Home / Solutions / Regulated
For regulated industries
When the code genuinely cannot leave.
Banking, insurance, health and government buyers often cannot use code-aware tooling at all, because the tooling wants the source. That constraint is the reason the agent exists.
Say this first
We do not make anyone compliant
No tool does, and a vendor who tells you otherwise is selling you a problem for later. Your regulator assesses you, on your controls, against your framework. What a testing tool can honestly offer is a way to do the testing your obligations already require, and evidence an assessor can follow.
Cyberlop Labs holds no certification and no empanelment. Not one. If your procurement requires an attestation or an empanelment number from the tool vendor before a pilot can start, we are too early for you, and we would rather say so now than spend a quarter of your time finding out. If you can run a technical evaluation on its own merits, we would like to talk.
The cycle you are already on
Somebody has set your testing calendar
You are not choosing whether to test. You are choosing what happens in the months between the tests your regulator already put on the calendar.
India: RBI and SEBI
Banks, NBFCs and market intermediaries run to a supervised cycle, with assessments and reporting obligations that do not move because a release slipped. The engagement is fixed; the application changes weekly. That gap is the part we cover.
The Gulf: NESA, NCA and SAMA
Buyers in the UAE work to NESA IAS v2; Saudi entities to NCA ECC-2, and financial institutions to the SAMA Cyber Security Framework. Each puts application testing and remediation evidence inside a mandated control set on a defined cadence.
Mandated work routes through your partner
Where a regulator requires a report signed by an empanelled firm, that firm signs it. We do the cross-role and business-logic testing underneath, and the empanelled partner reviews the evidence and puts their name on the deliverable. We are not that firm and will never present ourselves as one. How the partner route works →
Everything else is yours to schedule
Between the mandated engagements, run it nightly on staging or on every merge. Web applications and their APIs only. We do not touch networks or infrastructure, so the scope you authorise is narrow and easy to write down.
Constraints
The ones that normally end the conversation
Source cannot leave
Run the agent inside your own network. The code is read on your hardware and never transmitted. Four outbound calls, zero inbound ports, and your security team can watch all four. Private deployment is priced as an upgrade at $944 per application per year, so it is a line item you can put in a paper before you commit.
Everything must be attributable
A per-organisation audit log of who ran what, who changed which finding state, and who touched which credential. Timestamped, scoped to you, exportable.
Access must be least-privilege
Forty-three discrete permissions with roles, teams and group grants, single sign-on through Okta per organisation, and time-based multi-factor. Enforced at the API rather than hidden in the interface: 105 routes are verified against the authorization policy at boot, every boot.
Nothing may leak sideways
Each organisation holds its own database schema, so cross-customer access is structurally impossible rather than filtered out by a query someone can forget. Credentials sit in a vault encrypted at rest with a managed key backend. It is a short paragraph to write in an assessment because it is a short thing to describe.
Evidence
What you can hand an assessor
Proof, not assertion
Every finding carries the request, the response, the screenshot and the line of code. An assessor reading it can see what was done and reproduce it, which is a different conversation from reading a severity label.
Standard references
Findings carry CWE and OWASP references, so mapping them into the control language your assessor already uses is a translation rather than an argument.
Complete history
Every scan, every finding state change, every actor, timestamped and exportable. The remediation trail is the record, not a spreadsheet somebody maintained afterwards.
Security questionnaire pack
The answers your vendor-risk team will ask us for, written once and published, so the third-party review does not stall waiting on a form.
Proof of remediation
Not a claim that an issue was fixed, but a record of the exploit working, the change, and the same exploit then failing. Rescanning is a new guess; re-exploiting is proof.
Compliance evidence packs
Auditor artefacts that map findings and their remediation trail onto the framework you are assessed against. It ships 2 February 2027. It is an evidence format, not a certification, and it does not make you compliant. Your assessor decides that.
Being honest
What we do not have yet
You would find these in week three of a pilot. Better here.
No certification, no empanelment
We hold none, and none is in progress that we can point you at. Everything on this page is about the testing and the evidence, not about a badge we do not have.
No data residency regions yet
You cannot pin the hosted control plane to a region today. If residency is a hard requirement, run the agent inside your own network so the source and the scanning stay with you, and talk to us about what the control plane holds before you commit.
No published detection rate
None, and we will not invent one. The benchmark publishes 3 November against Juice Shop, WebGoat, DVWA and real open-source applications with known CVEs, including the misses. What we have not proved →
The operations are young
Off-box backups, a timed restore drill and a public status page land 18 December. Today we run the platform closely by hand, which works at this size and will not forever. Our security posture →
Bring your review board.
Those constraints are the ones that normally end a procurement, so bring the people who enforce them. We will take your architecture and security teams through the deployment model and answer their questions on the call.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.