Precision intelligence for the internet

We don't list the web. We read it.

See who's running what, who's exposed, and who to hit next — with the receipt behind every finding. One read for the people who sell and the people who secure.

See any company's stack in seconds — no signup. Or book a live scan →

Live readevidence on every findingglobal

overt · live profile sample data
Borowik Logistyka S.A. borowik-logistyka.pl · Warsaw 142 M zł revenue · 380 employees
  • Akamai CDN conf 95%
    www → CNAME → e8113.x.akamaiedge.net
  • No bot defence behind the CDN gap · play
    absence of challenge / JS-detection headers
  • DMARC policy p=none conf 98%
    TXT "v=DMARC1; p=none"
11 signal layers fused verified 2 days ago

What is Overt?

Overt is company intelligence you can prove.

One engine reads every company's public footprint — technology stack, security posture, attack surface, hiring, financials and change history — from evidence, scores it, and shows the exact signal behind every finding. That same fused read is packaged into whichever instrument your team works in: Prospect for go-to-market, Monitor for risk, Signal for your API and CRM.

Turn on the editions, seats and signal layers a workspace needs, and nothing it doesn't.

The evidence engine

Watch it read a company.

Point Overt at any domain and its public footprint resolves in seconds — every signal pulled from evidence, scored for confidence, and fused into one profile you can defend. Sample company, synthetic data.

The enemy

Lookups are a museum.

BuiltWith and Wappalyzer answer one question — what's installed — then stop. No row tells you who to approach, why they're in play now, or what to do about it. A frozen exhibit, not a working tool.

A directory isn't intelligence. That's where Overt starts.

Evidence

Every finding ships with its receipt.

This is what Overt knows about a company — and how it knows it. The CNAME, the header, the record, the date. Sample data, real mechanics.

finding 01 · cdnconfidence 95%
Akamai CDN
www.borowik-logistyka.pl
  → CNAME → e8113.x.akamaiedge.net
The CNAME chain is the receipt. Your rep can quote it.
finding 02 · gapplay
No bot protection detected behind the CDN
DMARC policy: p=none confidence 98%
TXT "v=DMARC1; p=none"
Overt reads gaps from the absence of signals, then scores them into plays for the vendor lines you carry — configured with you at onboarding.
accountsample data
Borowik Logistics S.A.
revenue 142 mln zł · 380 employees · Warsaw
Findings join to national-registry financials, so priority reflects deal size, not just tech.

When Overt isn't sure, the finding says so — a low-confidence detection ships with a low confidence score, not a confident guess.

Worldwide company surfaces mapped on demand, in any market
7 days maximum age of any company profile under watch
11 signal layers fused into one evidence-backed profile
1,000+ technologies detected — each with the receipt

The stack we read.
All of it.

Overt fingerprints 1,000+ technologies across every layer of a company's public footprint — and shows the exact signal behind each one. A sample of what it detects:

CDN & edge

  • Cloudflare
  • Akamai
  • Fastly
  • Amazon CloudFront
  • Azure Front Door
  • Google Cloud CDN

WAF, bot & DDoS

  • AWS WAF
  • Imperva
  • F5 BIG-IP
  • Akamai Bot Manager
  • DataDome
  • Cloudflare Bot Mgmt

Identity & access

  • Okta
  • Auth0
  • Microsoft Entra
  • Ping
  • ForgeRock
  • JumpCloud

Email security

  • Proofpoint
  • Mimecast
  • Microsoft Defender
  • Google Workspace
  • Barracuda
  • DMARC / SPF / DKIM

Cloud & hosting

  • AWS
  • Google Cloud
  • Microsoft Azure
  • Alibaba Cloud
  • DigitalOcean
  • Vercel

MarTech & analytics

  • Google Analytics
  • Adobe Analytics
  • Segment
  • HubSpot
  • Marketo
  • Amplitude

Observability & DevOps

  • Datadog
  • New Relic
  • Sentry
  • Dynatrace
  • GitHub
  • GitLab

Commerce & CMS

  • Shopify
  • WordPress
  • Adobe Experience Mgr
  • Magento
  • Salesforce Commerce
  • Contentful

…and hundreds more across appsec, CCaaS, CDP, consent, data platforms, e-sign, ERP, feature flags, payments and observability — re-verified continuously, never older than seven days.

market moves · sample
  • example-retail.pl removed Akamai Bot Manager
  • example-bank.pl added Imperva WAF
  • example-logistics.pl migrated CDN → Cloudflare
  • example-insurer.pl DMARC moved to p=reject
  • example-software.pl new SSO portal observed (Okta)
  • example-clinic.pl dropped reCAPTCHA
  • example-energy.pl exposed VPN gateway detected
  • example-uni.pl added Cloudflare Bot Management

How it works

  1. The corpus scans itself.

    299,000+ Polish domains re-verify on a continuous cycle; every scanned profile is under 7 days old. No crawl-then-export.

  2. Signals become scored plays.

    Headers, DNS records, certificates and registries resolve into findings with confidence scores, then into account priority.

  3. Your team works the list.

    Plays, company financials, change alerts. Export CSV, call the API, or work from the Chrome extension.

Comparison

They hand you a piece. We hand you the whole shot.

