed subdomains and orphaned assets go undetected by Qualys VMDR scans because they weren't manually added to the asset list.
- **Internal**: You feel exposed and anxious knowing there are forgotten servers you can't see but hackers can.
- **Philosophical**: Defensive posture belongs in proactive visibility, not in reactive cleanup.
**Success**: Every public-facing asset is mapped, scored, and integrated into your remediation workflow with zero blind spots.
**One Liner**: What if your security team saw every external blind spot before an attacker did? Guardiandeck maps your entire digital perimeter and triggers automated remediation tickets, ensuring no asset remains unprotected.
**Positioning**:
- **So That**: automatically discover and remediate forgotten shadow IT assets
- **Unlike**: Tenable ASM or Qualys VMDR
- **For Whom**: mid-market IT security leads
- **Category**: Attack Surface Management
**Call To Action**:
- **Direct**: Map your perimeter
- **Transitional**: View sample exposure report
**Failure Stakes**:
- Unpatched shadow IT becomes a breach entry point
- Compliance failures from unmonitored public assets
- Manual mapping keeps the team in reactive mode
**Transformation**:
- **To**: free to architect proactive defense, no longer stuck chasing forgotten IP addresses
- **From**: a security lead buried in manual penetration testing logs
**Controlling Idea**: External security requires continuous discovery, not manual asset lists.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if your security team saw every external blind spot before an attacker did? Guardiandeck maps your entire digital perimeter and triggers automated remediation tickets, ensuring no asset remains unprotected.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 3c93758de556bbf6

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Attack Surface Management for mid-market IT security leads. Unlike Tenable ASM or Qualys VMDR — automatically discover and remediate forgotten shadow IT assets.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 2e16ab61ea1025fc

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Publicly exposed subdomains and orphaned assets go undetected by Qualys VMDR scans because they weren't manually added to the asset list.
Solution: What if your security team saw every external blind spot before an attacker did? Guardiandeck maps your entire digital perimeter and triggers automated remediation tickets, ensuring no asset remains unprotected.
Customer: mid-market IT security leads
Unlike: Tenable ASM or Qualys VMDR
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: fc5579c2546ee22d

## Startup Token M E D D P I C C

**Pain**: Publicly exposed subdomains and orphaned assets go undetected by Qualys VMDR scans because they weren't manually added to the asset list.
**Metrics**: Target: Every public-facing asset is mapped, scored, and integrated into your remediation workflow with zero blind spots.
**Rendered**: Pain: Publicly exposed subdomains and orphaned assets go undetected by Qualys VMDR scans because they weren't manually added to the asset list.
Economic buyer: Security Operations Center
Metrics: Target: Every public-facing asset is mapped, scored, and integrated into your remediation workflow with zero blind spots.
Competition: Tenable ASM or Qualys VMDR
**Mechanism**: spine-derived-v1
**Competition**: Tenable ASM or Qualys VMDR
**Economic Buyer**: Security Operations Center
**Vocab Fingerprint**: d1750fb119e26b79

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Attack Surface Management for mid-market IT security leads

mid-market IT security leads — Publicly exposed subdomains and orphaned assets go undetected by Qualys VMDR scans because they weren't manually added to the asset list. What if your security team saw every external blind spot before an attacker did? Guardiandeck maps your entire digital perimeter and triggers automated remediation tickets, ensuring no asset remains unprotected.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 42d3b17a856f3614

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Attack Surface Management. What if your security team saw every external blind spot before an attacker did? Guardiandeck maps your entire digital perimeter and triggers automated remediation tickets, ensuring no asset remains unprotected. Serves mid-market IT security leads.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 04138f953d0168ee

## Neighborhood

### Candidate solutions

- [Demonstrate Virtual CFO Value](/Problems/Demonstrate_Virtual_CFO_Value) — candidate solution for · Problems

### Composed of

- [Vulnerability Detection Engine](/Software/Vulnerability_Detection_Engine) — composes · Software
- [Asset Scoring Service](/Services/Asset_Scoring_Service) — composes · Services
- [Edge Recon API](/Software/Edge_Recon_API) — composes · Software
- [Asset Discovery Worker](/Agents/Asset_Discovery_Worker) — composes · Agents
- [Remediation Execution Agent](/Agents/Remediation_Execution_Agent) — composes · Agents

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### What it offers

- [Edge Asset Scanner](/Software/Edge_Asset_Scanner) — offers · Software

### Competitors

- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — competes with · Competitors
- [Manual Penetration Testing](/Competitors/Manual_Penetration_Testing) — competes with · Competitors
- [Qualys VMDR](/Competitors/Qualys_VMDR) — competes with · Competitors
- [Tenable ASM](/Competitors/Tenable_ASM) — competes with · Competitors
- [CyCognito](/Competitors/CyCognito) — competes with · Competitors

### Similar Startups

- [Weborb](/Startups/Weborb) — similar · Startups
- [Scovers](/Startups/Scovers) — similar · Startups
- [Cloudint](/Startups/Cloudint) — similar · Startups
- [Shadowyard](/Startups/Shadowyard) — similar · Startups
- [Abrasiveridge](/Startups/Abrasiveridge) — similar · Startups
- [Mapleshape](/Startups/Mapleshape) — similar · Startups
- [Porosityscaffold](/Startups/Porosityscaffold) — similar · Startups
- [Domyn](/Startups/Domyn) — similar · Startups
- [Zerodaycrest](/Startups/Zerodaycrest) — similar · Startups
- [Aurossom](/Startups/Aurossom) — similar · Startups
- [Cascec](/Startups/Cascec) — similar · Startups
- [Forgouble](/Startups/Forgouble) — similar · Startups
- [Spot Strike Labs](/Startups/Spot_Strike_Labs) — similar · Startups
- [Awarestack](/Startups/Awarestack) — similar · Startups
- [Denoot](/Startups/Denoot) — similar · Startups
- [Synent](/Startups/Synent) — similar · Startups
- [Zenare](/Startups/Zenare) — similar · Startups
- [Mythenith](/Startups/Mythenith) — similar · Startups
- [Keystonepulse](/Startups/Keystonepulse) — similar · Startups

### Similar Competitors

- [CrowdStrike Falcon Surface](/Competitors/CrowdStrike_Falcon_Surface) — similar · Competitors
