For organisations that want to know what is actually exposed
Vulnerability scan: continuous and from the outside
A certificate tells you what is arranged on paper. A vulnerability scan measures what is actually exposed to the internet today: open ports, expired certificates, known vulnerabilities and forgotten subdomains.
What is a vulnerability scan?
A vulnerability scan is an automated examination that compares systems against databases of known vulnerabilities (CVEs) and misconfigurations. Vulnerability scans come in internal and external variants; Exposentry measures externally, from the internet, because that is where an attacker starts: domains and subdomains, open ports, certificates, email records and version information of internet-facing software.
Exposentry runs that scan continuously on OpenKAT, the open-source security scanner developed within the Dutch government; founder Edward Hasekamp contributes to that project. Findings are compiled into a monthly report, written in Dutch, with an explanation and concrete remediation steps for each finding, digitally sealed and independently verifiable.
How the Exposentry vulnerability scan works
1. Sign up and verify your domain
You sign up online and prove domain ownership via a DNS record or a file on your website. Nothing is installed and nobody gets access to your systems.
2. Mapping the attack surface
The scanner first maps what your organisation exposes to the internet, including subdomains and services that were long forgotten internally.
3. Continuous scanning
Everything found is continuously checked against known vulnerabilities and misconfigurations. New systems and new vulnerabilities are picked up automatically.
4. Monthly sealed report
You receive a monthly report with an explanation and remediation steps per finding, digitally sealed with a timestamp, so you can verify the report has not changed since it was created.
A scan is not a penetration test
A penetration test is in-depth manual testing at a single point in time, within an agreed scope. A vulnerability scan is broader, automated and continuous. The two complement each other: the scan keeps the basics demonstrably in order and shows where deep testing adds value.
Independent measurement, delivered directly to you
Exposentry does not sell remediation services for its findings and therefore has no stake in the outcome of the scan. Reports go directly to you and are not shared with third parties.
Frequently asked questions
What does a vulnerability scan cost?
Professionally executed one-off scans with reporting quickly cost several hundred euros each on the market; with manual interpretation added, prices move towards penetration-test rates of thousands of euros. Exposentry works continuously: a one-off baseline scan costs €495 and continuous monitoring starts at €249 per month, available online without a sales call. Switch to an annual plan within 60 days of the baseline and the full amount is credited.
How is this different from a penetration test?
A penetration test is manual, deep and point-in-time; a vulnerability scan is automated, broad and continuous. For the price of one penetration test per year, Exposentry continuously monitors your external attack surface. The knowledge base explains when to use which.
How often should you run a vulnerability scan?
More often than most organisations do. Tens of thousands of new vulnerabilities appear every year and your own environment keeps changing. The Dutch NCSC therefore describes vulnerability management as a continuous process; an annual scan leaves blind spots for months on end.
Is a vulnerability scan mandatory under NIS2?
No. NIS2 and the Dutch Cyberbeveiligingswet, in force since 15 August 2026, do not mandate any tool or scan by name. The law requires appropriate measures you can demonstrate; a continuous scan is a demonstrable building block. The knowledge base covers exactly how this works.
Is there a free vulnerability scan?
Yes, as a first impression. The free Exposentry security scan measures what your domain publicly exposes based on public sources, and emails you the result. A full vulnerability scan scans actively, looks deeper and monitors continuously.
Try the free security scan →Want to know what is exposed today?
Start with a one-off baseline scan for €495, or choose continuous monitoring from €249 per month. Signing up and verifying your domain takes minutes; the first scan can run the same day.
Start a scanPrefer to run OpenKAT yourself, or need custom work? Hasecon provides implementation, management and custom development →