fluid intelligence for continuous security

Your app keeps shipping. Your pentest tests yesterday's app.

A standing pentest on your external web and API surface: after every release, human-verified, one flat annual fee. Start with a free read-only check of your live site.

member of the Google for Startups Cloud Program

A 3D map of a company's external surface, root domain, hosts and endpoints, is drawn in green; one endpoint is flagged red as a high-severity signal and written up in a short report.

The free check

We look at your live site first.

Read-only, in ~20 minutes: at most ~300 page requests at ~1 per second, from one US IP. No logins, no test payloads, no port scanning. Nothing reaches your systems.

You get a short written report: every item, what we saw, and what an attacker could realistically do with it. It is yours whether or not anything follows.

How we check, and how to say no

Nothing scans until a researcher confirms your request.

flat · in writing

A report, or the hunt.

one-off · deep audit

€3,500fixed

One deep snapshot of your web app + API in 3-5 days: signed NIS2 / ISO 27001 report, a working PoC per finding, one retest included. For the audit, SOC 2, or the board.

the audit, in writing

standing hunt · every release

from

€9,900/ year

Your whole external surface, retested after every release. One flat annual fee, monthly on request. The fee does not grow with your release count.

How the hunt runs

A typical manual pentest is paid once, then months go dark. The standing hunt stays on, at one flat annual fee.

Replace the yearly snapshot.

Book 20 minutes and leave with a written annual fee, or a written decision not to proceed.

sales@rheono.dev