Most scanners produce a long list of "possible" issues and leave the sorting to you. Scrytide does that work: it scans behind the login, discards what doesn't hold with a written justification, verifies whether a vulnerability actually applies to your configuration, names the public exploit, and tells you plainly what it couldn't test. All read-only.
Point us at one target See how it worksAnyone can produce a list of possibilities. The value is in eliminating everything that isn't real — and being honest about what couldn't be checked — before a person has to read it.
Turning a raw scan into something a team can act on is analyst work — and a scanner leaves all of it on your desk. On one real client campaign, we estimate that at eleven to fifteen hours. Scrytide does it, and then it starts over on the next scan.
At a consultant's day rate, that's a working day and a half of analyst time — every night, not once a year.
Every point below runs in production today and is drawn from real client scans — not a datasheet. And the depth of the examination is identical on every plan: what changes between tiers is how many targets, not how hard we look.
Scan it like an outsider, or hand us credentials and we go where the real surface lives: on one target, the outside view saw 12 entry points, the authenticated view 91. Credentials, OAuth/OIDC, SAML, tokens — authenticated scanning is on every plan, an option that opens the application up, never an obligation.
An API has no form to crawl; it needs its own probes. Scrytide runs dedicated API profiles alongside the application scan — included in every plan, because a modern estate is mostly API.
On one real campaign, 63 raw findings, 40 discarded: a CRITICAL path that didn't exist, a product fingerprinted from a 131-byte page, a standard TLS 1.3 cipher called "not recommended." Each discard carries its measurements — and becomes a permanent rule so it never returns.
A version match isn't a vulnerability. Scrytide tests the exploitation condition on your actual configuration and states the result in the finding. On one client's Java application server, it measured the condition of each of eight CVEs in its HTTP stack — including one the NVD feed marked CRITICAL whose condition it found absent.
For each CVE, five sources are queried. When exploit code exists, the finding names the exact CVE and links it. "Two CVEs have exploits" tells you nothing you can act on; a named CVE you can look up, judge and prioritise.
Debian backports security fixes without changing the upstream version number — so a server can look "vulnerable" while being patched. Scrytide checks each CVE against the distribution tracker, lowers the severity when it's fixed, and hands you the command to confirm the package yourself.
Every control returns one of three states: it ran and got a usable answer, the surface legitimately isn't there, or the control couldn't work — an unproven negative. One detector fired 436 probes with no usable reply; an ordinary scanner would report "no vulnerability." Scrytide reports "this control established nothing."
A finding is marked resolved only after a fresh measurement proves it — never on a declaration. Between scans, what you've accepted or fixed stays that way; what regressed comes back, dated.
When an application firewall blocks the scan, that's a finding, not a failure: the HTTP code, the recognised signature, and the exact list of checks that couldn't run — with the note that the protection is doing its job. And the scan continues on every other path.
On one client, six DNS names — public site, staging, a CI console, a database interface — resolved to a single address, admin-panel names flagged distinctly rather than buried. And where classic engines returning 401/403 identified nothing, Scrytide read the headers: it recognises sixteen families of edge device by protocol signature and picked out an enterprise firewall and a carrier CPE where others saw a wall. Discovered names are reported, never scanned without authorisation.
This is the pentest mode. When a control wins an access — a default credential, a weak login — it drops it in a shared store, and later controls reuse it to reach what wasn't reachable without; a second pass replays them. The secret never appears in a report. Going further — real privilege escalation — happens only under written authorisation, scoped per perimeter.
Every finding carries four written parts: what it is in plain terms, why it matters on this configuration, how to fix it for the technology detected, and the command to verify the fix yourself. Every brief is written for a reader — plain language, not a raw dump of tool output.
This isn't a commercial preference — it's what the machine does. Much of what's been built makes no sense in a one-shot engagement: the first-detection date on every finding, the "open for 22 days" badge that turns amber when your decision window lapses, the automatic revocation of an accepted risk when the facts behind it change.
And the known surface grows with time: each campaign can reach hosts and endpoints the last one didn't, so the value of the product increases with the length of the subscription.
Your engineers need a fix and a way to check it. Your director needs to know whether to worry. Every Scrytide report carries a technical view with the confirmed findings and their evidence, and a summary view that says plainly where you stand.
Written for a reader — so you can hand a finding to a supplier or a committee without a translation and a meeting first. A report kept for twelve months that a regulated client can put in front of an auditor.
This is the boundary a regulated buyer wants drawn in black and white — and where the pentest-like depth ends.
Verifying an exploitation condition, obtaining an access and reusing it — that is real, and it's the depth a plain scanner never reaches. What Scrytide will not do is cross into harm: for a few vulnerabilities — request smuggling, compressed-response desync, HTTP-trailer leakage — a proof would mean poisoning a real visitor's response, and a third party would bear it. Full privilege escalation happens only under written authorisation, scoped per perimeter.
We prove access and verify conditions; we don't reason about your business logic or chain multi-step abuse the way a person does. That judgement stays human.
We produce evidence useful to a NIS2 or ISO 27001 file — we don't deliver the certification itself.
A public buyer or a data-protection officer looks for these before they look at the engine. Each one is built and running.
Daily history, behind multi-factor authentication and network-level restrictions. Reports are served by the application, never by a direct download link that could leak.
Retention windows that are actually enforced, not promised — and complete erasure of a client's data on request, in one command. Secrets are never stored in cleartext, and sensitive values inside a proof are masked.
Processing stays in the EU. AI-assisted analysis runs on EU infrastructure that neither reads, keeps nor trains on your data — never a consumer AI service. Encrypted, off-site backups, encrypted before they leave.
Being clear about this saves us both a wasted meeting.
A scanner subscription and Scrytide aren't the same product: one hands you a raw list, the other hands you the analyst's verdict. So the honest yardstick isn't a licence fee — it's what a manual security review costs, and how often you actually get one.
Same order of price as a once-a-year review, for continuous coverage and every fix checked before it's called fixed. What it doesn't do is replace a pentester's judgement on business logic — that boundary stays in writing, above.
Each additional target on Surface is €4 000 / year — so by the seventh, Scope (up to 10 targets) already costs less. Past 10, it's Group: dedicated capacity sized with you, not a per-target surcharge — because a dozen-plus targets a night is a throughput question, not a line item. You move up by arithmetic, never because a feature was held hostage.
Your price is set by the scope you declare at signing, and it doesn't move with what we find. Add a target and the price changes; find a hundred vulnerabilities inside it and it doesn't. You're never billed per vulnerability, per alert or per scan — that would only pay us to inflate a count.
A full campaign, the written report, and a re-check at thirty days — a finding, dated, not a stripped-down subscription. Subscribe within 60 days of that re-check and it's deducted from your first year — a first step into continuous coverage, not a cheaper alternative to it.
We'll scan it free, under NDA, then walk you through what comes back — a 30-minute live session once the scan has run, with the evidence for every confirmed finding and an honest account of anything we couldn't test. You'll leave that session knowing whether we're worth your time.
Request your free scan