Every step above is one we would want run against us, so here is where each lands.
Discovery starts from an apex domain and fans out into the estate you did not name —
Attack Surface Management does that work, and the evidence tying each asset back to your organisation sits on the
asset itself rather than being summarised into a number.
Validation is
Continuous Automated Red-Teaming. It answers the only question that changes what a team does on Monday — whether a
discovered exposure can actually be used — and it does that where it is safe and
authorised, against inventory already attributed to you, inside the scope agreed at
onboarding. Checks are non-destructive, and recovered credentials are reported so you
can revoke them rather than used to demonstrate access.
Removal is the third beat, and it forks on what is being removed. A
website takedown reaches the provider that holds the files; a
domain takedown is filed against the registration, which is a different counterparty with a different
evidence bar. Both end in one of a published set of states, refusals included, and the
provider directory names what each type of counterparty can actually remove — which is the form the
question above takes when you put it to whoever else you are evaluating.
The cheapest way to begin is not a trial at all. Ask for an
exposure snapshot: one apex domain, no call, and a written account of what is reachable from outside.
That tests the first of the three questions — is the picture correct — with no
procurement involvement, which is usually enough to decide whether a fourteen-day trial
is worth anyone’s fortnight.