The scanner that does the analyst's work

A market scanner hands you 63 findings.
We hand you the 23 that hold — and show our work on every one.

Most scanners produce a long list of "possible" issues and leave the sorting to you. Scrytide does that work: it scans behind the login, discards what doesn't hold with a written justification, verifies whether a vulnerability actually applies to your configuration, names the public exploit, and tells you plainly what it couldn't test. All read-only.

Point us at one target See how it works
12 → 91 endpoints
what authentication reveals — see below
Couldn't test ≠ nothing found
every control declares which
Read-only
nothing degraded, altered, or left behind
Proof, not noise

The difference between a finding and a guess

Anyone can produce a list of possibilities. The value is in eliminating everything that isn't real — and being honest about what couldn't be checked — before a person has to read it.

A market scanner
Stops at the login page — it scans the façade, not the application
Reports a CVE as "critical" the moment a version matches — whether or not it applies
Sixty-plus findings, unranked; more than half don't survive review
"2 CVEs have public exploits" — never says which
Silent when it couldn't test — "no result" reads as "nothing found"
A Scrytide report
Scans authenticated — the surface behind the login, on every plan
Measures whether a CVE's exploitation condition is met on your real configuration, and says so in the finding
Only what survived review — each discard carries a written, checkable justification
Names each CVE with a public exploit, with its links
Distinguishes "nothing found" from "couldn't test" — every control declares which
What you're actually buying

A scanner hands you the list.
The work is what comes after.

Turning a raw scan into something a team can act on is analyst work — and a scanner leaves all of it on your desk. On one real client campaign, we estimate that at eleven to fifteen hours. Scrytide does it, and then it starts over on the next scan.

Triage 63 findings, discard the 40 that don't hold3–4 h
Verify the exploitation condition of 8 CVEs2–3 h
Find the public exploit for ~50 CVEs across 5 sources2 h
Cross-reference ~50 CVEs with the distribution tracker1–2 h
Write each finding in plain language, checked3–4 h
Per scan · estimated analyst-equivalent11–15 h

At a consultant's day rate, that's a working day and a half of analyst time — every night, not once a year.

The engine

What it does that a scanner doesn't

Every point below runs in production today and is drawn from real client scans — not a datasheet. And the depth of the examination is identical on every plan: what changes between tiers is how many targets, not how hard we look.

01

Black-box, or behind the login — your call

Scan it like an outsider, or hand us credentials and we go where the real surface lives: on one target, the outside view saw 12 entry points, the authenticated view 91. Credentials, OAuth/OIDC, SAML, tokens — authenticated scanning is on every plan, an option that opens the application up, never an obligation.

02

It scans APIs on their own terms

An API has no form to crawl; it needs its own probes. Scrytide runs dedicated API profiles alongside the application scan — included in every plan, because a modern estate is mostly API.

03

It discards what doesn't hold — and proves why

On one real campaign, 63 raw findings, 40 discarded: a CRITICAL path that didn't exist, a product fingerprinted from a 131-byte page, a standard TLS 1.3 cipher called "not recommended." Each discard carries its measurements — and becomes a permanent rule so it never returns.

04

It checks whether a CVE really applies

A version match isn't a vulnerability. Scrytide tests the exploitation condition on your actual configuration and states the result in the finding. On one client's Java application server, it measured the condition of each of eight CVEs in its HTTP stack — including one the NVD feed marked CRITICAL whose condition it found absent.

05

It finds the public exploit — and names it

For each CVE, five sources are queried. When exploit code exists, the finding names the exact CVE and links it. "Two CVEs have exploits" tells you nothing you can act on; a named CVE you can look up, judge and prioritise.

06

It cross-references the distribution

Debian backports security fixes without changing the upstream version number — so a server can look "vulnerable" while being patched. Scrytide checks each CVE against the distribution tracker, lowers the severity when it's fixed, and hands you the command to confirm the package yourself.

07

It knows when it could not test

Every control returns one of three states: it ran and got a usable answer, the surface legitimately isn't there, or the control couldn't work — an unproven negative. One detector fired 436 probes with no usable reply; an ordinary scanner would report "no vulnerability." Scrytide reports "this control established nothing."

