cyberenforced.io

How it works

Client Journey

Most teams do not shop for GRC. They get asked to prove they are secure, and need an answer this week.

  1. Step 1

    Start free

    Sign up with email and a password, name your organization, and you can add a domain right away. A customer questionnaire or a cyber-insurance renewal is the usual reason teams start this week.

    No credit card

    No demo call and no invoice to begin. You see a real scan before anyone asks you to pay.

    Two domains free

    Subdomains stay free and uncounted, enough to answer the first questionnaire.

    Score in minutes

    The first scan starts as soon as you add a domain.

    You stay the owner

    Invite the team later. The owner role cannot be removed or demoted.

  2. Step 2

    Add a domain

    Enter the hostname only: example.com, not a full URL. The scan starts immediately.

    Mail authentication

    SPF and DMARC checks cover the email rows most questionnaires ask first.

    TLS and headers

    HTTPS, HSTS, CSP, and related header grades show up on the same scan.

    Open ports and expiry

    Risky services, SSH banners, and WHOIS or certificate expiry become findings.

    Subdomain discovery

    Found hosts nest under the parent domain and are scanned automatically.

  3. Step 3

    Read the score

    The dashboard score is a severity-weighted average of Production domains, not a count of how many you added.

    Production only

    Staging, UAT, and Development issues do not pull the score down.

    Severity-weighted

    Critical and high findings move the number more than noise.

    Plain-English fixes

    Each finding says what is wrong and how to fix it.

    One view of gaps

    Search, filter, and sort findings across every domain in the organization.

  4. Step 4

    Fix what matters

    Work the list until the gaps that block the questionnaire or renewal are closed.

    Track status

    Open, acknowledge, or resolve each finding as you work it.

    Group into projects

    Bundle related findings so a teammate can finish one job, not twenty tickets.

    Assign an owner

    Give a finding or project to the person who can actually change DNS or TLS.

    Due-date reminders

    Set a date and get notified before an item slips.

  5. Step 5

    Share the proof

    Hand the customer, insurer, or client a report, not a screenshot of your dashboard.

    CSV or PDF

    Download the findings when a form wants an attachment.

    Shareable link

    Send a public report URL. The recipient does not need a login.

    Revoke anytime

    Turn the link off when the review is done.

    Built for the ask

    Use it on a questionnaire, an insurance application, or a client QBR.

  6. Step 6

    Add more only when asked

    Scanning stays useful on its own. Add-ons sit on Pro, are invoiced, and turn on only when the form asks for more.

    GRC

    Controls, policies, and a risk register across up to 12 frameworks.

    Vendor Security

    A third-party inventory with criticality, reviews, and overdue dates.

    Training

    Assign “Spot It. Stop It. Report It.” and track who passed.

    Invoiced on Pro

    A staff member enables the module after you are quoted. No in-app checkout.

Who it's for

Built for the company that just got asked

  • The ops lead handed a questionnaire. A customer security questionnaire is blocking a deal. Answer it this week: start free, see your gaps in minutes, and share a clean report link with the customer.
  • The IT owner facing an insurance renewal. The cyber-insurance form now wants email authentication, TLS, and staff training. Get SPF/DMARC, TLS, and training sorted, with a report you can attach to the application.
  • The MSP watching many small clients. New client onboarding or a quarterly review, without a $25k GRC suite. Monitor each client’s attack surface, hand them a report, and add compliance or training when they need it.

What we are honest about

  • GRC evidence is a notes field, with no automated collection from AWS, Okta, or GitHub.
  • Plans and add-ons are invoiced; there is no self-serve card checkout in the product.
  • Built for SMBs and MSPs serving them, not as an enterprise attestation platform.
Client Journey | CyberEnforced