Product · how it works

Everything between your domain and the evidence.

No agents, no code changes, no traffic re-routing. Origin works entirely from the outside — the same vantage point an attacker has, and the same one your customer’s reviewer cares about.

01 · Verify & discover

Prove the domain once. Origin finds the rest.

Add one DNS TXT record to prove ownership. From the apex, Origin enumerates subdomains and probes what’s live — building an asset inventory with first-seen and last-seen dates that updates itself on every scan.

Asset inventory — acme-software.co.uk
www.acme-software.co.uklive · https · first seen Feb 2026
api.acme-software.co.uklive · OpenAPI imported
staging.acme-software.co.uknew · found Tue 02:00
docs.acme-software.co.uklive · static
+ 10 morewatched weekly
02 · Check

Safe, deterministic checks — built on proven scanners.

Origin orchestrates respected open-source engines behind one calm findings model, with rate limits and exclusions you control. We don’t invent detection; we make it usable and provable.

CheckWhat it catchesEngine
TLS & certificates
Expiring or misissued certificates, weak protocols and signature algorithms, chain problems your customers' browsers will reject.
nuclei · httpx
DNS posture
Missing SPF, DMARC and CAA records — the gaps that allow email spoofing in your company's name and uncontrolled certificate issuance.
dns_posture
HTTP surface
Missing security headers, version disclosure, exposed admin panels and services that shouldn't face the internet.
httpx · nuclei
Web application
Templated vulnerability checks across your public pages — known CVEs, misconfigurations, exposed files and takeover-able subdomains.
nuclei
API
Import your OpenAPI definition and Origin tests the endpoints you actually expose — safe mode by default, active rules only on scopes you approve.
OWASP ZAP
Scan profiles

Three depths, on whatever cadence suits you.

baseline

The weekly heartbeat

TLS, DNS posture, headers and HTTP surface across every verified asset. Fast, safe, and the backbone of your evidence history.

api

Your API, by its own spec

ZAP-driven checks against the endpoints in your imported OpenAPI definition. Safe mode by default; active rules per approved scope.

deep

The quarterly sweep

Everything in baseline and api, plus the fuller nuclei template set. Slower, still rate-limited, scheduled when it suits you.

03 · Triage, on the record

Every decision has an owner and a reason.

Findings move through a real workflow — and every step lands in the append-only audit log, so the story your evidence pack tells is complete.

open

A finding arrives, assigned to whoever owns the fix

Assign teammates, filter by severity or asset, share the exact view by URL. Viewers (your client contact, your assessor) see everything and can change nothing.

accept

Accept a risk — with a written reason

Some findings are known trade-offs. Accepting one requires a reason, records who decided, and keeps it visible in evidence rather than swept away.

supprs.

Suppress a false positive, accountably

Suppression also requires a reason and an author. It drops out of the default view, never out of the record — and you can reopen it any time.

resolve

Fix it, re-scan, and the pack updates itself

The next scheduled scan confirms the fix; the finding's timeline shows open → assigned → resolved with dates. That's the line your reviewer wants to see.

04 · Prove

The evidence pack: built to be forwarded.

Human-readable on top.

Scope, checks performed, findings and their status, scan history — written so a non-specialist reviewer can follow it without a walkthrough.

Machine-verifiable underneath.

An HMAC-SHA256-signed manifest covers every artefact in the bundle. Your reviewer verifies it offline — no Origin account, no trust in us required.

Honest about its limits.

Each pack states exactly what was checked and what wasn’t. Automated external checks are not a penetration test, and your pack never pretends they are.

See it on your own domain.

One DNS record. First findings within the hour.