Wappalyzer and BuiltWith read the tech off a homepage. Overt reads the whole company — every subdomain, the CDN/WAF/DDoS posture, the registry financials, who's hiring, what they buy — and shows the receipt for every line. They give you a tech list; we give you the account, proven.

And signals the list vendors never attempt — BGP-level DDoS posture, buying-team geography, registry financials and hiring intent, each with the receipt.

Capability OvertTechnographics(BuiltWith / Wappalyzer)Sales intel(ZoomInfo)Security ratings(BitSight)
Technology stack ~·
Security posture grade ··
Attack surface & exposure ··
Company financials ·~·
Buying-team contacts ··
Change feed — the day it moves ··~
Evidence + confidence on every finding ···

✓ full  ·  ~ partial  ·  · not offered. Category comparison of typical capabilities, not a feature audit of any one release.

See the full comparison — Overt vs Wappalyzer, BuiltWith, ZoomInfo & BitSight

One engine

Three instruments.

The same fused read, packaged for the team that needs it — and priced on the unit that matches the value, not headcount alone.

Overt Prospect
01 Go-to-market

Overt Prospect

Find, score and work the accounts that fit your offer — every finding carrying the receipt that opens the conversation.

priced byseats + scan & enrichment credits

Overt Monitor
02 Security & third-party risk

Overt Monitor

Put a portfolio of accounts, vendors or competitors under continuous watch. Get the alert the day a posture grade slips or a stack changes.

priced byper monitored entity

Overt Signal
03 RevOps & data teams

Overt Signal

The enrichment endpoint, change-feed and native CRM sync — Overt's intelligence inside the tools you already run.

priced byusage-metered API · committed volume

Editions — turn on the signal layers a workspace needs:
  • Security & Channel
  • MarTech GTM
  • Infrastructure & Cloud
  • Risk / TPRM
  • RevOps / Data
  • Intelligence

Works with the tools you already run.

CSV export that imports clean into any CRM REST API with an OpenAPI spec Chrome extension that scores any site your team visits Webhook alerts into Slack, Teams or Google Chat

Enterprise & security

Built for the teams that get audited.

The same rigour we apply to reading a company's posture, we apply to our own. Governance, isolation and data rights are in the product today — not on a roadmap slide.

We read what's public. And we show our work.

Detection is passive — HTTP response headers, DNS records, certificate-transparency logs, public routing data and registries. No intrusion; active probing exists only as an opt-in check for targets you're authorized to assess. It runs on Cloudflare's network, with data stored in the EU. [DPA and sub-processor list available at signature.]

Roles & permissions

Four roles, ten granular permissions, enforced server-side on every request — not just hidden in the UI.

SSO & directory sync

SAML / OIDC single sign-on and SCIM provisioning, brokered through an enterprise identity layer.

Audit trail

Every member, key and billing action logged, tenant-scoped, and exportable for your reviews.

Tenant isolation

Strict per-workspace separation; a request can only ever read its own tenant — cross-tenant access is denied, not filtered.

Your data, on your terms

One-click workspace export (machine-readable) and permanent erasure — GDPR Article 20 and 17, built in.

Hardened by default

Content-Security-Policy, HSTS, signature-verified webhooks, per-tenant rate limits, and no third-party trackers on the app.

API & data feed

Scoped API keys, an OpenAPI contract, and change-feed webhooks to Slack, Teams or your warehouse.

EU-aware data handling

Company data is public-infrastructure signal, not personal data; corpus held in the EU, sub-processors disclosed.

Posture, stated plainly — GDPR-ready and data-minimised today; auth currently processed in the US (disclosed in our privacy policy), EU residency available on enterprise. SOC 2 is on the roadmap, and we'll say so honestly until it's signed — no badge theatre.

Questions buyers actually ask

Where does the data come from?

From what companies publish to the internet by operating there: response headers, DNS and email records, TLS certificates, routing announcements, public job boards, and official company registries. Nothing requires access to the target’s systems.

How accurate is it?

Accurate enough to show its work. Every finding carries the exact signal it was derived from and a confidence score; a CNAME match is treated differently from an HTML hint, and the score says so. When we’re not sure, you see that too.

Is this GDPR-safe?

Detection reads publicly observable infrastructure signals about companies, not individuals. Company records come from public registries. Contact enrichment inside the product uses licensed data providers. [A DPA and sub-processor list are available at signature.]

How global is the coverage?

Any public domain in the world can be scanned on demand, with the same evidence model. The always-fresh corpus layer goes deep market-by-market — the first market is live today, and the expansion sequence is being set with early-access partners.

How is this different from BuiltWith or Wappalyzer?

They profile technologies. Overt is built for one buyer: security sellers. It scores accounts into displacement plays, attaches the evidence, joins company financials, and alerts on change — the work between “what they run” and “what you say in the first email.”

What does it cost?

Pricing is being set with founding customers, and we’ll state it plainly on the call — no quote theater. Early-access teams get founding terms.

What happens on the live scan?

You bring 10–20 accounts you actually work. We run Overt on them live and walk through the findings, plays and evidence together. If the data doesn’t earn the next meeting, that’s a useful answer too.

Book a live scan

See your territory the way Overt sees it.

Bring your accounts. Leave with findings you can quote.

Or read any company free, no signup — type a domain →

Early access · Poland-deep, EU-bound · Built by a security-channel sales team for security-channel sales teams

request · live scan20 min

We reply from a human inbox, usually same day.