Which attack surface map should you hire: runZero or Censys?
Choose runZero when the week is owned-network asset discovery and exposure management. Choose Censys when you need internet-wide attack-surface search and ASM against what the public Internet already indexes.
“Attack surface management” used to be one RFP line that meant “find what we own before attackers do.” That label still shows up on both invoices. The category split underneath it did not stay still: one desk grew around placing discovery engines on networks you control, the other around querying a continuously refreshed map of the public Internet.
Between these two, runZero productizes agentless asset discovery and exposure management for owned networks: Explorers run active scans and passive sampling, merge API integrations, and fingerprint IT, OT, IoT, cloud, and mobile inventory you are responsible for. Censys productizes internet-wide attack-surface visibility: the Censys Internet Map across all 65,535 ports, managed ASM for attributed external assets, and pivots into the Censys Platform plus ARC research when an exposure becomes an adversary question. RunZero also documents external scanning with hosted Explorers, and Censys is not a DNS-only seed expander. The centers still differ. Broader shortlist context: attack surface management tools.
| Job | Owned-network asset discovery and exposure management (IT, OT, IoT, cloud, mobile) | Internet-wide attack-surface search and ASM (what attackers can already query) |
|---|---|---|
| How a bad day closes | Explorer scan or passive sample finds unknown or unmanageable devices; risk findings route to owners | Internet Map / ASM surfaces a new host, port, cert, or service; ticket or ARC alert drives remediation |
| Operator morning unit | Assets and services inside networks you can place an Explorer on, plus correlated integration records | Attributed internet-facing assets, exposure deltas, and investigation pivots on the Internet Map |
| Deploy | SaaS console; optional self-hosted console on Platform; self-hosted and runZero-hosted Explorers | SaaS Censys Platform and ASM; cloud connectors; API and SOC integrations |
| License/pricing | Community free ≤100 assets; Platform starts at $5,000; 21-day full trial (checked 11 Sep 2026) | Platform Core / Adversary Investigation / Security Operations via Contact Sales; ASM sales / marketplace quote (checked 11 Sep 2026) |
| Who operates it | Asset, CAASM, and exposure owners validating inventory on owned networks | External ASM, CTI, and SOC teams querying what the internet indexes about the org |
That is the owned-network argument in one sentence. External indexes will not settle a fight about a device that never left RFC1918.
That is the opposite desk: something unexpected became internet-visible, and the ASM feed caught it before the owner finished explaining.
We reviewed first-party documentation, public pricing pages, product and press posts, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.
runZero

Censys

Editions and pricing
Procurement friction differs. runZero publishes a free Community ceiling and a Platform floor. Censys publishes named Platform plans without public dollars and routes ASM through sales.
| Public price table | Yes. Community free for ≤100 assets; Platform starts at $5,000; 21-day full-featured trial (pricing page checked 11 Sep 2026) | Named Platform tiers (Core, Adversary Investigation, Security Operations) are Contact Sales; Credits packages start at $100; ASM is sales / AWS Marketplace quote (checked 11 Sep 2026) |
|---|---|---|
| Named lines | Community Edition; runZero Platform; optional self-hosted console with Care; Explorers | Censys Platform; Attack Surface Management; Censys ARC research and Rapid Response |
| What the quote usually meters | Asset volume and Platform packaging above the Community ceiling | Users, history depth, enrichment API volume, Collections, and whether ASM is on the same contract |
| Free forever SKU | Community Edition at ≤100 assets | No public free forever ASM SKU; limited search / credit paths exist separately from managed ASM |
If the spreadsheet must freeze a published dollar before a call, runZero already posts Community and a Platform start. Censys will keep those cells in Contact Sales until the scope (Platform vs ASM) is clear.
Owned-network discovery and exposure management
This is the desk that places discovery capacity on networks you control, then correlates what Explorers and integrations actually see.
| Primary unit of work | Assets and services discovered via Explorers (active + passive) and merged integrations | Internet-facing hosts, services, certificates, and attributed org assets on the Internet Map |
|---|---|---|
| Blind-spot focus | Unknown, unmanageable, OT, and IoT devices that never took an agent | Forgotten or unexpected internet exposures, including nonstandard ports and self-signed hosts |
| Remediation shape | Risk findings, ownership assignment, topology and dashboards inside the Platform | Exposure deltas into ticketing / VM tools; ARC alerts; Platform investigation when the question is adversary infrastructure |
| What teams argue about | Whether Explorer coverage and scan windows are complete enough to trust the inventory | Whether attribution and continuous external refresh replace an on-network discovery engine |
On 31 July 2026 runZero shipped 5.1 with BYOK or self-hosted AI workflows, autonomous discovery that expands scan scope from prior results, and a native Dragos integration for OT context. Between these two, buy that owned-network loop when the open failure is inventory truth inside the perimeter, not when the RFP is only “show me what Shodan-class indexes already list.”
Internet-wide search and ASM
This is the other desk: continuous measurement of the public Internet, then attribution and alerting for what belongs to you.
| External discovery | External attack-surface tasks and runZero-hosted Explorers on Platform; still centered on your scoped targets | First-party Internet Map scanning across all 65,535 ports as the default visibility story |
|---|---|---|
| Search / investigation | Deep inventory search, risk dashboards, and topology inside your collected data | Platform search, Collections, threat modules, and pivots from an ASM hit into adversary infrastructure |
| Research signal | Vendor research and tools such as SSHamble; product center remains exposure management | Censys ARC formalized 10 Mar 2026 for internet threat research and Rapid Response advisories |
| Integration note | First-party pricing table lists a Censys connector to merge externally-facing details into runZero inventory | ASM and Platform integrate with ticketing, SIEM, and enrichment workflows |
On 10 March 2026 Censys unveiled Censys ARC as a dedicated internet threat research collective feeding Rapid Response and Platform intelligence. For a wider external-discovery shortlist, see attack surface management tools.
Where they overlap
Both sell discovery language, exposure language, and SaaS consoles that feed remediation queues. Both can talk about external assets. If your RFP only says “attack surface management,” both will tick boxes.
When to use both
Running both is common when the program needs two maps: Explorers proving what exists on owned networks, and an Internet Map proving what the outside world can already see. runZero’s own integration list includes Censys as an external enrichment source, which is a concrete “both” path rather than a marketing slogan.
Skip runZero for this pair if the only open failure is continuous internet attribution and you will not place Explorers or own scan windows. Skip Censys for this pair if the painful week is OT, IoT, and internal unknowns that never appear on a public index.
Decide the map first. If the product must discover and manage exposure on owned networks, that is runZero. If the product must search and monitor what the public Internet already indexes, that is Censys. Only then open the sales quotes.
FAQs
Is runZero just an EASM tool?
No. First-party pages center exposure management and agentless discovery across IT, OT, IoT, cloud, and mobile on networks you can place Explorers on. External scanning exists, but it is not the same job as a global Internet Map ASM desk.
Is Censys only a search engine?
Censys markets both Platform internet intelligence and Attack Surface Management. ASM is the continuous attributed external inventory; Platform search and ARC support investigation and research around those exposures.
Do either publish list prices?
runZero publishes Community (free ≤100 assets) and Platform starting at $5,000 on its pricing page (checked 11 Sep 2026). Censys Platform plans are Contact Sales; ASM is sales-quoted.
Is this a scored bake-off?
No. Order is editorial.