# Weborb

*/Startups/Weborb*

## Startup Overview

IT and security teams lose visibility over unmanaged web applications, orphaned APIs, and rogue infrastructure scattered across the public web. To eliminate this blind spot, the platform autonomously crawls and catalogs shadow web assets, mapping an organization's complete external attack surface without manual input.

Heavy enterprise tools like Tenable ASM and Cortex Xpanse demand complex configurations, while manual spreadsheets fall out of date the moment they are saved. Operating completely agentless, this system integrates instantly to discover external exposures. It continuously updates the asset inventory in real time, giving security teams immediate, accurate visibility the moment a new shadow asset comes online.

## Startup Founding Hypothesis

**Approach**: that crawls and catalogs shadow web assets autonomously
**Competitors**:
- [Tenable ASM](/Competitors/Tenable_ASM)
- [Cortex Xpanse](/Competitors/Cortex_Xpanse)
- [Manual asset spreadsheets](/Competitors/Manual_asset_spreadsheets)
**Differentiator2x2**: completely agentless to integrate and continuously updated in real time

## Startup Solution Coordinate

**Solution**: [Weborb Asset Scanner](/Software/Weborb_Asset_Scanner)

## Startup Position2x2

```mermaid
quadrantChart
title Asset Discovery Positioning
x-axis Heavy Integration --> Completely Agentless
y-axis Point-in-time Scans --> Continuous Real-time Updates
quadrant-1 Automated Real-Time
quadrant-2 Heavy Continuous
quadrant-3 High Effort Stale
quadrant-4 Agentless but Periodic
Manual asset spreadsheets: [0.15, 0.15]
Tenable ASM: [0.75, 0.35]
Cortex Xpanse: [0.45, 0.75]
Weborb: [0.85, 0.85]
```

## Startup Offer

**Proof**:
- Targeting the discovery of abandoned staging environments within 24 hours of initial configuration.
- Aiming to eliminate manual asset spreadsheet tracking for mid-market security teams.
- Designed to autonomously identify exposed cloud infrastructure tied to corporate namespaces without credentialed access.
**Tiers**:
- Name: Essential Discovery · Price: ~$300–$600/mo · Inclusions: Up to 5 primary root domains, daily automated sub-domain enumeration, passive DNS correlation, and standard shadow IT alerting for small security teams.
- Name: Continuous Mapping · Price: ~$800–$1,500/mo · Inclusions: Up to 25 primary root domains, continuous real-time crawling, exposed cloud bucket discovery, and intended integration with standard IT issue trackers.
- Name: Enterprise Perimeter · Price: ~$2,500–$5,000/mo · Inclusions: Unlimited primary root domains, autonomous deep-crawling for orphaned APIs, rapid asset attribution, and designed webhook support for SIEM ingestion.
**Guarantee**: If Weborb fails to uncover at least one previously unknown, publicly accessible shadow asset attached to your covered domains within the first 14 days, your first month of service is fully refunded.
**Business Function**: ProvideService
**Objection Handlers**:
- We already use a vulnerability scanner. -> Vulnerability scanners only test known IP blocks; Weborb maps the unknown shadow assets you haven't pointed them at yet.
- Won't this trigger our own WAF or intrusion detection? -> Weborb is designed to operate purely from the outside-in using passive DNS, certificate transparency logs, and public crawls, avoiding aggressive exploit payloads.
- Pricing by asset will get unpredictable fast. -> Weborb tiers are based solely on your known primary root domains, meaning you are not financially penalized when the platform discovers hundreds of unknown subdomains.
- It will flood our alerts with false positives. -> The crawler correlates DNS records and SSL certificates to filter out parked domains and unverified third-party hosts before generating an alert.
**Pricing Architecture**: Tiered
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical cybersecurity register driven by absolute factual certainty.
**Tagline**: Map your complete external attack surface without deploying agents.
**Icon Concept**: server
**Palette Intent**: electric-signal
**Visual Identity**: High-contrast neon green and deep terminal black define the palette, supported by monospaced typography to evoke raw network telemetry.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Weborb → SecOps Analyst → Chief Information Security Officer (CISO)
**Gtm Motion**: Acquisition relies on a self-serve, single-domain scan that instantly reveals forgotten subdomains or exposed development servers to the evaluating security analyst. Expansion happens by upselling the CISO on continuous, automated monitoring across the organization's entire IP space and subsidiary network.
**Agent Channel**: Intended for registry as a structured API tool in the LangChain ecosystem and designed to list in the OpenAI marketplace, enabling autonomous SOC agents to dynamically query the organization's exposed web assets during threat hunting workflows.
**Primary Channel**: Organic search driven by technical teardowns of common shadow IT exposures, capturing security engineers actively querying terms like 'agentless subdomain enumeration' or 'continuous external attack surface monitoring'.

