# unexplained traffic in the perimeter log. who is this? $ dig +short -x 48.206.21.101 scan-07.aevyrascan.com. $ curl -s https://aevyrascan.com/ips.txt # AevyraScan egress addresses # One address per line. Comment lines begin with #. 48.206.21.96/28 48.206.152.144/28
Aevyra maps what your organisation exposes to the internet. It scans from published addresses, names itself in every request, and shows the evidence behind each finding — so your team can check the work instead of taking it on trust.
What you get
Every asset records how it was discovered and which engagement it belongs to. A host found three ways is one asset with three pieces of evidence, not three findings.
Each score is built from signed evidence, and you can see what it was built from. Two sources that repeat the same fact count once — a correlation is not a confirmation.
Every request carries AevyraScan/1.0 and a link to the
page listing every address we scan from. If your team sees us, they
can identify us in one lookup — without calling anyone.
How it behaves
Discovery is passive by default. Anything that touches a client's systems harder than a normal request — port scanning, vulnerability checks — needs both gates open, and either one closes it.
Where your data goes
Callbacks from out-of-band checks land on infrastructure we run, not a public collector. Address geolocation happens inside our own network. This page loads no fonts, no analytics and no scripts from anyone else — the same rule the whole platform follows, and one you can verify by reading the source of what you are looking at.
Talk to us
Engagements start with a scoping conversation: which organisations are in scope, what you have already assessed, and what you would want us to leave alone.
hello@aevyra.io