Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Solutions / Regulated

For regulated industries

When the code genuinely cannot leave.

Banking, insurance, health and government buyers often cannot use code-aware tooling at all, because the tooling wants the source. That constraint is the reason the agent exists.

Say this first

We do not make anyone compliant

No tool does, and a vendor who tells you otherwise is selling you a problem for later. Your regulator assesses you, on your controls, against your framework. What a testing tool can honestly offer is a way to do the testing your obligations already require, and evidence an assessor can follow.

Cyberlop Labs holds no certification and no empanelment. Not one. If your procurement requires an attestation or an empanelment number from the tool vendor before a pilot can start, we are too early for you, and we would rather say so now than spend a quarter of your time finding out. If you can run a technical evaluation on its own merits, we would like to talk.

The cycle you are already on

Somebody has set your testing calendar

You are not choosing whether to test. You are choosing what happens in the months between the tests your regulator already put on the calendar.

India: RBI and SEBI

Banks, NBFCs and market intermediaries run to a supervised cycle, with assessments and reporting obligations that do not move because a release slipped. The engagement is fixed; the application changes weekly. That gap is the part we cover.

The Gulf: NESA, NCA and SAMA

Buyers in the UAE work to NESA IAS v2; Saudi entities to NCA ECC-2, and financial institutions to the SAMA Cyber Security Framework. Each puts application testing and remediation evidence inside a mandated control set on a defined cadence.

Mandated work routes through your partner

Where a regulator requires a report signed by an empanelled firm, that firm signs it. We do the cross-role and business-logic testing underneath, and the empanelled partner reviews the evidence and puts their name on the deliverable. We are not that firm and will never present ourselves as one. How the partner route works →

Everything else is yours to schedule

Between the mandated engagements, run it nightly on staging or on every merge. Web applications and their APIs only. We do not touch networks or infrastructure, so the scope you authorise is narrow and easy to write down.

Constraints

The ones that normally end the conversation

Source cannot leave

Run the agent inside your own network. The code is read on your hardware and never transmitted. Four outbound calls, zero inbound ports, and your security team can watch all four. Private deployment is priced as an upgrade at $944 per application per year, so it is a line item you can put in a paper before you commit.

Everything must be attributable

A per-organisation audit log of who ran what, who changed which finding state, and who touched which credential. Timestamped, scoped to you, exportable.

Access must be least-privilege

Forty-three discrete permissions with roles, teams and group grants, single sign-on through Okta per organisation, and time-based multi-factor. Enforced at the API rather than hidden in the interface: 105 routes are verified against the authorization policy at boot, every boot.

Nothing may leak sideways

Each organisation holds its own database schema, so cross-customer access is structurally impossible rather than filtered out by a query someone can forget. Credentials sit in a vault encrypted at rest with a managed key backend. It is a short paragraph to write in an assessment because it is a short thing to describe.

Evidence

What you can hand an assessor

Live

Proof, not assertion

Every finding carries the request, the response, the screenshot and the line of code. An assessor reading it can see what was done and reproduce it, which is a different conversation from reading a severity label.

Live

Standard references

Findings carry CWE and OWASP references, so mapping them into the control language your assessor already uses is a translation rather than an argument.

Live

Complete history

Every scan, every finding state change, every actor, timestamped and exportable. The remediation trail is the record, not a spreadsheet somebody maintained afterwards.

27 Oct

Security questionnaire pack

The answers your vendor-risk team will ask us for, written once and published, so the third-party review does not stall waiting on a form.

16 Nov

Proof of remediation

Not a claim that an issue was fixed, but a record of the exploit working, the change, and the same exploit then failing. Rescanning is a new guess; re-exploiting is proof.

2 Feb

Compliance evidence packs

Auditor artefacts that map findings and their remediation trail onto the framework you are assessed against. It ships 2 February 2027. It is an evidence format, not a certification, and it does not make you compliant. Your assessor decides that.

Being honest

What we do not have yet

You would find these in week three of a pilot. Better here.

No certification, no empanelment

We hold none, and none is in progress that we can point you at. Everything on this page is about the testing and the evidence, not about a badge we do not have.

No data residency regions yet

You cannot pin the hosted control plane to a region today. If residency is a hard requirement, run the agent inside your own network so the source and the scanning stay with you, and talk to us about what the control plane holds before you commit.

No published detection rate

None, and we will not invent one. The benchmark publishes 3 November against Juice Shop, WebGoat, DVWA and real open-source applications with known CVEs, including the misses. What we have not proved →

The operations are young

Off-box backups, a timed restore drill and a public status page land 18 December. Today we run the platform closely by hand, which works at this size and will not forever. Our security posture →

Bring your review board.

Those constraints are the ones that normally end a procurement, so bring the people who enforce them. We will take your architecture and security teams through the deployment model and answer their questions on the call.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.