Home / Honest
Straight talk
We haven’t published a detection rate.
And we are not going to make one up. Every tool in this space leads with a big number. We could cook one up this week against a test set we picked ourselves, and it would mean nothing. That is a decent reason to be sceptical of everyone else’s too.
Instead
A benchmark anyone can reproduce
Running against known-vulnerable applications and real open-source projects with known CVEs, then publishing everything, including what we got wrong.
Juice Shop
The OWASP teaching application. Node, deliberately riddled and well documented, so every miss is checkable against a published answer key.
WebGoat
OWASP’s Java equivalent. A different language and framework, to show the approach is not tuned to one stack.
DVWA
The PHP standard. Old, blunt and universally understood, which makes it a fair floor.
Real applications
Open-source projects with known CVEs, where nobody wrote the bugs to be found.
What we will publish for every application: detection rate, false-positive rate, wall-clock duration and dollars per scan, plus the method, so anyone can run it themselves. If the numbers are ugly, you will see them anyway. That is rather the point.
Today
What we are missing right now
We would rather you found these here than three weeks into a pilot.
No published proof yet
The benchmark is dated, not done. Until 3 November, every claim on this site is one we can demonstrate live on your application. That is a different thing from a number, and we are not pretending otherwise.
No reference customers yet
We are early and we say so. The first customers are signing now. If you need three references in your industry today, we are not there.
The operations are young
Off-box backups, a timed restore drill and a public status page land 18 December. Cost and time caps per scan land 13 November. Today we run the platform closely by hand, which works at this size and will not forever.
Narrower by design
We do not compete on signature breadth, we do not scan networks or infrastructure, and there is no free tier. Those are choices, not gaps. For some buyers they are the wrong choices.
How we work
The rules we hold ourselves to
Receipts or nothing
A finding without the request, the screenshot and the line is not a finding. We do not invent numbers, testimonials, results or findings.
Say the hard thing
We publish the misses. We tell you your access control is good when it is. We report a slipped date the same week it slips.
Never test without permission
The scope is sacred. No demo scans of anyone’s production, ever. Not for a prospect, not out of curiosity.
Judge us on your own application
Until the benchmark publishes there is no number for us to hand you, so a demo is the substitute. We run it while you watch, and you see what it catches and what it walks straight past.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.