complyeah
External pentest · SOC 2 & ISO 27001

The external pentest your auditor actually accepts.

Connect a domain, prove you own it, and get an AI-run external penetration test - delivered as a control-mapped report and a shareable certificate. $50 per pentest, and you re-verify every fix.

No source codeVerified ownershipAttributable egress
External pentest · CertificateVerified
Security posture
Strong
api.yourdomain.com
0
Critical
0
High
0
Medium
1
Low
Mapped toSOC 2 CC7.1ISO 27001 A.8.8
Issued & shareable - re-tested on every change.
How it works

Four steps to an audit-ready result.

Automated penetration testing that stays audit-ready: no agents to install, no source-code access, no security team required. Setup takes minutes; most scans finish in hours, and you leave with a pentest report auditors accept.

  1. 01

    Connect a domain

    Add your app's domain. We issue a one-time verification token - nothing runs yet.

  2. 02

    Prove ownership

    Drop a DNS TXT record or a file. We re-check it immediately before every scan. No scan ever runs on a domain you haven't proven you own.

  3. 03

    Run the pentest

    AI agents test your external surface - throttled, from attributable infrastructure, with no create, modify, or delete actions.

  4. 04

    Get the report

    Download an auditor-ready, control-mapped report and a shareable certificate - with a fix on every finding.

The deliverable

The scanner is commodity. The report is the product.

Anyone can point tools at a domain. What an auditor needs is a clear, mapped, remediation-first report they can put in the file - and a certificate you can share with a customer.

Low severityapi.yourdomain.com
Missing HSTS header

The site does not set Strict-Transport-Security, so a first request can be downgraded to HTTP.

Fix · ~15 min

Add a Strict-Transport-Security response header with a max-age of at least one year.

Posture grade, not a wall of red

Every report leads with an A-F grade and severity counts, so the headline is a decision - not a panic.

A fix on every finding

Each issue is paired with concrete remediation and an effort estimate, ordered so you fix what matters first.

Control-mapping appendix

Findings map to the exact controls your auditor checks - SOC 2 and ISO 27001:2022 - as a first-class appendix.

Stated methodology & scope

Assessed against OWASP WSTG, PTES, and NIST SP 800-115, with an explicit external-only scope and limitations statement.

Re-test evidence trail

Re-scan after you fix. Criticals and highs carry a remediation trail - the evidence auditors weight most.

Human-verified sign-off

Some auditors want a human sign-off. Add a reviewer attestation to any comprehensive report for $50 - our team reviews it and counter-signs your certificate with a verifiable digital signature.

Why complyeah

Built for founders shipping SOC 2 - not for a SOC team.

One flat price per pentest

$50 runs a full pentest on one domain, valid a full year - $30 each once you have 15+ verified domains. No subscriptions, no seats, no per-IP metering, no surprise invoice after the scan.

External-only

We test what the internet can reach. No source-code access, no agents to install, nothing to deploy.

Re-verify your fixes

Fixed a finding? Re-verify it right from the report, so your certificate reflects what you shipped - not last quarter.

Authorized by design

No scan runs without verified ownership and a stored authorization. Re-checked before every run. There is no override.

Calm, decision-first reporting

Grade, counts, and fixes - presented so a founder can act, not a report engineered to scare you into a retainer.

Auditor-ready output

Control mapping, methodology, scope, and a remediation trail - the shape auditors already expect.

Mapped, not just scanned

Every finding lands on a control your auditor already uses.

A SOC 2 pentest and ISO 27001 penetration testing need evidence an auditor trusts - so every finding maps to the exact SOC 2 and ISO 27001:2022 controls below.

SOC 2CC4.1SOC 2CC6.1SOC 2CC7.1SOC 2CC7.2ISO 27001A.8.8ISO 27001A.8.29
MethodologyOWASP WSTGPTESNIST SP 800-115
Pricing

$50 per pentest. One domain. Valid 12 months. Buy as many as you like.

Adding a domain is always free; running a comprehensive pentest spends one $50 credit. Reach 15 verified domains and every pentest is $30 - automatically. Not ready to buy? Start with a free posture snapshot.

