Security and trust at EASMLens

Last updated 28 September 2026

A security platform should be held to a higher standard than the systems it watches. This page sets out how EASMLens is run and what we commit to. Ask us for anything that is not here.

Certification

EASMLens is operated under an information security management system certified to ISO/IEC 27001. We can share our certificate and statement of applicability under a confidentiality agreement.

Availability

EASMLens is offered with a 99.9% uptime service level agreement. The terms of the SLA are set out in your agreement with us.

Hosting

The platform runs on Microsoft Azure. If your organisation has a data residency requirement, tell us the specific obligation and we will confirm in writing what we can commit to.

What EASMLens sends to your systems

Discovery uses DNS, certificate transparency logs, internet-wide scan datasets and other public sources, and sends nothing to your systems. EASMLens then runs non-destructive active checks against the internet-facing assets in your scope: service and version detection, web server configuration checks and lightweight API authentication checks. It never attempts to exploit a vulnerability, never logs in to your systems, and does not need credentials, agents or network access to your environment.

Only include assets you own or are authorised to test. Some markets regulate security testing services, so our country guides flag where local advice is worth taking.

Tenant separation and access

Each customer organisation has its own tenant with its own users, assets and findings. Access is role-based, and multi-factor authentication is available for user accounts. Accounts are provisioned by an administrator rather than through public self-service sign-up.

AI analysis

EASMLens uses an AI model to explain and prioritise what its data sources have found. The model is hosted by us rather than by a third-party AI provider, and it never decides what was found.

Integrations

EASMLens integrates with Splunk, ServiceNow, Jira, PagerDuty and Microsoft Sentinel, so findings can flow into the tools your teams already use.

Reporting a vulnerability

If you believe you have found a security vulnerability in EASMLens, please email info@easmlens.com with the details rather than testing further. We will acknowledge your report and keep you informed as we investigate.