1. What is Trust Monitor?
Trust Monitor helps organisations identify and monitor security exposures that may exist beyond traditional vulnerability scanning.
Using Open-Source Intelligence (OSINT), DNS analysis, passive discovery and continuous monitoring, Trust Monitor provides visibility into both trusted third-party services and external security exposures across the wider ecosystem that supports your applications.
It is comprised of two key capabilities:
Capability | Purpose |
Trusted Third-Party Services | Discover the external services your applications depend on and understand their level of access and influence. |
Security Exposure Discovery | Identify exposed credentials, misconfigurations and attack surface weaknesses that may sit outside a predefined scan scope. |
2. Why do organisations need Trust Monitor?
Traditional vulnerability scanning is highly effective at identifying security issues within applications and infrastructure that organisations own and manage.
However, modern applications often rely on a wide range of external services and providers, while security exposures can exist outside assets being actively scanned.
Examples include:
File storage and CDNs
Payment gateways
Analytics and marketing platforms
Social media integrations
Cloud-hosted services
SaaS platforms
Trust Monitor helps organisations gain visibility into these dependencies and uncover security exposures that may otherwise go unnoticed.
3. How does Trust Monitor work with AppCheck scanning?
AppCheck Scanning
Helps organisations:
Discover vulnerabilities in applications, APIs and infrastructure.
Assess weaknesses and prioritise remediation.
Continuously test owned assets.
Trust Monitor
Helps organisations:
Discover third-party dependencies and trusted services.
Identify exposed credentials and configuration weaknesses.
Detect subdomain takeover opportunities and cloud storage exposures.
Monitor for suspicious changes and newly emerging exposures.
Together
AppCheck Scanning answers:
"What vulnerabilities exist in the assets we own?"
Trust Monitor answers:
"What exposures exist across the services, assets and providers we depend on?"
Together they provide broader visibility across both the direct attack surface and the wider ecosystem supporting your applications.
4. How does Trust Monitor work?
Trust Monitor uses a combination of:
Open-Source Intelligence (OSINT) to identify publicly visible assets, services and exposures associated with your organisation.
DNS analysis to discover domains, subdomains and trust relationships.
Passive web discovery to identify third-party services, scripts and technologies used across your web estate.
Cloud and SaaS validation to identify common exposure and misconfiguration scenarios.
This approach enables Trust Monitor to uncover both trusted third-party relationships and external security exposures without requiring access to your applications or infrastructure.
Unlike traditional security scanners, Trust Monitor uses passive techniques and does not require credentials, cloud access or third-party integrations.
What information does Trust Monitor provide?
| Area | What it helps you do |
Trust Relationships | Understand which third-party services support your applications. |
Trust Levels | Identify services with the greatest level of influence over your applications. |
Vulnerabilities & Exposures | Discover exposed credentials, misconfigurations and infrastructure weaknesses. |
Change Monitoring | Detect newly discovered dependencies and significant ecosystem changes. |
Alerts & Notifications | Stay informed as new exposures and findings are identified. |
5. What types of security exposures can Trust Monitor identify?
Trust Monitor can identify a range of external security exposures, including:
Exposure Type | Description |
Exposed Secrets & Credentials | Exposed API keys, tokens and other credentials, with validation where possible. |
Cloud & SaaS Misconfigurations | Insecure configuration of cloud services and third-party platforms. |
Subdomain Takeover Opportunities | DNS configurations that could allow attackers to claim unused resources. |
Cloud Storage Exposure | Publicly accessible storage that may expose data or functionality. |
Indicators of Compromise | Suspicious changes that may warrant further investigation. |
Where possible, findings are accompanied by supporting evidence and remediation guidance.
How should these findings be used?
Trust Monitor findings are designed to complement traditional AppCheck scan results.
A typical workflow is:
Review newly discovered third-party services and dependencies.
Prioritise relationships with the highest trust levels.
Investigate any identified vulnerabilities or exposures.
Review unexpected changes and new dependencies.
Remediate exposed credentials, misconfigurations or takeover opportunities.
Enable alerting to identify new exposures as they emerge.
6. What are Trust Levels?
Trust Levels indicate how much access or influence a third-party service has over an application.
Generally, the greater the level of access, the greater the potential impact if that service is compromised.
Trust Level | Example | Why it matters |
| Low | External link | Users must actively leave your application to interact with the third party, limiting its influence over the user experience. |
| Medium | Third-party images or CSS | Can affect how content is displayed and may impact user trust if altered or compromised. |
| High | Embedded forms, payment widgets or iframes | Users interact with third-party content while remaining within your application. A compromise could affect sensitive transactions or data collection. |
| Highest | Third-party JavaScript | Executes within the user's browser with a high degree of access to application functionality and user interactions. A compromise could lead to data exposure, malicious content injection or account/session compromise. |
Trust Levels help organisations prioritise attention based on potential impact, allowing security teams to focus on the services with the greatest access to or influence over their applications.
7. What value does Trust Monitor provide?
Trust Monitor helps organisations:
Understand third-party dependencies and trust relationships.
Discover security exposures that may sit outside traditional scan scope.
Improve visibility across their web estate and insight into supply-chain exposure.
Support governance and compliance activities.
Continuously monitor for new exposures and ecosystem changes.
8. What is Trust Monitor not?
Trust Monitor is not:
❌ A replacement for AppCheck vulnerability scanning.
❌ A software composition analysis (SCA) solution.
❌ An attack surface management platform.
❌ A guarantee that third-party providers are secure.
❌ A compliance certification tool.
Trust Monitor is designed to complement AppCheck scanning by extending visibility into trusted services, external dependencies and security exposures.
Frequently Asked Questions
Who can use Trust Monitor?
Trust Monitor is available to customers who have the feature included within their AppCheck subscription.
Do all users have access to Trust Monitor?
Yes. Once enabled for an organisation, Trust Monitor is visible to all users within that account.
How is Trust Monitor scoped?
Trust Monitor uses apex domains (for example, example.com) as its scope. Once a domain is added, Trust Monitor automatically begins analysing the wider ecosystem associated with that domain.
How are findings presented?
Trust Monitor findings are displayed within the Trust Monitor interface, where users can review exposures, affected assets and supporting context.
Does Trust Monitor require credentials or integrations?
No. Trust Monitor uses passive discovery techniques and does not require credentials, cloud access or third-party integrations.
Why use Trust Monitor if I already run vulnerability scans?
Traditional vulnerability scanning focuses on assets that are explicitly in scope and actively tested. Trust Monitor complements this by identifying trusted third-party relationships, exposed credentials, infrastructure weaknesses and other security exposures that may exist outside that predefined scope, helping provide a broader view of your overall security posture.
Comments
0 comments
Article is closed for comments.