## Startup Customer Journey

```mermaid
flowchart LR; A[Technical Teardown Blog] --> B[Self-Serve Domain Scanner]; B --> C[Exposed Subdomain Report]; C --> D[Continuous Asset Tracker]; D --> E[Enterprise Asset Dashboard]; E --> F[SOC Agent API Endpoint];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day single-root-domain discovery sprint: Proves the engine can autonomously surface at least one forgotten staging environment or orphaned API without credentialed access.
- 30-day webhook integration pilot: Validates that discovered shadow assets route cleanly into the security team's standard IT issue tracker with accurate DNS and SSL correlation data.
**Target Metrics**:
- Target: 1 or more previously unknown shadow assets discovered within the first 14 days of deployment
- Aim: Under 24 hours to identify newly exposed cloud infrastructure tied to covered corporate namespaces
- Target: 100 percent elimination of manual asset-tracking spreadsheets for security teams
- Aim: 0 false-positive alerts generated from parked domains or unverified third-party hosts
**Target Case Studies**:
- Mid-market software company Security Director: Transitions from a static, manually updated IP spreadsheet to continuous real-time crawling that automatically discovers abandoned staging environments.
- Enterprise financial services CISO: Integrates Weborb webhooks into the corporate SIEM, enabling autonomous, credential-free discovery of exposed cloud infrastructure without triggering internal WAF alerts.
- Small e-commerce IT Manager: Eliminates shadow IT blind spots by deploying daily automated sub-domain enumeration across 5 root domains, catching forgotten marketing subdomains before they are exploited.
**Testimonial Targets**:
- Security Director: Confirms that pricing by known primary root domain removes the financial penalty of discovering hundreds of vulnerable subdomains.
- Security Operations Center Analyst: Validates that passive DNS correlation and certificate transparency log scraping operate completely outside-in, triggering zero WAF block alerts.
- VP of Information Security: Highlights how the platform feeds traditional vulnerability scanners by identifying the unknown IP blocks the scanners were previously missing.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major cloud service providers and WAFs like Cloudflare outright block or heavily rate-limit the autonomous scanning engine, neutralizing the real-time continuous update capability. · Mitigation Status: unmitigated
- Severity: high · Description: Incumbents like Palo Alto Networks bundle real-time agentless discovery into existing enterprise Cortex Xpanse contracts at zero additional cost. · Mitigation Status: unmitigated
- Severity: moderate · Description: The autonomous crawler generates an unmanageable volume of false-positive asset attributions, exhausting customer security teams and driving high churn. · Mitigation Status: in-progress
- Severity: moderate · Description: Enterprise compliance audits refuse to accept purely external agentless scans as proof of full inventory, blocking deals in highly regulated financial and healthcare sectors. · Mitigation Status: unmitigated

## Startup Competitors

- [Tenable ASM](/Competitors/Tenable_ASM) — Incumbent ASM
- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — Enterprise Platform
- [Manual Asset Spreadsheets](/Competitors/Manual_Asset_Spreadsheets) — Status Quo
- [Censys ASM](/Competitors/Censys_ASM) — Scanner Alternative
- [CyCognito](/Competitors/CyCognito) — Legacy EASM

## Startup Solution Stack

- [Shadow Asset Catalog Service](/Services/Shadow_Asset_Catalog_Service) — Service-as-Software
- [Autonomous Discovery Agent](/Agents/Autonomous_Discovery_Agent) — Agent
- [Subdomain Recon Worker](/Agents/Subdomain_Recon_Worker) — Agent
- [Agentless Scan Engine](/Software/Agentless_Scan_Engine) — Software
- [Asset Telemetry API](/Software/Asset_Telemetry_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the defender who knows the network better than any adversary
- **Want**: to see the entire external attack surface that is visible to attackers
- **Identity**: the security lead at a mid-market enterprise
**Plan**:
- Step: Input root domains · Detail: Provide the corporate namespaces you already know to start the autonomous crawl.
- Step: Inspect shadow assets · Detail: Review the live list of previously unknown subdomains and orphaned cloud storage discovered by the engine.
- Step: Sync security alerts · Detail: Route discovered assets to your SIEM or issue tracker for immediate risk mitigation.
**Guide**:
- **Empathy**: When a developer spins up a new staging environment without telling IT, your vulnerability scanner remains blind to the risk.
**Problem**:
- **Villain**: Shadow IT sprawl
- **External**: Stale asset spreadsheets and manual DNS lookups fail to track forgotten staging servers and orphaned cloud buckets in AWS or Azure.
- **Internal**: You feel exposed by the blind spots lurking behind unmapped domains and abandoned APIs.
- **Philosophical**: Every security lead deserves absolute visibility into their perimeter — not a mounting list of unknowns.
**Success**: The external perimeter is fully mapped and continuously monitored, with zero shadow assets remaining in the dark.
**One Liner**: Manual asset spreadsheets cost security leads visibility. Weborb crawls and catalogs shadow web assets so you can secure every endpoint before an attacker finds it.
**Positioning**:
- **So That**: eliminate shadow IT blind spots without deploying agents
- **Unlike**: Manual asset spreadsheets
