From signup to your first findings
This is the whole of your first session: about ten minutes of your attention, then a wait.
1. Create your account
Sign up with your work e-mail. Personal addresses are refused, because a workspace belongs to a company and the domain is how colleagues join it later. Our team reviews each new account before it is switched on. See Signing up for the steps and for what to do if the code doesn't arrive.
2. Add your domain
After you sign in, the home page shows an empty asset card. Press Add Asset to open setup at the assets step, or use Finish setting up if you see that banner.
Add your organisation's main domain. One is enough to start with. Adding ten at once makes the first results harder to read, not richer.
3. Nothing to press
Discovery starts as soon as the domain is saved. Adding your website in the organisation step or adding assets starts the first scan. There is no "Start scan" button, and a nearly empty screen in the first minute doesn't mean anything failed.
4. What arrives, and when
The first scan is a quick, passive one, and its first results appear within minutes. It looks at your domain's DNS and mail set-up, its certificates and what is publicly known about it. Deeper checks take longer: subdomains and hosts, exposed code and secrets, leaked credentials and lookalike domains. How much of that runs depends on your plan.
Findings keep arriving after the first ones appear. A number that grows while you watch means the scan is working, not counting things twice.
5. Your first look
Start on Attack Surface → Overview. Two things are worth your attention on day zero, and the rest can wait:
- The inventory. Hosts and subdomains you did not know existed. This is the part that is almost always new information, even for teams who feel on top of their estate.
- Exposures. Ranked by what one fix closes, not by raw severity — so the top row is usually the best use of an afternoon.
Expect a few hundred findings on a first scan of a real estate. That is normal and is not a judgement about you. What matters next is which ones are real and which matter, and that is the next guide: Reading your first results.
What you will not see yet
Some checks are listed but locked on the free plan — port scanning, service detection and the deep analysis passes. They are shown rather than hidden on purpose: you should be able to see what has not been examined. A quiet result from a check that never ran is not a clean bill of health.
See Plans, credits and limits.
If nothing appears at all
- Check the domain on your asset list is spelled as you expect.
- Give it thirty minutes — some sources are slow.
- Check coverage before concluding you are clean. "We found nothing" and "we could not look" are different answers, and the difference matters more than anything else on the page. See Coverage honesty.