Our platforms: EASM, AI-native AppSec and GRC
Three European SaaS platforms that complement our pentest engagements: EASM for external attack surface management (asset discovery, shadow IT, NIS2), SecAI for AI-driven application security (contextual taint-based SAST, SCA, IaC and secrets in a single scan), and GRC to prepare for NIS2 against the French ReCyF framework.
EASM
Your external attack surface, mapped from a single domain.
Starts from a single domain name and rebuilds the inventory on its own, with no agent and no internal access. It finds what nobody declared: the staging environment left open, the subdomain of a terminated vendor.
- Entry point
- €0 (Discovery), then €99 / mo (Pro)
- Best for
- You expose more on the internet than your inventory accounts for.
SecAI
Contextual AI SAST: follow the data flow, not the regexes.
Reads the source code rather than the surface: taint tracking along real execution paths, reachability for dependencies. False positives get filtered before your review, not during it.
- Entry point
- €0 (Starter), then €99 / mo (Pro)
- Best for
- You ship code and your current scanner produces more alerts than fixes.
GRC
Prepare for NIS2 with the ReCyF framework, one information system at a time.
Works on the file, not the machine: the 20 objectives and 152 acceptable means of ReCyF, a per-system analysis, a dated action plan and an evidence register. Preparation for the framework, not certification.
- Entry point
- €149 / mo (Starter)
- Best for
- You will fall under NIS2 and your tracking currently lives in a spreadsheet.
Looking for a human engagement instead?
EASM and SecAI run continuously and unattended, GRC keeps your preparation file. A penetration test, on the other hand, is run by hand on a scoped perimeter, with a report and a retest.