Single-tenant WordPress.com footprint; surface is the actual surface
Allied Advisors Group operates a single-domain WordPress.com-hosted web presence with no evidence of shadow infrastructure; the observed attack surface is very likely the actual attack surface rather than a curated public-facing subset.
Analytical reasoning
Four independent subdomain enumeration corpora (Certificate Transparency via certspotter, HackerTarget hostsearch, AnubisDB passive DNS, and Common Crawl) converge on the same answer: the apex alliedadvisorsgroup.com plus www and nothing else. The shared Let's Encrypt certificate 14537423605 bundles the target with 44 unrelated WordPress.com customer domains, which is the expected pattern for Automattic-managed hosting and not an indicator of intentional concealment. Combined with the WordPress.com nameservers and Automattic /24 IP range, the recon evidence is very likely a complete picture of the firm's internet-exposed infrastructure. The competing hypothesis that the firm operates additional private infrastructure (cloud accounts, vendor portals, internal SaaS) is not refuted by recon but produces no exposed surface in passive collection.