Discover
Evidence Surface maps your full external perimeter from the Evidence Graph, our live model of the entire internet. Your complete inventory is ready in seconds, including the assets your current tools have never seen.
The first cybersecurity solution that backs its findings with money.
CISOs tell us they…
A FIRE is a CVE that caused a documented financial loss at a real organization. We built the list from insurance claims, DFIR forensic records, reinsurer tables, and public disclosures. If a CVE is on this list, someone lost money to it. If it's not, no one ever has.
Your team gets a list it can finish: most first scans turn up single-digit FIREs. And every finding shows a dollar figure from loss data for your industry and size, so the work finally has a number behind it. New loss data can add new FIREs to the list.
Our loss data exists in no public database and no competitor's product. Evidence has it because we were built for insurers before we were sold to security teams, using the records of what companies actually paid when a breach hit.
The Evidence Platform works like nothing else on the market. Three steps, one record, and money behind the results:
Evidence Surface maps your full external perimeter from the Evidence Graph, our live model of the entire internet. Your complete inventory is ready in seconds, including the assets your current tools have never seen.
Evidence Scan checks every asset every 24 hours against the FIRE list (the CVEs with documented financial losses behind them) plus KEVs and any custom lists you run. Each finding comes with its dollar exposure, calculated from incident data for your industry and size.
Evidence Reporting turns the results into board-ready summaries that export to slides or email: exposure in dollars, risk retired in dollars, and the streak once you hit zero.
Mythos Warranty backs the whole chain with up to $5M, because our platform is accurate enough to stake money on.
Every asset in your inventory is a single record in the Evidence Graph, and all four products work from it.
Patch a FIRE and all four views update from the same event: the finding closes, the dollars come off your exposure, the board summary updates, the proof gets logged.
Product screen - the unified asset recordCompanies get breached through assets they didn't know they owned. We mapped the whole internet and resolved who owns what, so your attack surface is ready before you log in, including the 40% of assets mature security teams missed in our customer testing. New assets flow in as your footprint changes, and acquisitions show up without reconfiguring anything.
Every severity score is a proxy for one binary question: has this ever cost someone money? Scan answers it directly, every day, on every asset. Most first scans turn up single-digit FIREs. Zero is within reach, and we track your streak once you get there.
How much financial risk has your program eliminated this year? Evidence tracks every dollar you remediate: a risk-retired total that climbs with every fix, exposure by business unit, and peer rankings built from what those companies actually lost. Walk into the board meeting speaking dollars and cents.
We put up to $5M behind knowing which CVEs cause financial loss. Every vendor says they know which vulns matter, but Evidence is the first vulnerability management company to put its money where its mouth is. Lose money to a CVE that isn't on the FIRE list, and we pay you up to $5M.
Catch a new FIRE within a day of it appearing on your perimeter.
See findings in minutes. Deploy no agents, hand over no credentials, provision nothing.
Compare your FIRE exposure to companies your industry and size, measured from real losses instead of surveys.
Carriers scan your perimeter before they price your premium. Get that view first and fix what would have raised your rate.
Run EASM, scanning, reporting, and warranty coverage on one platform and one budget line.
Copy dollar figures, trendlines, and benchmarks straight into the board presentation you already build.
FIRE gives you something unique in vuln management: a list you can finish fixing.
Reach zero FIREs and hold it, and Evidence starts counting up your streak: a number that inspires your team and impresses the board.
Product screen - the zero-FIRE streak counterCISOs average 18–26 months in the job while the rest of the C-suite gets four years. Breaches are one reason. The bigger one is having no way to show leadership what the program is worth. Evidence stops the breaches that cost money and proves you did it, in dollars, with up to $5M in coverage while you do.
For enterprise →Questionnaires self-report and ratings tools guess. Evidence shows you any applicant's real footprint before you bind, audits the application against their real perimeter, and monitors your whole book daily against the CVEs that generate claims. When a new CVE is used to cause a breach, you learn right away which insureds are exposed to the same CVE.
For carriers →Clients leave when they get breached or can't see what they're paying for. Evidence handles both: catch the FIREs before they end the contract, and walk into every QBR with the dollars of risk you retired. Onboarding a new client is as simple as typing their domain.
For MSSPs →Their last company was acquired by Tenable. That's when they started asking the question that became Evidence: which vulnerabilities actually cost money?
Secured Yahoo's websites for over a hundred million users, founded WhiteHat Security in 2001, and helped build web application security into a discipline. Served as Chief of Security Strategy at SentinelOne through its IPO, then co-founded Bit Discovery, acquired by Tenable in 2022. Since Black Hat 2014 he has argued that security vendors should warranty their products. Root Evidence is where he stopped waiting for the industry to catch up.
Built eBay's anti-fraud and anti-phishing systems, pen-tested over 2,100 banks and critical systems at SecTheory, and is credited with discovering or formalizing Slowloris and Clickjacking. VP of Labs at WhiteHat Security, co-founder of Bit Discovery. At Root Evidence he leads the engineering and detection work behind the FIRE list, the EASM architecture, and the data pipeline.
Scaled operations and led strategic M&A across high-growth cybersecurity organizations for 20+ years, guiding WhiteHat Security through its acquisition by NTT Security and Bit Discovery through its acquisition by Tenable. At Root Evidence she runs the business behind the platform: operations, finance, people, and partnerships, from first design partner to GA.
25+ years designing and building software products. As a founding UI engineer on Facebook's Growth team he built the first ten minutes of every new user's experience, shipped interfaces used daily by a third of the world, and co-invented Facebook Live. Co-founded and exited WhiteHat Security and Bit Discovery. At Root Evidence he leads product and design across the platform.
We'll show your financial exposure, on your actual perimeter, in minutes.
Book the demo. Bring the results to your next board meeting.