Kervo AI
[ The loop · Know ]
Kervo AI · Know

See everything you have, and everything that's exposed.

Kervo AI maps your internet-facing surface from your domains and pulls your internal estate from the EDR, vulnerability scanners and patch management tools you already run. Every domain, cloud workload, server, endpoint and network device, plus leaked credentials and vendors, in one live inventory that maintains itself.

platform.kervo.ai / know / attack-surface
Know / Attack surfaceliveacme-prodATTACK SURFACE1,288 assetss3-backup-prodCloud14.1K+2.3% · 7dCNetwork31.7K+0.4% · 7dBCode9.3K-1.1% · 7dCExternal2.4K+0.0% · 7dANEW THIS WEEK+38vpn-legacy.acme.comhostnews3-backup-prodS3 · public-readexposedapi.payco.iovendor · TLS 1.0new10.0.4.12devicenew
Seed domains plus the tools you run
no asset list required
Full picture within 48 hours
days, not months
One inventory
external, cloud, servers, endpoints, network devices, code and vendors, deduplicated
[ Products in Know ]5 pages
[ The problem ]

Why this stage exists

Ask most teams for their asset inventory and you get a CMDB that was accurate eighteen months ago, a cloud console and someone's memory. That gap is where breaches start: an acquisition's 400 unaudited hosts, a contractor's credential in a breach dump. Nothing outside the inventory gets scanned, patched or monitored.

Your EDR knows the endpoints it's installed on. Your scanner knows the subnets it was pointed at. Your patch tool knows the machines it manages. Each holds a piece, and nobody holds the picture.

[ What Kervo AI does here ]

What Kervo AI does here

Give Kervo AI your domains, read-only cloud access and API keys for the tools you already run. From the outside, it enumerates subdomains, fingerprints services and finds forgotten infrastructure. From the inside, it pulls hosts, servers, endpoints and network devices from your EDR (CrowdStrike, Microsoft Defender, Palo Alto Cortex XDR, Sophos), your vulnerability scanners (Nessus, Rapid7, OpenVAS) and your patch management tools, alongside the asset graph from AWS, Azure and GCP. The built-in network scanner finds the devices none of them manage.

The output is one deduplicated inventory with every relationship mapped: the same server seen by your EDR, your scanner and your cloud account becomes one asset. Everything is cross-referenced against dark web sources and your vendor list, and new subdomains, open ports, unmanaged devices and newly public workloads are flagged within the hour.

[ Capabilities ]4 in this stage
01

Asset Discovery (CAASM)

The inventory underneath all of Know. Kervo AI connects to your EDR, vulnerability scanners, patch management, identity provider and cloud accounts, and runs its own network scanner, to find every host, server, endpoint, network device, container, application and identity. The same machine reported by five tools becomes one asset, with its owner, patch state and relationships mapped and kept current. Tag criticality here and Evaluate ranks by blast radius.

02

External Attack Surface Management (EASM)

Continuous discovery of everything facing the internet: subdomains, IP ranges, cloud endpoints, API gateways, acquired infrastructure. Each asset is fingerprinted for version, known CVEs and certificate validity.

03

Dark Web Monitoring

Breach dumps, paste sites, criminal marketplaces, ransomware leak pages and threat-actor channels, watched for your domains, brand and executives. Findings arrive with the account, the source and an attribution.

04

Third-Party Risk Management (TPRM)

Outside-in monitoring of your vendors' real posture, with no questionnaires. A vendor whose posture degrades in March does not stay approved until January.

[ How it works ]

How it works

Discovery runs from the outside in and from the inside out. From outside, passive DNS, certificate transparency, WHOIS and OSINT build the external map without touching your infrastructure, followed by lightweight, rate-limited probing of what's found. From inside, read-only API connections pull assets from your cloud accounts, identity provider, EDR, vulnerability scanners and patch management tools. The built-in network scanner then covers the devices none of them see, such as switches, firewalls, printers and unmanaged hosts.

All of it feeds one data model, so a leaked credential correlates with the identity it belongs to, the laptop that identity signs in from and the servers that laptop can reach.

[ Where it sits in the loop ]

Where it sits in the loop

Know produces the complete picture. It does not tell you what to worry about. Evaluate works out which few findings matter, ranks them by what an attacker can reach, and assembles them into attack paths.

[ FAQ ]Know
What if we don't have a complete asset list?

That is the assumption. You provide seed domains, cloud credentials and API access to the tools you already run, and Kervo AI builds the inventory. Teams routinely find 20 to 40% more internet-facing assets than they had on record, and internal devices that no single tool was tracking.

Which tools can Kervo AI pull assets from?

EDR and XDR platforms such as CrowdStrike, Microsoft Defender, Palo Alto Cortex XDR and Sophos. Vulnerability scanners such as Nessus, Rapid7 and OpenVAS. Patch management tools, your identity provider, and AWS, Azure, Google Cloud and Oracle Cloud. The built-in network scanner covers devices none of them manage. See the full integrations list.

Does discovery require agents?

No new agents. External discovery is largely passive, cloud accounts and your existing tools connect through read-only APIs, and the built-in scanner covers the rest of the network. If you already run an EDR, Kervo AI reads from the agents you have.

How long until we see our full attack surface?

First findings within hours. A complete picture across external, cloud, endpoints and network within 48 hours of connecting.

What permissions does Kervo AI need on our cloud accounts?

Read-only, least privilege. Kervo AI never modifies your configuration, and the permission sets are documented and reviewable before you grant anything.

How is dark web monitoring different from a breach-notification service?

A breach service says an address appeared in a dump. Kervo AI says which employee, what the account reaches, and whether the credential is being sold.

[ The whole loop ]
Get started

See what's actually exposed.

We run discovery against your real domains, cloud accounts and the tools you already run, and walk you through what comes back, including the assets you didn't know about.