08

It verifies the fix before calling it fixed

A finding is marked resolved only after a fresh measurement proves it — never on a declaration. Between scans, what you've accepted or fixed stays that way; what regressed comes back, dated.

09

It turns a block into information

When an application firewall blocks the scan, that's a finding, not a failure: the HTTP code, the recognised signature, and the exact list of checks that couldn't run — with the note that the protection is doing its job. And the scan continues on every other path.

10

It maps surface others miss

On one client, six DNS names — public site, staging, a CI console, a database interface — resolved to a single address, admin-panel names flagged distinctly rather than buried. And where classic engines returning 401/403 identified nothing, Scrytide read the headers: it recognises sixteen families of edge device by protocol signature and picked out an enterprise firewall and a carrier CPE where others saw a wall. Discovered names are reported, never scanned without authorisation.

11

It obtains an access — and uses it

This is the pentest mode. When a control wins an access — a default credential, a weak login — it drops it in a shared store, and later controls reuse it to reach what wasn't reachable without; a second pass replays them. The secret never appears in a report. Going further — real privilege escalation — happens only under written authorisation, scoped per perimeter.

12

It writes for a person, not a parser

Every finding carries four written parts: what it is in plain terms, why it matters on this configuration, how to fix it for the technology detected, and the command to verify the fix yourself. Every brief is written for a reader — plain language, not a raw dump of tool output.

Why a subscription, not a mission

A one-off audit is a photo.
Scrytide is a curve.

This isn't a commercial preference — it's what the machine does. Much of what's been built makes no sense in a one-shot engagement: the first-detection date on every finding, the "open for 22 days" badge that turns amber when your decision window lapses, the automatic revocation of an accepted risk when the facts behind it change.

And the known surface grows with time: each campaign can reach hosts and endpoints the last one didn't, so the value of the product increases with the length of the subscription.

  • Nightly campaign, per clientrestricted to the targets you authorise
  • First-detection date & ageing"open for 22 days" — proof of progress for your auditor
  • State preserved between scansan accepted risk stays accepted until the facts change
  • Growing discoverythe known surface of a target expands scan after scan
  • Twelve-month history30 daily reports, then monthly — retained automatically
The report

Two readers. One document.

Your engineers need a fix and a way to check it. Your director needs to know whether to worry. Every Scrytide report carries a technical view with the confirmed findings and their evidence, and a summary view that says plainly where you stand.

Written for a reader — so you can hand a finding to a supplier or a committee without a translation and a meeting first. A report kept for twelve months that a regulated client can put in front of an auditor.

A finding, as it reads
Expired certificate — CI console, exposed to the internet
Why it matters here"The risk isn't the browser warning — it's what it becomes. Your users have seen it for months. They've learned to click 'proceed anyway' — so they'd accept a fraudulent certificate the same way, without noticing."
Verify it yourself…a single command, for the exact package and version detected.
How far it goes

We exploit to prove — never to damage.

This is the boundary a regulated buyer wants drawn in black and white — and where the pentest-like depth ends.

It goes far enough to be sure. It stops before harm.

Verifying an exploitation condition, obtaining an access and reusing it — that is real, and it's the depth a plain scanner never reaches. What Scrytide will not do is cross into harm: for a few vulnerabilities — request smuggling, compressed-response desync, HTTP-trailer leakage — a proof would mean poisoning a real visitor's response, and a third party would bear it. Full privilege escalation happens only under written authorisation, scoped per perimeter.

"We exploit only to measure. We degrade no service, we alter none of your data, and we leave nothing behind."

It doesn't replace a human pentester

We prove access and verify conditions; we don't reason about your business logic or chain multi-step abuse the way a person does. That judgement stays human.

It isn't a compliance certificate

We produce evidence useful to a NIS2 or ISO 27001 file — we don't deliver the certification itself.

For a regulated buyer

The questions a DPO asks before the technical ones

A public buyer or a data-protection officer looks for these before they look at the engine. Each one is built and running.

Access

A dedicated client portal

Daily history, behind multi-factor authentication and network-level restrictions. Reports are served by the application, never by a direct download link that could leak.

