DNS Footprint
Complete DNS visibility: domains, every resolving subdomain, the full record inventory, and change tracking between assessments.
Namespace Command is an enterprise External Attack Surface Management and security-operations platform. It continuously discovers, monitors, analyses, and governs your entire internet-facing estate, from an external attacker's perspective, with nothing to install and no access to your environment.
It closes the four gaps every estate carries: assets nobody knew existed, findings nobody owns, evidence nobody is continuously collecting, and incidents that should have been prevented.
Illustrative render of the Klarvant Namespace Command experience. Klarvant does not publish screenshots of the live platform; this visualisation conveys the structure of the interface without exposing customer data or production UI.
By role
Five seats, one digital estate. Pick yours.
CISO / Head of Security
Klarvant turns the discoverable external estate into a governed asset list with owners, an A to F posture rating across six categories, and clear remediation paths. Risk concentration is explained by root cause, not just ranked by severity, so you can show the board where the systemic gaps are and where the next pound of investment belongs. Findings that matter, finished, and a posture trend you can defend quarter on quarter.
See it in a demoGRC / Compliance
Controls are evaluated automatically against your real asset data, not a questionnaire, and scored pass, fail, or warning. The same control satisfies requirements across NIST CSF, ISO 27001, SOC 2, CIS Controls, HIPAA, and GDPR, so evidence is collected once. Thirty-day drift analysis surfaces regression before the auditor does.
See it in a demoSecOps / IT Operations
Discovery starts at onboarding with zero integration. Each finding carries severity, root cause, and the asset it belongs to. Less time hunting for what is yours, more time fixing what is broken.
See it in a demoBrand / Legal Counsel
The brand surface is part of the asset graph, not a separate tool. Trademark and impersonation findings sit alongside certificate and DNS issues, governed under the same ownership model and resolved through the same workflow.
See it in a demoM&A / Corporate Development
Klarvant maps a target's external footprint without engaging them, including third-party dependencies and supplier chains. Better-informed transactions, fewer post-close surprises, a defensible record of what was assessed at signing.
See it in a demoDiscover
Discovery is fully external and needs nothing installed. Every surface is monitored continuously, with historical comparison between assessments, so you see exactly what changed.
Complete DNS visibility: domains, every resolving subdomain, the full record inventory, and change tracking between assessments.
The whole certificate estate, every TLS endpoint, expiry forecasting, and post-quantum readiness, including certificates issued but not yet deployed.
Sender-authentication posture across SPF, DMARC, and DKIM, plus mail-server transport security per host.
Complete IP inventory with geolocation, network-operator distribution, and an interactive endpoint map.
Page inventory with security-header analysis, look-alike grouping, third-party script checks, and technology detection.
Brand-threat intelligence: shadow assets, impersonation and phishing, a claim-and-approve workflow, and professional takedown support.
Supplier inventory and dependency graph with concentration analysis and change-impact monitoring.
Data-residency mapping: jurisdiction, endpoint geography, cloud-region usage, and cross-border data flows.
Detected-technology inventory with version tracking for vulnerability assessment and change monitoring over time.
Digital twin
The digital twin shows interconnected assets, dependency chains, and blast radius, making invisible risk visible.
Interactive visualisation
Drag to rotate · Scroll to zoom
13
Organisation domains
.com, .uk, .de, .jp, .cn, .au, .sg, .za, .eg, .co, .br, .in, .ca
14
Supplier dependencies
AWS, Azure, GCP, Cloudflare, Akamai, Oracle, and more
3
Suppliers in simulated outage
AWS US-East, Azure, OVH affected
Illustrative visualisation with example data.
Explore the digital twin simulationHow risk is scored
Every domain, organisational unit, and organisation gets a letter grade, rolled up from six categories so a parent domain reflects everything beneath it.
The posture rating in Klarvant Namespace Command.
DNS, TLS, Email, Web, Network, and Accountability. Each yields a 0 to 100 score that rolls up into an A to F grade.
Open findings reduce the relevant scores in proportion to severity, and a serious condition, such as an expired certificate, caps the final grade.
Findings map to seven strategic root causes, so the platform reports not just what is wrong but why a whole category keeps recurring.
See it in action
How findings trend over time, and how the platform turns them into a posture score and a prioritised queue.
Scale
7B+
Identifiers mapped across the corpus
180+
Defined finding types, each with remediation guidance
90+
Security metrics captured per assessment
249
Countries supported across data-residency regions US, EU, UK
Reference figures from the live Namespace Command V4 platform.
Continuous compliance
Map the estate to the frameworks you answer to, and the platform keeps the evidence current between audits, not only at audit time.
Controls are checked automatically against your actual asset data and scored pass, fail, or warning. No questionnaires, no self-attestation.
The same control can satisfy requirements across several frameworks at once, so evidence is collected once and reused, not rebuilt for every audit.
Every failure pinpoints the specific assets responsible, and 30-day drift analysis surfaces a slipping posture before an auditor would.
The five-pillar lifecycle
Complete visibility. Prioritised action. Continuous compliance. Namespace Command runs the same five-stage lifecycle across your entire external estate, governed under one model. See how each stage works in depth.
See everything
Zero-integration discovery across nine discovery surfaces, including domains, certificates, email, suppliers, and brand exposure. Results from day 1.
Find the gaps
Findings are detected and classified automatically after each assessment, then tracked through a full lifecycle with a complete audit trail.
Understand risk
Thirteen specialist AI areas and the personal advisor, Nora, turn findings into plain-language briefings and root-cause insight.
Create accountability
Assign verified owners to every zone, set standards and thresholds, and drive remediation, so nothing sits unowned.
Prove it
Controls are evaluated continuously against real asset data across six frameworks plus custom, with audit-ready evidence.
FAQ
Nothing to install: no agents, no API keys, no privileged access. Discovery works entirely from publicly observable data, such as DNS, certificate transparency, WHOIS, and web content, so there is no integration overhead and no access into your environment.
Discovery begins immediately at onboarding, with results from day 1. Time to a first complete snapshot scales with the size of your namespace, not the complexity of setup: no configuration, no vendor participation, no setup delay.
Nine discovery surfaces: DNS, certificates, email security, IP intelligence, web surface, external discovery (brand), third-party suppliers, digital sovereignty, and technologies.
NIST CSF, ISO 27001, SOC 2, CIS Controls, HIPAA, and GDPR, plus customer-defined custom frameworks. Controls are evaluated automatically against your real asset data.
CISOs and security leadership, GRC and compliance teams, SecOps and IT operations, brand and legal counsel, and M&A teams running pre-deal due diligence.
Data-residency options are available for the US, EU, and UK to meet regulatory and sovereignty requirements.