Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Honest

Straight talk

We haven’t published a detection rate.

And we are not going to make one up. Every tool in this space leads with a big number. We could cook one up this week against a test set we picked ourselves, and it would mean nothing. That is a decent reason to be sceptical of everyone else’s too.

Instead

A benchmark anyone can reproduce

Running against known-vulnerable applications and real open-source projects with known CVEs, then publishing everything, including what we got wrong.

Juice Shop

The OWASP teaching application. Node, deliberately riddled and well documented, so every miss is checkable against a published answer key.

WebGoat

OWASP’s Java equivalent. A different language and framework, to show the approach is not tuned to one stack.

DVWA

The PHP standard. Old, blunt and universally understood, which makes it a fair floor.

Real applications

Open-source projects with known CVEs, where nobody wrote the bugs to be found.

4Numbers published
3 NovPublication date
YesMisses included
2 MarNext run, diffed

What we will publish for every application: detection rate, false-positive rate, wall-clock duration and dollars per scan, plus the method, so anyone can run it themselves. If the numbers are ugly, you will see them anyway. That is rather the point.

Today

What we are missing right now

We would rather you found these here than three weeks into a pilot.

No published proof yet

The benchmark is dated, not done. Until 3 November, every claim on this site is one we can demonstrate live on your application. That is a different thing from a number, and we are not pretending otherwise.

No reference customers yet

We are early and we say so. The first customers are signing now. If you need three references in your industry today, we are not there.

The operations are young

Off-box backups, a timed restore drill and a public status page land 18 December. Cost and time caps per scan land 13 November. Today we run the platform closely by hand, which works at this size and will not forever.

Narrower by design

We do not compete on signature breadth, we do not scan networks or infrastructure, and there is no free tier. Those are choices, not gaps. For some buyers they are the wrong choices.

How we work

The rules we hold ourselves to

Receipts or nothing

A finding without the request, the screenshot and the line is not a finding. We do not invent numbers, testimonials, results or findings.

Say the hard thing

We publish the misses. We tell you your access control is good when it is. We report a slipped date the same week it slips.

Never test without permission

The scope is sacred. No demo scans of anyone’s production, ever. Not for a prospect, not out of curiosity.

Judge us on your own application

Until the benchmark publishes there is no number for us to hand you, so a demo is the substitute. We run it while you watch, and you see what it catches and what it walks straight past.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.