Data

Erasure & retention, implemented

Retention windows that are actually enforced, not promised — and complete erasure of a client's data on request, in one command. Secrets are never stored in cleartext, and sensitive values inside a proof are masked.

Location

European, end to end

Processing stays in the EU. AI-assisted analysis runs on EU infrastructure that neither reads, keeps nor trains on your data — never a consumer AI service. Encrypted, off-site backups, encrypted before they leave.

Fit

Who this is for — and who it isn't

Being clear about this saves us both a wasted meeting.

Built for you if…

  • You run web applications, APIs or internet-facing infrastructure that matter to the business
  • You want the analyst's verdict — verified, sorted, written — not a raw list to triage yourself
  • You're regulated and need evidence an auditor will accept
  • You need your data to stay in the EU, never sent to a consumer AI service

Probably not the right fit if…

  • You want a self-service scanner licence, with no human review attached
  • You're buying to tick a compliance box rather than to find real exposure
  • What you need isn't web, API or infrastructure testing at all
Pricing

Priced against a pentest — not a scanner licence.

A scanner subscription and Scrytide aren't the same product: one hands you a raw list, the other hands you the analyst's verdict. So the honest yardstick isn't a licence fee — it's what a manual security review costs, and how often you actually get one.

€8 000–12 000
a one-application penetration test — a week of work, one report, then eleven quiet months
vs
from €15 000 / year
same order of price — but up to three of your targets, verified every night, all year

Same order of price as a once-a-year review, for continuous coverage and every fix checked before it's called fixed. What it doesn't do is replace a pentester's judgement on business logic — that boundary stays in writing, above.

A target is anything you point us at — a web app, an API, an IP, a host. That's the whole unit: there's no separate count for APIs, endpoints or environments behind it. Scan it black-box, or hand us credentials to go deeper; either way, we only scan what you authorise in writing. Same engine, same depth on every plan — only the number of targets changes.
Surface
A small estate — up to three targets
15 000/ year
billed annually · nightly campaign · human review included
  • Up to 3 targets — web apps, APIs, IPs, any mix · up to 2 credential sets
  • The full engine on every target: black-box or authenticated, triage, condition verification, named exploits, auto-escalation
  • Twelve-month history · state kept between scans · report written for a reader, not a parser
  • Per-client isolation · dedicated client portal · EU-only processing
Request a scoped quote
Recommended
Scope
A mid-sized, multi-site organisation
30 000/ year
billed annually · nightly campaign · human review included
  • Everything in Surface, at the same depth — just more of your estate:
  • Up to 10 targets — any mix of web apps, APIs, IPs, hosts
  • Up to 10 credential sets — production, staging, whatever you point us at
Request a scoped quote
Group
Holdings and large estates
Custom
transparent scoping · dedicated capacity
  • Everything in Scope, at the same depth:
  • More than 10 targets
  • Dedicated scanning capacity, sized to your estate
  • One scope, one contract, across everything you run
Talk to us

Each additional target on Surface is €4 000 / year — so by the seventh, Scope (up to 10 targets) already costs less. Past 10, it's Group: dedicated capacity sized with you, not a per-target surcharge — because a dozen-plus targets a night is a throughput question, not a line item. You move up by arithmetic, never because a feature was held hostage.

Priced on scope — never on findings.

Your price is set by the scope you declare at signing, and it doesn't move with what we find. Add a target and the price changes; find a hundred vulnerabilities inside it and it doesn't. You're never billed per vulnerability, per alert or per scan — that would only pay us to inflate a count.

€6 000
one-off audit

Not ready to subscribe? Start with a dated snapshot.

A full campaign, the written report, and a re-check at thirty days — a finding, dated, not a stripped-down subscription. Subscribe within 60 days of that re-check and it's deducted from your first year — a first step into continuous coverage, not a cheaper alternative to it.

Request an audit

Point us at one target you think is clean.

We'll scan it free, under NDA, then walk you through what comes back — a 30-minute live session once the scan has run, with the evidence for every confirmed finding and an honest account of anything we couldn't test. You'll leave that session knowing whether we're worth your time.

Request your free scan
One target · mutual NDA · a 30-minute live walkthrough after the scan runs, not the full written report · read-only · we only scan what you authorise in writing.