Nine discovery surfaces
DNS, certificates, email security, IP intelligence, web surface, external discovery (brand), third-party suppliers, digital sovereignty, and technologies.
How it works
Interconnected risk demands interconnected visibility. Namespace Command takes you from zero visibility to governed, audit-ready compliance in one continuous loop, with zero-integration deployment.
Every organisation faces the same challenge: interconnected digital risk hiding in plain sight. The five stages guide you from uncertainty to control.
See everything
Submit your primary domains. Namespace Command autonomously discovers your entire internet-facing estate using zero-integration, agentless discovery. No credentials, no agents, no API keys.
Example input
example.com, example.co.uk, example.ioDNS, certificates, email security, IP intelligence, web surface, external discovery (brand), third-party suppliers, digital sovereignty, and technologies.
DNS, certificate transparency, WHOIS, SPF and DMARC, and more. Nothing installed, and no access into your environment.
Assets you never registered, surfaced, with historical comparison between every assessment. Results from day 1.
Find the gaps
After every assessment, findings are detected and classified automatically across all active assets, then tracked through a full lifecycle with a complete audit trail.
Expired or weak certificates, missing email authentication, outdated transport security, fragile DNS, and dangling records.
Each finding opens, can be assigned, acknowledged, and resolved or dismissed, with first-seen, last-seen, and recurrence all tracked.
Five severity levels and seven category buckets, across 200+ defined finding types, each with remediation guidance.
A findings dashboard with prioritised remediation queues, plus card, list and compact views, and an organisational findings map.
Understand why
A multi-agent AI layer runs after each assessment and turns raw findings into prioritised, plain-language intelligence.
Thirteen specialist AI areas produce per-domain briefings; the personal advisor, Nora, synthesises them into one briefing tailored to each user's role.
Findings map to seven strategic root causes, so you see why a whole category of issues recurs, not just the individual gaps.
A pre-built Ontology of the external digital ecosystem carries findings, assessments and ratings, with explicit provenance on every element. Dependency Signals adds CVE intelligence: newly published CVEs with KEV and EPSS exploitation context, matched against the technologies detected in the estate.
A rotatable 3D globe and impact simulation: what happens if a supplier, certificate, or DNS provider fails, and what the blast radius would be.
An A to F grade per domain, organisational unit, and organisation, rolled up across seven categories (DNS, TLS, Email, Web, Network, Accountability, Defensive).
Create ownership
Turn findings into accountability. Assign owners, set the standards you hold the estate to, and govern the cryptographic transition ahead.
Assign Owner, Technical, Security, and Manager roles to DNS zones with email-verified sign-off, suggested owners, an accountability map, and audit-ready coverage export.
Enable or disable control definitions, set per-organisation pass thresholds, and map controls to your compliance frameworks.
No-code Apps you assemble in the drag-and-drop App Composer act on findings under the same organisation-level isolation: opening a Jira ticket, posting to Slack, emailing the accountable owner, or raising a user-defined finding into the lifecycle. Every action is recorded in the App actions ledger. See Ontology and Apps.
Classify endpoints into cryptographic-risk tiers, set migration targets and deadlines, and track progress toward quantum-safe adoption.
Prove it
Keep the evidence current between audits, not only at audit time.
Controls are evaluated automatically against real asset data and scored pass, fail, warning, not-applicable, or pending. Failures pinpoint the assets responsible.
A prioritised remediation queue in card, list and compact views, so your team always knows what to work on next.
Point-in-time snapshots and 30-day drift analysis surface a slipping posture before an auditor would.
The compliance engine is framework-agnostic: continuous evidence against any framework, including customer-defined internal policy. NIST CSF, ISO 27001, SOC 2, CIS Controls, HIPAA and GDPR are recognised examples, not a ceiling.
Why this approach
No agents, API keys, or questionnaires. Submit domains and see results from day 1.
Thirteen specialist AI areas and the personal advisor, Nora, turn raw findings into prioritised, plain-language intelligence.
Your estate as an interconnected graph, with dependency mapping and blast-radius impact simulation.
An A to F grade across seven categories (DNS, TLS, Email, Web, Network, Accountability, Defensive), rolled up from domain to organisation.
Zone ownership, standards and pass thresholds, and post-quantum governance, in one model.
Prioritised remediation queues and root-cause analysis, so tactical fixes and strategic initiatives run in parallel.
From day 1
Time to first value
9
Discovery surfaces
13 + Nora
AI analysis areas
Zero
Agents or API keys
We run zero-integration discovery against the namespace you give us, with results from day 1. The demo opens on your real estate, not slideware.
Book a demo