The external pentest your auditor actually accepts.
Connect a domain, prove you own it, and get an AI-run external penetration test - delivered as a control-mapped report and a shareable certificate. $50 per pentest, and you re-verify every fix.
Four steps to an audit-ready result.
Automated penetration testing that stays audit-ready: no agents to install, no source-code access, no security team required. Setup takes minutes; most scans finish in hours, and you leave with a pentest report auditors accept.
- 01
Connect a domain
Add your app's domain. We issue a one-time verification token - nothing runs yet.
- 02
Prove ownership
Drop a DNS TXT record or a file. We re-check it immediately before every scan. No scan ever runs on a domain you haven't proven you own.
- 03
Run the pentest
AI agents test your external surface - throttled, from attributable infrastructure, with no create, modify, or delete actions.
- 04
Get the report
Download an auditor-ready, control-mapped report and a shareable certificate - with a fix on every finding.
The scanner is commodity. The report is the product.
Anyone can point tools at a domain. What an auditor needs is a clear, mapped, remediation-first report they can put in the file - and a certificate you can share with a customer.
The site does not set Strict-Transport-Security, so a first request can be downgraded to HTTP.
Add a Strict-Transport-Security response header with a max-age of at least one year.
Posture grade, not a wall of red
Every report leads with an A-F grade and severity counts, so the headline is a decision - not a panic.
A fix on every finding
Each issue is paired with concrete remediation and an effort estimate, ordered so you fix what matters first.
Control-mapping appendix
Findings map to the exact controls your auditor checks - SOC 2 and ISO 27001:2022 - as a first-class appendix.
Stated methodology & scope
Assessed against OWASP WSTG, PTES, and NIST SP 800-115, with an explicit external-only scope and limitations statement.
Re-test evidence trail
Re-scan after you fix. Criticals and highs carry a remediation trail - the evidence auditors weight most.
Human-verified sign-off
Some auditors want a human sign-off. Add a reviewer attestation to any comprehensive report for $50 - our team reviews it and counter-signs your certificate with a verifiable digital signature.
Built for founders shipping SOC 2 - not for a SOC team.
One flat price per pentest
$50 runs a full pentest on one domain, valid a full year - $30 each once you have 15+ verified domains. No subscriptions, no seats, no per-IP metering, no surprise invoice after the scan.
External-only
We test what the internet can reach. No source-code access, no agents to install, nothing to deploy.
Re-verify your fixes
Fixed a finding? Re-verify it right from the report, so your certificate reflects what you shipped - not last quarter.
Authorized by design
No scan runs without verified ownership and a stored authorization. Re-checked before every run. There is no override.
Calm, decision-first reporting
Grade, counts, and fixes - presented so a founder can act, not a report engineered to scare you into a retainer.
Auditor-ready output
Control mapping, methodology, scope, and a remediation trail - the shape auditors already expect.
Every finding lands on a control your auditor already uses.
A SOC 2 pentest and ISO 27001 penetration testing need evidence an auditor trusts - so every finding maps to the exact SOC 2 and ISO 27001:2022 controls below.
$50 per pentest. One domain. Valid 12 months. Buy as many as you like.
Adding a domain is always free; running a comprehensive pentest spends one $50 credit. Reach 15 verified domains and every pentest is $30 - automatically. Not ready to buy? Start with a free posture snapshot.
A real security check. No card required.
- TLS / certificate, security-header & cookie checks
- Detection of exposed secrets & API keys
- Email-DNS hygiene (SPF, DMARC)
- Posture grade + every finding paired with a fix
- A snapshot, not a pentest - upgrade any time
The full auditor-ready external pentest. One credit, one scan.
- One comprehensive external penetration test
- Auditor-ready report + shareable live certificate
- SOC 2 & ISO 27001:2022 control mapping
- Re-verify each finding after you fix it
- Add as many domains as you want - free to verify
- Buy as many credits as you want; each is valid a full year
The same pentest at a volume price - unlocked automatically.
- Every pentest is $30 instead of $50
- Unlocks automatically at 15 or more verified domains
- The same credit: one domain, valid 12 months
- No subscription, no seats - buy any quantity
Volume programs, procurement, and a human sign-off on your reports.
Talk to us- Volume pricing and consolidated invoicing
- Human-verified sign-off available on your reports
- Priority support and onboarding
No subscriptions. No seats. No per-IP metering. A pentest is $50 (or $30 each once you have 15+ verified domains), and a human sign-off is $50 per report.
The things founders ask first.
Still unsure? Start a scan - you verify ownership before anything runs.
How much does it cost?
One flat price: $50 runs one comprehensive external pentest on one domain, and the credit is valid for a full year (12 months). There's no subscription and no seats - buy as many credits as you want, and add as many domains as you want (verifying a domain is free; running a pentest spends one credit). Once you have 15 or more verified domains, every pentest is $30. A shallow posture snapshot is always free, and a human sign-off on any report is $50.
Can I get a refund, and how long do credits last?
Every credit is valid for a full year (12 months), and we email you before one expires. If you change your mind, you can withdraw and refund any credit you haven't used within 14 days of purchase - self-serve from your billing page, back to your original payment method. Starting a scan uses a credit and waives that 14-day withdrawal for it. And if a scan ever fails on our side, we restore the credit automatically at no cost to you.
Do auditors accept AI-run pentests?
For external testing, most SOC 2 and ISO 27001 auditors accept a well-scoped, methodology-backed report with a clear remediation trail - which is exactly what we produce. Where an auditor requires a human sign-off, you can add a reviewer attestation to any comprehensive report for $50 - our team reviews it and counter-signs your certificate with a verifiable digital signature.
What exactly do you test?
Your external, internet-facing surface: web applications, APIs, and exposed services on domains you've verified. It's external-only by design - no source-code review, no internal-network testing, and no social engineering.
Why is this a fraction of the price of a normal pentest?
A traditional pentest is priced on consultant hours - scoping calls, manual testing, and a hand-written report push a single engagement into five figures. We automate the commodity scanning and the report assembly, run entirely external and self-serve, and reuse the same engine across every customer - so the same audit-grade, control-mapped report lands at a fraction of the cost, often around a tenth. You're paying for the report and the workflow, not billable hours. Where an auditor wants human sign-off, add a reviewer attestation to any comprehensive report for $50.
How do you make sure a scan is authorized?
No scan runs without DNS-verified ownership of the domain and a stored authorization that records scope and rules of engagement. Ownership is re-checked immediately before every scan, and there is no override - it's enforced in the service layer, not just the UI.
Is it safe to run against production?
Yes. Testing is external, throttled, and non-invasive - no create, modify, or delete actions on your systems - and runs from attributable, self-identifying infrastructure so your team can recognize our traffic.
How long does it take?
Setup is a few minutes: add a domain, drop a DNS record, authorize. Most external scans complete in hours, and you can re-test as often as you deploy.
Prove your security posture in an afternoon.
Connect a domain, verify it, and run your first external pentest. You'll have a report and a shareable certificate the same day.