See the risks. Move with confidence.
Manage testing, remediation and monitoring in one place.
How it works
6 layers, 89 test categories
6 layers, 89 test categories, more than 100,000 automated security checks and 24/7 monitoring: from your website to your network, from your staff to your cloud infrastructure, under one roof.
- 6security layersWeb · Network · People · Cloud · Code · Mobile
- 89test categories
- 100,000+automated security checks
- 1,700+attack techniques and scenarioscontrolled simulation
- 600+cloud configuration checks
- Thousandsup-to-date vulnerability templates
- 24/7continuous monitoring option
- 46
Web / site layer
Thousands of up-to-date vulnerability templates and more than 100,000 known vulnerability signatures are scanned in the background.
View details - 20
Network layer
More than 100,000 known vulnerability signatures are matched against your network services.
View details - 14
People / process layer
Most attacks start with an email or a phone call. We measure how prepared your staff and processes are for that.
View details - 4
Cloud layer
More than 600 cloud configuration checks for AWS, Azure and Google Cloud.
View details - 4
Code / development layer
We catch vulnerabilities inside the code, before the application goes live.
View details - 1
Mobile layer
We examine your Android and iOS app both through its code and while it runs.
View details
Ongoing enterprise service lines
Beyond testing: continuous monitoring, response, simulation and consulting.
- External attack surface management (ASM)Every asset you expose to the internet (domains, servers, panels) is monitored continuously; you are told about a newly opened door or a certificate about to expire.
- 24/7 security monitoring (SOC)Logs from your systems are monitored without interruption and an alert is raised when something looks suspicious. The extent of human review depends on the monitoring level you choose.
- Emergency incident response and forensicsFast response during an attack: stopping the spread, preserving evidence and working out step by step what happened.
- Threat intelligenceWe give you advance information about current threats aimed at your sector and the technologies you use, and update your defences accordingly.
- Attack simulation and purple teamingWith more than 1,700 attack techniques and scenarios we test, together with your team and in a controlled way, whether your defences spot attacks.
- Deception and decoy systemsDecoy systems and fake credentials that look real are placed on your network; if anyone touches them, the attacker is spotted early.
- Compliance readiness consulting (KVKK, ISO 27001, PCI DSS)We identify the gaps and prepare a roadmap to get you ready for these requirements. We are not a certification body; we help you prepare for the audit.
- Password strength auditWith your permission we measure how well the passwords on company accounts resist guessing. We never share the passwords themselves; we only report the weak accounts.
- Security automation (SOAR)We turn repetitive response steps, such as blocking a suspicious address and notifying the right person, into automated workflows, so incidents get a faster and more consistent response.
The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.
Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.
Solutions for your needs.
Only explicitly authorized assets and agreed scope are assessed.
Cybersecurity · Testing
- Authorized scope
- Risk table
- Finding evidence
- Remediation plan
Cybersecurity · Remediation
- Quote per finding
- Fix work plan
- Change notes
- Retest report
Cybersecurity · Monitoring
- Asset inventory
- Alert rules
- Incident timeline
- Monthly report
Cybersecurity · Incident response
- Incident triage
- Containment plan
- Recovery plan
- Incident report
Cybersecurity · Simulation
- Authorized scope
- Authorized attack scenario
- Defense review
- Remediation plan
Cybersecurity · Compliance
- Gap analysis
- Policy drafts
- Evidence list
- Readiness review
Cybersecurity · Mobile apps
- App permissions
- Data flow
- Storage review
- Risk table
Cybersecurity · Cloud security
- Identity and access review
- Network review
- Configuration review
- Risk table
Cybersecurity · Code security
- Code review
- Dependency review
- Secret review
- Fix work plan
Cybersecurity · Deception and decoys
- Isolated decoys
- Alert rules
- Response playbook
- Scope boundaries
Cybersecurity · Badge verification
- Assessment summary
- Validity period
- Badge verification
- Renewal retest
Cybersecurity · Testing · Security testing packages
- Authorized scope
- Risk table
- Finding evidence
- Remediation plan
Cybersecurity · Monitoring · External attack surface
- Asset inventory
- Exposure changes
- Alert rules
- Monthly report
Cybersecurity · Monitoring · Basic monitoring
- Alert rules
- Availability signals
- Incident timeline
- Monthly report
Cybersecurity · Monitoring · SOC-Lite
- Alert rules
- Triage plan
- Response playbook
- Scope boundaries
Cybersecurity · Monitoring · Enterprise SOC
- Log scope
- Incident triage
- Response playbook
- Responsibility and governance
Deliverables and acceptance criteria are agreed during scoping.
What sets the price of security work
In security work, the price depends on what is examined, how deeply and how often. The scope is agreed in writing, and no system outside it is touched.
Number of assets in scope
The basic unit is the number of web assets, network blocks, cloud accounts or monitored devices. One web asset covers a domain, its subdomains and one connected application.
Method and package level
Black-box or grey-box testing, whether areas behind a login are tested with test accounts, and the chosen package (Starter, Standard, Comprehensive) change the effort involved.
Tests that need separate approval
Phishing, phone-based social engineering and tests that could disrupt your service are not in the default scope. If you want them, each is planned as a separate line with separate written approval.
Retest and fixing
One retest within 30 days of the report is included in the price. Fixing the vulnerabilities is a separate service, priced per issue and by risk level, with a bulk discount when there are many.
Monitoring level
For ongoing monitoring, the chosen level (external attack surface, basic monitoring, SOC-Lite or Enterprise SOC) and the number of monitored assets or devices set the monthly fee.
Incident response model
For incident response you can choose an annual standby agreement or a one-off engagement; the length of the response and the number of affected systems set the price.
The price becomes clear in a written quote listing the assets, the method and the date range, prepared after a short first conversation; nothing is charged up to that point. No test starts without a signed written authorisation.
Request a quoteLet's talk about your project.
Tell us what you need; we will define the scope together.