The product

One platform. Eight modules.

Each module is rate-limited, audit-logged, and safety-pinned. Together they answer one question: is your perimeter actually doing what you said it does?

Asset & service discovery

Identify open ports, services, banners, OS fingerprints, and protocols across your authorized scope. Tools: Nmap, naabu, custom safe TCP/UDP probes.

  • TCP/UDP discovery
  • Service fingerprinting
  • Banner detection
  • Reverse DNS / ASN / Geo
  • Rate-limited & throttled

Firewall rule analysis

Vendor-neutral rule parsing into a normalized intermediate representation. Detectors run over the normalized model — same logic across all vendors.

  • Palo Alto / FortiGate / Cisco ASA + Firepower
  • Check Point / Juniper SRX / SonicWall / Sophos / pfSense
  • Any-any, shadow, overly-permissive detection
  • Missing egress, exposed admin from any, risky VPN
  • Configurable severity + business context

Exposure validation

Verifies which services are externally reachable, and checks security posture without authentication attempts. Probes are HEAD/OPTIONS-only.

  • TLS version, cipher, cert chain audit
  • RDP / SSH / SMB / SNMP / LDAP detection
  • Default certificate detection
  • Management interface exposure
  • Default credentials indicators (banner-only)

Segmentation validation

Multi-vantage TCP handshake probes prove allowed/denied paths between declared zones. Result: violation matrix against your policy.

  • Declared zone policy matrix
  • Multi-vantage worker deployment
  • TCP handshake only — no payload
  • Violation flagging with evidence
  • Production-safe by construction

Evidence vault

WORM-locked, encrypted, hash-chained evidence. Every finding is replayable; every export is signed.

  • S3 / MinIO with object-lock
  • KMS-managed encryption
  • Tamper-evident hash chain
  • Chain-of-custody tracking
  • Pre-signed URLs, 5-min TTL

Risk scoring

CVSS base score × business context multiplier. Each finding maps to MITRE ATT&CK techniques, CIS Controls, and your compliance frameworks.

  • CVSS 3.1 vector + score
  • Business-context multiplier
  • MITRE ATT&CK mapping
  • Severity: Critical → Info
  • Custom per-tenant weighting

Reporting engine

Templated, signed, deliverable in five formats. Executive, technical, compliance, and remediation reports.

  • PDF / DOCX / HTML / JSON / CSV
  • Ed25519-signed with verifiable fingerprint
  • Async generation, link delivery
  • Custom branding for MSSPs
  • Per-framework compliance pivots

AI assistance

Claude-powered explanation, recommendation, and natural-language querying — strictly tenant-scoped, never the source of truth.

  • Plain-English finding explanations
  • Remediation steps grounded in CIS + vendor docs
  • Natural language → structured query
  • Per-tenant token budgets
  • Output is suggestion, never auto-applied

The platform

Eight modules. One pane of glass.

Each module is purpose-built and rate-limited. Together they answer the one question that matters: is the perimeter actually doing what we said it does?

Asset & service discovery

Nmap, naabu, and custom safe probes map open ports, services, banners, and protocols across your authorized scope.

Firewall rule analysis

Parsers for Palo Alto, FortiGate, Cisco ASA, Check Point, pfSense, Juniper, SonicWall, Sophos. Detects any-any, shadow rules, missing egress.

Exposure validation

Verifies which services are externally reachable. Flags exposed RDP, SMB, SNMP, Telnet, weak TLS, expired or default certificates.

Segmentation validation

Multi-vantage TCP handshake probes prove which zones can — and can't — talk. Violations against your declared policy are surfaced immediately.

Encrypted evidence vault

Object-locked storage with a tamper-evident hash chain. Every finding is replayable for audit, with full chain-of-custody.

Risk scoring engine

CVSS base score × business context. Mapped to MITRE ATT&CK, CIS Controls, PCI-DSS, ISO 27001, NIST CSF, GDPR, and DPDPA.

Audit-ready reporting

Executive, technical, and compliance reports in PDF, DOCX, JSON, CSV, or HTML — all cryptographically signed and verifiable.

AI-assisted remediation

Claude-powered explanations, natural-language queries over findings, and remediation guidance grounded in vendor docs and CIS benchmarks.

How it works

Four steps. Audit-grade outcome.

01

Define & sign scope

Your security lead authors a scope — CIDRs, domains, exclusions, validity window — and signs it with Ed25519. No scope, no scan.

02

Request & approve

Engineers create a scan request bound to the scope. Production-touching scans require dual approval and step-up MFA.

03

Run, rate-limited & safe

Workers run with a signed, compiled-in safety profile. Discovery, exposure, segmentation, and rule analysis — all non-destructive.

04

Review evidence & export

Findings are scored, mapped, and persisted with hash-chained evidence. Export signed reports — PDF, DOCX, JSON, or HTML.

Architecture

Built like the systems we audit.

Stateless workers. Signed artifacts. Append-only audit. Tenant isolation in eight layers. Deployable as SaaS, dedicated, or on-prem (including air-gapped).

Edge

WAF · CDN · mTLS

API gateway

OIDC · RBAC · audit

Orchestrator

FSM · scope check

Workers

Go · safety-pinned

Data plane

Postgres · RLS · Redis

Evidence vault

WORM · hash chain

Tenant isolation

Token → app context → Postgres RLS → storage prefix → network policy.

Supply chain

Cosign-signed images. Admission verifies provenance. SLSA L3 target.

Observability

OpenTelemetry → Tempo. Loki for logs. Audit log → Kafka → WORM.

Full design lives in our internal docs — happy to walk you through it on a call.

Walk into your next audit with evidence, not estimates.

A 30-minute demo on real findings. We'll walk through scope signing, a live scan, and a signed compliance report — all on a customer-style sandbox.

No credit card. No agent install. Authorized-only by design.

Chat with us