Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / About

Cyberlop Labs

We got tired of findings nobody believed.

Built in New Delhi, in three parts: the problem we kept running into, what we built about it, and what we are honest about.

Part one

The problem

Every team we spoke to had the same two problems, and neither was the one their tooling was sold against.

The scanner produced hundreds of findings and nobody trusted any of them. Triage became a permanent tax: an engineer spending an afternoon proving a thing was not real, then doing it again next week. A list that long is not coverage. It is a queue nobody will ever reach the bottom of.

And the annual penetration test produced a document that was accurate for about a week. After that the application kept changing and the report kept ageing, until the next engagement found problems that had been shipped eleven months earlier.

Both problems have the same root: the tool cannot prove anything. It cannot prove a finding is real, and it cannot prove a fix worked. Underneath that sits a smaller, stranger fact. A scanner has one login. It can be a visitor. It cannot be a customer, an admin and a support agent at the same time, so it can never answer the question a breach actually turns on: who can see what?

Part two

What we built

Cyberlop is application security testing that logs in as every user role, reads your code while attacking your running app, and reports only what it exploited, with the request, the screenshot and the line. It proves the fix, runs inside your own network, and costs less than one scanner target. Close the loop.

We built around proof instead of around coverage, and named the company after the part everyone else leaves out. Three ideas carry the whole product.

Who can see what.

Every role against every door. Green means locked. Pink means someone got in who shouldn’t.

Exploited, not suspected.

If we didn’t break it, we don’t report it. Then we prove the fix.

Your code never leaves.

Runs on your machine. Four outbound calls, zero inbound ports.

Where this goes

Vision and mission

Vision

Every app tested the way an attacker would test it

Every app tested the way an attacker would test it (every role, every door, every deploy) and every fix proven, not promised.

Mission

A platform priced for the smallest security team

We give security teams, and the firms that serve them, a platform that logs in as every role, reads the code while attacking the running app, reports only what it exploited, and proves the fix, inside the customer’s own network, at a price a five-person company can pay.

How we decide things

Five values

Every job description, interview and review refers to these by name. They are not on a wall; they are what an argument here gets settled with.

Receipts or nothing.

Proof over claims. A finding without the request, the screenshot and the line isn’t a finding.

Say the hard thing.

Publish the misses. Tell the customer their access control is good when it is.

Never test without permission.

The scope is sacred. No demo scans of anyone’s production, ever.

Your code stays yours.

Privacy by architecture, not by policy.

Close the loop.

Find, exploit, fix, verify. Nothing is done until the re-exploit fails.

Part three

What we are honest about

We are early, and we say so. There is no published detection rate on this site, because we have not measured one honestly yet and we are not going to invent one this week against a test set we picked ourselves. The benchmark publishes 3 November against Juice Shop, WebGoat, DVWA and real open-source applications with known CVEs. It carries the detection rate, the false-positive rate, the wall-clock duration and the dollars per scan, with the misses included. If the numbers are ugly, you will see them anyway.

We hold no certification and no empanelment. If your procurement needs one before a pilot can start, we are too early for you, and saying that now is cheaper for both of us than saying it in February.

We are also narrower than the category on purpose. Web applications and their APIs only. No networks, no infrastructure. There is no free tier and no per-scan billing. Price is a fact, not an apology. Those are choices, and for some buyers they are the wrong ones. The full list of what we have not proved →

Who is building it

Built in New Delhi

Cyberlop Labs builds Cyberlop from New Delhi, India. The people who write the product are the people you deal with, so a question about how something works reaches somebody who can answer it rather than a support queue.

We set up every account by hand. That is slower than a signup form and it is deliberate: we would rather understand what you have built before we test it, and tell you early if we are the wrong fit.

We also run remote internships for people who want to learn this work properly. What they involve →

Talk to the people who built it.

Whoever takes the demo works on the product, so bring the awkward questions. You will get a straight answer, including when the answer is that we cannot do it yet.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.