Worth being precise, because this category is full of vague claims and you will find out the truth in your first week anyway.
There is no certificate-transparency mining or DNS brute-forcing in the product today. It monitors the scope you define. If discovering forgotten hostnames you have never heard of is your primary requirement, Umbra does not solve that yet, and we would rather tell you now than have you discover it after signing.
What it does instead is go deeper on what you do know about: a full port sweep and proven exploitation beats a longer list of hostnames nobody validated.
Version-matching produces volume, and volume is where security programs go to die. Umbra treats a CVE match as a candidate: something to go and test, not something to hand you.
The agent fires the exploit against the live service and keeps the request and response. What reaches your queue is the subset that worked, with the proof attached — see{" "} exploit validation {" "} for how a candidate becomes a finding, and how often it doesn't.
Plans include an asset allowance, but scanning is not metered — cadence is yours to set, and re-testing a finding we already reported is free and never counted. You are not billed per scan, per port, or per finding. Deep Audits and Checks are the two counted units, and{" "} the pricing page {" "} says exactly what each plan includes.
Discovery, fingerprinting and CVE matching on the free tier. No card.
Part of{" "} continuous security validation {" "} — discover, prove, fix, re-test.