Products
What you can run in one login
Scanning is the core every organization gets. GRC, Vendor Security, and Training & Awareness are paid add-ons on Pro, sold separately, enabled when you need them.
Security Scanning
The free core: continuous external checks on the things questionnaires and insurers actually ask about.
- DNS, SPF, DMARC, TLS, HTTP security headers (HSTS/CSP), open ports, SSH banners, WHOIS expiry, and subdomain discovery
- Per-domain security score, findings you can open / acknowledge / resolve, and plain-English remediation guidance
- CSV/PDF export and revocable shareable report links, no login required for the recipient
- Free for up to 2 domains and 2 public IPs (subdomains stay free and uncounted); Pro adds unlimited domains, 25 IPs, daily scans, a change digest, extra mail/web checks, IP CSV/PDF export, and CISA.gov KEV correlation
GRC
Lightweight controls, policies, and a risk register: enough structure to answer the questionnaire without an enterprise GRC contract.
- 1,102 controls across 12 frameworks: ISO 27001, SOC 2, PCI DSS, NIST CSF, HIPAA, GDPR, CCPA/CPRA, NIST 800-53, CIS Controls, COBIT, FedRAMP, and CMMC
- Policies with versioning and member acknowledgment; risk register with likelihood × impact, treatment, owners, and documents
- Evidence is a manual notes field, a deliberate simplicity and price tradeoff, not automated cloud-integration collection
- Sold as one add-on on Pro, tiered by how many frameworks you need
Vendor Security
A third-party inventory you can actually keep current when a customer asks who you rely on.
- Vendor name, criticality tier, review status, and next-review date with an overdue badge
- Optional link from a vendor to a single Risk Register entry
- Sold separately from GRC. Add it only if vendor questionnaires are part of how you buy or sell
Training & Awareness
Staff-authored courses and quizzes so you can show that people were trained, not just told.
- Shared catalog you assign to the whole organization, with an optional due date
- Multiple-choice quiz graded server-side; completion roster for follow-up
- Flagship course: “Spot It. Stop It. Report It.” plus Phishing Awareness Basics
- Useful when a cyber-insurance form or customer questionnaire asks for security-awareness training