From adding a target to a verified fix and a report your board can read.
Add a domain, IP address, or CIDR range. It's validated immediately for SSRF safety: private IP ranges, DNS-rebinding attempts, and cloud metadata endpoints are all blocked before a scan ever touches it.
Choose Quick for a fast pass or Comprehensive for full coverage. Scans run in the background across Nmap, Nikto, httpx, SSLyze, and WhatWeb, and process concurrently across multiple targets.
Every finding gets a CVSS-based severity rating and specific remediation guidance, not generic advice to 'apply security patches.'
Assign, comment, and track status on individual findings without leaving Cysvera.
Trigger a targeted retest on a finding you've marked fixed. If the vulnerability is still there, Cysvera reopens it automatically instead of trusting that "fixed" means fixed.
Every completed scan plots a new point on your risk trend chart, plus a diff against your last scan: new findings, resolved findings, unchanged findings.
A severity-filtered, per-target scoped PDF mapped to SOC 2 Type II, ISO 27001, and PCI DSS v4.0, ready for your board, your auditor, or an enterprise prospect's security questionnaire.
No. Cysvera scans from the outside in. You add your domains and IPs, we handle everything else remotely. No agents, no internal access required.
It depends on target size and scan mode. Quick scans are built for a fast pass; Comprehensive scans run the full scanner suite and take longer. Either way, scans run in the background, so you don't have to sit and watch a progress bar.
Nmap for port and service discovery, Nikto and httpx for web-layer issues, SSLyze for TLS/SSL misconfigurations, and WhatWeb for technology fingerprinting. All open-source, all industry-standard.
Retest that specific finding from its detail page. Cysvera reopens it automatically if the vulnerability is still present, instead of silently trusting that a status change means it's gone.
All scan findings and evidence logs are stored in an isolated tenant database. Evidence logs use SHA-256 checksums to detect tampering. Your data is never shared with other tenants.
Yes. The executive report is designed to be readable by non-technical stakeholders. You can share it directly with investors, enterprise prospects, or auditors.
Add your first target and get an executive security report in minutes.