wyrmsightClosed Beta

Know what your web apps actually connect to.

Every third-party script, tracker and API your pages load, watched every day, with an alert when something changes.

The vendors you approved load vendors you didn't.

Across 200 public sites we scan: 94 load Google Tag Manager, 74 end up connected to doubleclick.net, and 25 reach the ad exchange at rubiconproject.com. One site connects to 128 separate third-party domains.

The tags your teams install pull in a chain of others. That chain changes without a release, without a ticket, and without anyone telling your security team.

Server-side tooling cannot see it. It happens in your users' browsers.

How it works

  1. Step one

    We load your app in a real browser. Not a crawler, not an agent, not a tag you install. Nothing changes on your side.

  2. Step two

    We record every connection the page makes. The same thing you would see in the DevTools Network tab, captured and kept.

  3. Step three

    We do it again tomorrow, and tell you what changed. Across every app you add, not just the important one.

What you see

Connections

Every domain your applications talk to, per app and across your whole estate, first-party and third-party, with the resources behind each one.

Changes

New scripts, changed scripts, new connections, dated and diffed against yesterday.

Alerts

Notifications and a daily digest when something new shows up, including connections to domains on known-malicious threat feeds.

Exports

Every list exports to CSV. It's your data, to use however you want.

Who it's for

Security teams responsible for more web applications than they can watch by hand. If you have one site and you already know every script on it, you do not need this.

It tends to matter most to people who have been asked a question they could not answer from the code: what are we actually loading, when did that start, and who approved it.

About the beta

WyrmSight is in closed beta. It is free, participants are picked by hand, and it is early software: expect rough edges, no SLA, and the possibility that data gets reset. We ask participants to keep what they see to themselves while the beta runs.

Applying takes about two minutes and grants nothing on its own. If you are a fit we will email you when your access is ready.