Free scan
$0
Shallow posture snapshot

A real security check. No card required.

  • TLS / certificate, security-header & cookie checks
  • Detection of exposed secrets & API keys
  • Email-DNS hygiene (SPF, DMARC)
  • Posture grade + every finding paired with a fix
  • A snapshot, not a pentest - upgrade any time
Pay per pentest
$50/ scan
One domain · valid 12 months

The full auditor-ready external pentest. One credit, one scan.

  • One comprehensive external penetration test
  • Auditor-ready report + shareable live certificate
  • SOC 2 & ISO 27001:2022 control mapping
  • Re-verify each finding after you fix it
  • Add as many domains as you want - free to verify
  • Buy as many credits as you want; each is valid a full year
Team rate
Volume
$30/ scan
At 15+ verified domains

The same pentest at a volume price - unlocked automatically.

  • Every pentest is $30 instead of $50
  • Unlocks automatically at 15 or more verified domains
  • The same credit: one domain, valid 12 months
  • No subscription, no seats - buy any quantity
Enterprise
Custom
Talk to us

Volume programs, procurement, and a human sign-off on your reports.

Talk to us
  • Volume pricing and consolidated invoicing
  • Human-verified sign-off available on your reports
  • Priority support and onboarding

No subscriptions. No seats. No per-IP metering. A pentest is $50 (or $30 each once you have 15+ verified domains), and a human sign-off is $50 per report.

Questions

The things founders ask first.

Still unsure? Start a scan - you verify ownership before anything runs.

How much does it cost?

One flat price: $50 runs one comprehensive external pentest on one domain, and the credit is valid for a full year (12 months). There's no subscription and no seats - buy as many credits as you want, and add as many domains as you want (verifying a domain is free; running a pentest spends one credit). Once you have 15 or more verified domains, every pentest is $30. A shallow posture snapshot is always free, and a human sign-off on any report is $50.

Can I get a refund, and how long do credits last?

Every credit is valid for a full year (12 months), and we email you before one expires. If you change your mind, you can withdraw and refund any credit you haven't used within 14 days of purchase - self-serve from your billing page, back to your original payment method. Starting a scan uses a credit and waives that 14-day withdrawal for it. And if a scan ever fails on our side, we restore the credit automatically at no cost to you.

Do auditors accept AI-run pentests?

For external testing, most SOC 2 and ISO 27001 auditors accept a well-scoped, methodology-backed report with a clear remediation trail - which is exactly what we produce. Where an auditor requires a human sign-off, you can add a reviewer attestation to any comprehensive report for $50 - our team reviews it and counter-signs your certificate with a verifiable digital signature.

What exactly do you test?

Your external, internet-facing surface: web applications, APIs, and exposed services on domains you've verified. It's external-only by design - no source-code review, no internal-network testing, and no social engineering.

Why is this a fraction of the price of a normal pentest?

A traditional pentest is priced on consultant hours - scoping calls, manual testing, and a hand-written report push a single engagement into five figures. We automate the commodity scanning and the report assembly, run entirely external and self-serve, and reuse the same engine across every customer - so the same audit-grade, control-mapped report lands at a fraction of the cost, often around a tenth. You're paying for the report and the workflow, not billable hours. Where an auditor wants human sign-off, add a reviewer attestation to any comprehensive report for $50.

How do you make sure a scan is authorized?

No scan runs without DNS-verified ownership of the domain and a stored authorization that records scope and rules of engagement. Ownership is re-checked immediately before every scan, and there is no override - it's enforced in the service layer, not just the UI.

Is it safe to run against production?

Yes. Testing is external, throttled, and non-invasive - no create, modify, or delete actions on your systems - and runs from attributable, self-identifying infrastructure so your team can recognize our traffic.

How long does it take?

Setup is a few minutes: add a domain, drop a DNS record, authorize. Most external scans complete in hours, and you can re-test as often as you deploy.

Prove your security posture in an afternoon.

Connect a domain, verify it, and run your first external pentest. You'll have a report and a shareable certificate the same day.