h0SINT maps everything your organisation has reachable from the internet, works out which parts actually matter, and writes it up as a report you can defend. Self-hosted — your asset inventory never leaves your network.
The gap between what you think is exposed and what an attacker can actually reach is where breaches start.
One pipeline. Every step leaves evidence behind, so any claim in the output traces back to the thing that produced it.
Maps the estate and synthesizes scan, exploit and infrastructure data into a draft.
Confirm what is real, teach it the false positives. It remembers both.
Adversarial fact-checking removes what the evidence does not support.
A grader marks the report against its own evidence and sends it back until it holds.
PDF, HTML, or straight into Google Docs and Slides.
Overnight it re-checks every domain you track and connects them to each other — shared hosting, reused certificates and repeat problems surface without anyone asking. Anything it infers is checked before it is trusted.
Three screens do most of the work. The rest is documented screen by screen.

DNS, IPs, ports, URLs, vulnerabilities and the technology behind them — beside a severity breakdown and the workflow rail that carries it to a finished report.

Findings are scored on whether an exploit exists and is being used in the wild — not on a raw severity number alone. Mark a false positive once and it stays marked.

Shared IPs, ASNs, certificates and technologies surface the links between the domains you own — the exposure a single-domain scan can never show you.
14 scans of h0sint.com over 21 days, through the same passive pipeline the free scan runs. Every number here came out of the tool, and the findings it raised against us were fixed and re-verified externally.
Assets tracked per scan. The dips are not the estate shrinking — they are scans that covered less. We show them unsmoothed, because “absent from a scan” and “gone from the internet” are different claims, and conflating them is how a scanner ends up lying to you.
Real passive reconnaissance, run live from public sources. Nothing is touched on your systems and nothing is stored — the result is computed for this page and forgotten when you close it.
Every engagement starts with a conversation. I scope it against your actual estate, and I tell you straight if it is not worth doing.
A full scan of your external estate, then the part that matters: I triage every finding by hand, remove what is noise, and write it up so it survives review. You get the deliverable, not raw tool output.
We run it side by side. Calls where we scan your estate live, I explain what each finding means and how it was reached, and we review the results together — so your team leaves understanding their exposure and the tradecraft, not just holding a PDF.
The platform, self-hosted on your infrastructure, with an annual licence. Your data never leaves your network. Guided installation and a walkthrough for whoever will own it; you run it on your own terms.
Indicative starting points. Final scope and price depend on the size of your estate — we agree both before anything runs.
Which domains you care about, what you are trying to find out, and any deadline. I read every message and reply to every serious one.
Passive reconnaissance only · EU-hosted · nothing active runs without your written authorization.