External + internal attack surface, on one graph
Lens shows how an open port the internet can see reaches the exact internal application behind it — the full outside-in path on one live security graph. A complete EASM platform with its own external scanner built in, it unifies the scanners you already run, scores everything with one Lens Risk Score, and surfaces shadow AI no one registered.
From open port to the app behind it
Lens unifies external and internal surface on one graph and scores risk where it matters.
- 1
Discover
Find exposed hosts, services and shadow IT with the built-in external scanner, and pull in the scanners you already run.
- 2
Map
Draw external and internal surface onto one live security graph — and trace each open port to the exact internal app behind it.
- 3
Prioritize
Score everything with one Lens Risk Score, propagated by blast radius, so the next fix is the one that matters.
The attack surface, on a live graph.
Lens resolves your external footprint onto a navigable graph, flags shadow AI and exposed services, and scores each finding by blast radius — so the next fix is the one that actually matters.
What it does
Outside-in path mapping
See how an externally visible open port reaches the exact internal application or service behind it — the full outside-in path, drawn on one live security graph.
Complete EASM, built-in scanner
Everything an EASM platform should have, with its own external scanner included — bring your own vulnerability scanner if you prefer, and run the EASM standalone.
Unifies your scanners
Pull Tenable Nessus, Qualys, Recorded Future and the tools you already run into one external-and-internal picture, instead of a stack of disconnected consoles.
AI & shadow-AI exposure
Discover self-hosted model servers (Ollama, vLLM, LM Studio), MCP servers and AI agents — then flag the ones exposed, unauthenticated or running a vulnerable runtime.
Lens Risk Score (LRS)
One 0–100 score blends CVSS, EPSS, KEV and internet-reachability — propagated across the graph by blast radius, not raw CVE counts.
Why teams run Lens
- ✓ Trace an internet-facing open port straight to the exact internal application behind it, on one graph.
- ✓ Run a complete EASM with its own scanner, or bring your own and sell it standalone.
- ✓ Unify Tenable Nessus, Qualys, Recorded Future and your other tools into one external-and-internal view.
- ✓ Surface the shadow AI nobody registered — exposed model servers, MCP endpoints and over-privileged agents.
- ✓ Prioritize by one Lens Risk Score and business blast radius, not raw CVE counts.
Attack surface
last 24hSee Seraxi on your environment.
Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.