How Cysvera works

From adding a target to a verified fix and a report your board can read.

01

Add your target

Add a domain, IP address, or CIDR range. It's validated immediately for SSRF safety: private IP ranges, DNS-rebinding attempts, and cloud metadata endpoints are all blocked before a scan ever touches it.

02

Run a scan

Choose Quick for a fast pass or Comprehensive for full coverage. Scans run in the background across Nmap, Nikto, httpx, SSLyze, and WhatWeb, and process concurrently across multiple targets.

NmapNiktohttpxSSLyzeWhatWeb
03

Review prioritized findings

Every finding gets a CVSS-based severity rating and specific remediation guidance, not generic advice to 'apply security patches.'

04

Fix it

Assign, comment, and track status on individual findings without leaving Cysvera.

05

Retest to verify

Trigger a targeted retest on a finding you've marked fixed. If the vulnerability is still there, Cysvera reopens it automatically instead of trusting that "fixed" means fixed.

REOPENEDif the fix didn't hold, otherwiseVERIFIED
06

Track your risk score over time

Every completed scan plots a new point on your risk trend chart, plus a diff against your last scan: new findings, resolved findings, unchanged findings.

07

Generate an executive report

A severity-filtered, per-target scoped PDF mapped to SOC 2 Type II, ISO 27001, and PCI DSS v4.0, ready for your board, your auditor, or an enterprise prospect's security questionnaire.

Frequently asked questions

Do I need to install anything on my servers?

No. Cysvera scans from the outside in. You add your domains and IPs, we handle everything else remotely. No agents, no internal access required.

How long does a scan take?

It depends on target size and scan mode. Quick scans are built for a fast pass; Comprehensive scans run the full scanner suite and take longer. Either way, scans run in the background, so you don't have to sit and watch a progress bar.

What scanners does Cysvera use?

Nmap for port and service discovery, Nikto and httpx for web-layer issues, SSLyze for TLS/SSL misconfigurations, and WhatWeb for technology fingerprinting. All open-source, all industry-standard.

What happens if a fix doesn't actually work?

Retest that specific finding from its detail page. Cysvera reopens it automatically if the vulnerability is still present, instead of silently trusting that a status change means it's gone.

How is my data stored?

All scan findings and evidence logs are stored in an isolated tenant database. Evidence logs use SHA-256 checksums to detect tampering. Your data is never shared with other tenants.

Can I share reports with my clients or investors?

Yes. The executive report is designed to be readable by non-technical stakeholders. You can share it directly with investors, enterprise prospects, or auditors.

Ready to see your attack surface?

Add your first target and get an executive security report in minutes.