- **For Whom**: mid-market security teams
- **Category**: Attack Surface Management
**Call To Action**:
- **Direct**: Launch asset discovery
- **Transitional**: View sample perimeter report
**Failure Stakes**:
- Data breaches via unpatched shadow assets
- Zero visibility into abandoned cloud environments
- Compliance failure for unmapped infrastructure
**Transformation**:
- **To**: the lead who secures every public corporate endpoint
- **From**: a defender managing assets in static spreadsheets
**Controlling Idea**: True perimeter security requires autonomous discovery of what you don't know exists.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Manual asset spreadsheets cost security leads visibility. Weborb crawls and catalogs shadow web assets so you can secure every endpoint before an attacker finds it.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 18bf5e602953393f

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Attack Surface Management for mid-market security teams. Unlike Manual asset spreadsheets — eliminate shadow IT blind spots without deploying agents.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: c6fd52f9887f08b1

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Stale asset spreadsheets and manual DNS lookups fail to track forgotten staging servers and orphaned cloud buckets in AWS or Azure.
Solution: Manual asset spreadsheets cost security leads visibility. Weborb crawls and catalogs shadow web assets so you can secure every endpoint before an attacker finds it.
Customer: mid-market security teams
Unlike: Manual asset spreadsheets
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 9d2670f80f248f1e

## Startup Token M E D D P I C C

**Pain**: Stale asset spreadsheets and manual DNS lookups fail to track forgotten staging servers and orphaned cloud buckets in AWS or Azure.
**Metrics**: Target: The external perimeter is fully mapped and continuously monitored, with zero shadow assets remaining in the dark.
**Rendered**: Pain: Stale asset spreadsheets and manual DNS lookups fail to track forgotten staging servers and orphaned cloud buckets in AWS or Azure.
Economic buyer: SecOps Analyst
Metrics: Target: The external perimeter is fully mapped and continuously monitored, with zero shadow assets remaining in the dark.
Competition: Manual asset spreadsheets
**Mechanism**: spine-derived-v1
**Competition**: Manual asset spreadsheets
**Economic Buyer**: SecOps Analyst
**Vocab Fingerprint**: 92780d78bc2d5f87

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Attack Surface Management for mid-market security teams

mid-market security teams — Stale asset spreadsheets and manual DNS lookups fail to track forgotten staging servers and orphaned cloud buckets in AWS or Azure. Manual asset spreadsheets cost security leads visibility. Weborb crawls and catalogs shadow web assets so you can secure every endpoint before an attacker finds it.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 35f894a973c097b7

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Attack Surface Management. Manual asset spreadsheets cost security leads visibility. Weborb crawls and catalogs shadow web assets so you can secure every endpoint before an attacker finds it. Serves mid-market security teams.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 18c71498ceb35b05

## Neighborhood

### Candidate solutions

- [Untangle Intercompany Eliminations](/Problems/Untangle_Intercompany_Eliminations) — candidate solution for · Problems

### What it offers

- [Weborb Asset Scanner](/Software/Weborb_Asset_Scanner) — offers · Software

### Composed of

- [Shadow Asset Catalog Service](/Services/Shadow_Asset_Catalog_Service) — composes · Services
- [Autonomous Discovery Agent](/Agents/Autonomous_Discovery_Agent) — composes · Agents
- [Agentless Scan Engine](/Software/Agentless_Scan_Engine) — composes · Software
- [Asset Telemetry API](/Software/Asset_Telemetry_API) — composes · Software
- [Subdomain Recon Worker](/Agents/Subdomain_Recon_Worker) — composes · Agents

### Competitors

- [Manual Asset Spreadsheets](/Competitors/Manual_Asset_Spreadsheets) — competes with · Competitors
- [Cortex Xpanse](/Competitors/Cortex_Xpanse) — competes with · Competitors
- [Tenable ASM](/Competitors/Tenable_ASM) — competes with · Competitors
- [Censys ASM](/Competitors/Censys_ASM) — competes with · Competitors
- [CyCognito](/Competitors/CyCognito) — competes with · Competitors

### Embodies

- [Software](/Theses/Software) — embodies · Theses

### Similar Startups

- [Cloudint](/Startups/Cloudint) — similar · Startups
- [Shadowyard](/Startups/Shadowyard) — similar · Startups
- [Guardiandeck](/Startups/Guardiandeck) — similar · Startups
- [Scovers](/Startups/Scovers) — similar · Startups
- [Keystonepulse](/Startups/Keystonepulse) — similar · Startups
- [Mapleshape](/Startups/Mapleshape) — similar · Startups
- [Porosityscaffold](/Startups/Porosityscaffold) — similar · Startups
- [Multishadow](/Startups/Multishadow) — similar · Startups
- [Zenare](/Startups/Zenare) — similar · Startups
- [Denoot](/Startups/Denoot) — similar · Startups
- [Awarestack](/Startups/Awarestack) — similar · Startups
- [Forgouble](/Startups/Forgouble) — similar · Startups
- [Apyard](/Startups/Apyard) — similar · Startups
- [Summitgate](/Startups/Summitgate) — similar · Startups
- [Domyn](/Startups/Domyn) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Casdomain](/Startups/Casdomain) — similar · Startups
- [Abrasiveridge](/Startups/Abrasiveridge) — similar · Startups
- [Potera](/Startups/Potera) — similar · Startups
- [Assanager](/Startups/Assanager) — similar · Startups
