Clay model of a mapped attack surface with one rust-colored exposed asset

Every way in, mapped. The ones that matter, proven.

Agents attribute your external surface from public trails, not from a list you supply. An operator decides what is worth attacking, and proves it.

The challenge

Three shifts happened at once, and none of them wait.

Clay blocks expanding outward from an infrastructure model
01

Attack surface is expanding rapidly as organizations adopt AI

Do you know how your attack surface looks to an AI attacker?

Where this is going

AI is already attacking infrastructure at scale, and it does not wait for your review cycle.

200,000

API requests in two minutes, from one AI-driven campaign.

89 %

More attacks from AI-enabled adversaries than a year earlier.

−7 days

Mean time to exploit. The exploit now arrives before the patch.

The engagement, end to end

Four use cases, one continuous engagement.

Agents run the sweep. A person runs the proof.

Use case 01Discover

Find what you never listed

Domains, cloud edges, web applications, APIs, repositories outside your org, the vendors you depend on, and the agent endpoints nobody inventoried. Every asset attributed from registration, certificate and infrastructure trails—not from a list you supply.

Read more the full asset catalogue

Asset catalogue

Continuous
889assets attributed, none supplied

Domains & subdomains412

Vendor dependencies204

Cloud edges118

APIs63

Web applications46

Repositories outside the org37

Agent endpoints9

Registration, certificate & infra trails+31 this week

Verified attack path

5 hops
*.acme.comsurface
ci-runner-11verified
ghp_••••write access
prod-artifactsreached
verified hopdroppedproduction reached
Chained by an operatorProduction reached

Use case 02Attack & prove

Proof, not probability

Secrets tested against live authentication. APIs fuzzed for the authorisation they forgot. New CVEs matched to your actual stack, then exploited to prove reach. An operator chains the findings until something touches production.

Read more how findings are validated

Use case 03Intelligence

Your exposure isn’t only your infrastructure

Credentials traded in breach dumps and infostealer logs, matched against logins that still accept them. Breaches at your suppliers, scoped to what reaches your systems. Domains staged to impersonate you.

Read more intelligence sources

Exposure intelligence

3 sources
Breach dumps & infostealer logsLive

41 acme.com addresses, 9 in plaintext

One pair still accepted by vpn-gw.legacy

Supplier breach — Northbridge LtdScoped

Scoped to what reaches your systems

2 of 14 integrations hold write scope

Lookalike domainsWatched

acme-billing.co registered 6 days ago

MX configured, no mail sent yet

Credentials, suppliers, impersonationChecked hourly

March report

4 pages
9Newly exposed
5Closed
1Reached
15 weeksSurface up 41%

Staging balancer answered on 443

V-02 closed, token rotated

9 new subdomains entered the survey

Anything critical reaches you the day it is proven

Use case 04Change

Know what changed about you

Every month: what you now expose that you didn’t, what closed, and what an operator reached in between. The report is the record—anything critical reaches you the day it’s proven.

Read more a sample report

Cylent Labs

What we found, written down.

Field notes from live engagements, the methods behind them, and the numbers we can share.

Clay security nodes surrounding exposed source code

Jun 2026 / Case study12 min

Shadow Code: an AI built the backdoor. Another AI found it.

Read
Clay blocks tracing a CI supply-chain attack path

May 2026 / Case study11 min

One pull request to own the supply chain

Read
Cutaway clay model of an exposed monitoring system

May 2026 / Case study10 min

No login required: a Grafana that hands out database credentials

Read
Clay model of a public sign-up path leading into protected data

May 2026 / Case study10 min

One sign-up form away: anonymous to full recon

Read
Clay package blocks sharing one dependency name across two registries

Q1 2026 / Case study9 min

We published the package they forgot to reserve

Read
All writing Published as findings close — no cadence, no newsletter