Personal perimeter audit

atlas

Open-target perimeter + performance dashboard. Any syntactically valid domain is scannable — guard rails are syntactic validation, per-source upstream quotas, and Cloudflare Access JWT gating this dashboard to a single user. See docs/SECURITY.md.

Run all

Fan out a single domain across modules

Modules to run

Estimated upstream calls: 0

Perimeter

Defensive audit modules

Free tier /api/perimeter/ct-logs

Certificate Transparency logs

All certs ever issued for domain + subdomains (crt.sh).

Free tier /api/perimeter/dns-current

DNS current records

A / AAAA / MX / TXT / NS / SOA / CAA via Cloudflare DoH.

Free tier /api/perimeter/dns-propagation

DNS propagation (multi-resolver + multi-region)

Fan out same query across 4 public resolvers + 8 simulated regions via Google DoH ECS. Grid view + consensus + divergent rows.

Free tier /api/perimeter/headers-ssl

Headers + SSL

HTTP response headers + security-header grading + most-recent TLS cert.

Free tier /api/perimeter/subdomains-passive

Passive subdomain enumeration

Union of crt.sh + AlienVault OTX + HackerTarget hostnames for the domain. Optional OTX_API_KEY secret bypasses public rate limit.

Free tier /api/perimeter/whois

WHOIS / RDAP

Registrar, expiry, nameservers, statuses via RDAP.

Performance

Health probes

Free tier /api/performance/ttfb-single

TTFB (single-region)

Time-to-first-byte from the nearest Cloudflare PoP to the Worker.