Everyone else sells you a scan. We do the paperwork.
Ryvx checks your website every two weeks, asks you six plain questions, and writes the documents your bank, insurer or biggest customer is asking for: a dated certificate, an information security policy, an access control statement and an incident response plan.
Thirteen automated checks, a dated one-page certificate you can forward to an insurer or a lender, and an alert the day your checkout page changes. Ryvx is a UK sole trader, not a security firm with a badge to sell. This page says plainly what is checked, what you declare yourself, and the one thing it is not.
Free instant peek, no sign-up needed. Create a free account for the full report, or get the free desktop app.
Nine checks we ran. Eight questions you answered. Your report shows which is which.
Every run, every two weeks, produces a status board with twelve PCI DSS rows and five Cyber Essentials rows. Nine of those seventeen rows are checked by Ryvx itself, from real scan evidence: a header present, a cookie flag set, a component version current. The other eight rows need something a scan cannot see from the outside, like whether your card machines are locked up, and are answered by you directly, as six questions (two of them, firewall and antivirus, each answer one PCI row and one Cyber Essentials row at once).
A report showing seventeen identical green ticks is showing a reader eight boxes somebody ticked themselves, with no way to tell which ones. Ryvx labels every row by who established it, checked by Ryvx or declared by the business, and never lets a typed "yes" wear the same mark as a result the engine actually observed. That is the version that survives being read by an auditor, an insurer's claims handler, or your own board.
- Is there a barrier between the internet and your systems?
- Have all default passwords and settings been changed?
- Do you let your payment provider handle card numbers, rather than storing them yourself?
- Is your website properly encrypted?
- Do your computers have antivirus?
- Is your website free of known security holes?
- Can only the right people see customer data?
- Does everyone have their own login?
- Are card machines and paper records locked up?
- Do you keep a record of who accessed what?
- Do you test your security regularly?
- Do you have a written security policy?
- Is there a barrier between the internet and your systems?
- Is your website set up securely, with no default settings left on?
- Is your software kept up to date?
- Can only the right people get to customer data?
- Do your computers have antivirus?
The certificate and the paperwork under it, not a drawing of either.
Every image below is a real page from a real run of the code above, not a mockup. The business, domain and answers are invented for this example, and every document says so on its own first page.
Example run, not a real customer's report: Example Shop Ltd, example-shop.co.uk
The one-page document you forward to a bank, an insurer or a customer's security questionnaire. This example shows a business partway through: four of seventeen requirements declared by the business, the other thirteen still needing attention. A report showing everything fine on day one would be worthless, so the example does not pretend otherwise.
Same example business, three documents: Example Shop Ltd
Underneath the certificate, Ryvx writes three template documents generated straight from the answers you gave, so you start from a filled-in draft instead of a blank page. Each one opens by saying so on its own first page: a template, not legal advice, for the business named on it to check and complete before relying on it.
How the business protects customer data and what everyone working for it is expected to do. For staff to follow, and for anyone reviewing the business to read.
Who can reach customer data, how that access is given and taken away, and the one-person-one-login rule. For an auditor, insurer or bank checking who can see what.
What happens if there is a security incident or a data breach: who is told, in what order, and how fast. For the business's own team, and for anyone who asks whether one exists.
Thirteen checks, the same list every run.
A fixed, read-only battery, so the result is comparable from one run to the next rather than depending on what an agent happened to try this time, and so nothing changes about what gets checked between the day you sign up and the day a claim is on the line.
Their confirmation covers their form. Only their form.
Under PCI DSS v4.0.1, a merchant filling out SAQ A can satisfy requirements 6.4.3 and 11.6.1 by getting their payment provider to confirm its embedded payment solution protects against script attacks. That confirmation is real, and it covers exactly one thing.
- Their own embedded payment form
- “when implemented according to the TPSP’s/payment processor’s instructions”
- An analytics tag
- A chat widget
- A marketing pixel added and forgotten about
Most merchants do not know that boundary exists. None of the examples above are covered by the letter, and 6.4.3 still asks for an inventory of every script on the page, with a reason each one is there. 11.6.1 asks for a mechanism that alerts when a payment page's scripts or security headers change without authorization: a letter is a snapshot, and nobody is checking whether it's still true after the next redeploy.
Every external script by URL, integrity hash and crossorigin attribute. Every inline script by its own SHA-256 hash and byte length, never the script body itself.
Checked at least once every seven days. A changed script isn’t reported as an attack; it's reported as a change, with a plain “this changed, was that you?” asked of a human.
check_payment_page_scripts is what builds the 6.4.3 inventory; page_integrity.py is the 11.6.1 mechanism, holding a baseline and emailing you the day something changes.
This does not, by itself, satisfy 11.6.1 end to end. Ryvx provides the detection and the alert; you still have to read it, act on it, and separately maintain your own list of which scripts you authorized under requirement 6.4.3. Nothing here knows what you approved, only what changed.
A one-page certificate, built to be forwarded.
An insurance renewal that asks about your website. A customer's security questionnaire. A lender's due diligence checklist before they extend you credit. None of those three are PCI DSS, and all three land on a small business owner's desk regularly. Every run of Ryvx Compliance produces a dated, plain-English, one-page PDF you can forward instead of writing a paragraph from memory: what was tested, what was found, and what you declared yourself, each labeled by which is which. There is no percentage and no single number: a score invites being quoted out of context, so this document reports a plain count of what is in order and what needs attention instead.
Ryvx never writes that a customer is "certified", "compliant" or "accredited". This is a record of what was checked and what was declared, for you to send on, not a badge.
Not a PCI Approved Scanning Vendor
PCI DSS requirement 11.3.2 requires a quarterly external vulnerability scan performed by an ASV. Ryvx Compliance does not perform that scan and does not stand in for it. What it does, deliberately and well, is 6.4.3 and 11.6.1 above, plus the wider PCI DSS and Cyber Essentials status board: real, checkable evidence for exactly what it covers.
Tags on a finding, not a second checklist.
PCI DSS and Cyber Essentials get the full status board above because both are a fixed set of yes/no requirements. These four are different: every finding is mapped to the specific control it speaks to, one finding at a time: a mapping from a real finding to a real control id, not a claim that your business has been checked against the framework as a whole.
Against a consultant's day rate for the same paperwork.
Two optional add-ons. Thirteen automated checks and a forwardable certificate twice a month, no one's time booked. Billed on its own schedule, never metered in credits the way Strike and Agent are, and never grants or spends any.
See the full breakdown →Both cover one website. Checking more than one? Choose how many on the pricing page.
The parts a skeptical buyer would poke at, stated first.
The provider's letter still matters
Get it. It's free, it's worth having, and Ryvx is not a substitute for it. It confirms their own form resists script attacks when implemented to their instructions. It says nothing about anything else running on that page, which is the part Ryvx inventories every two weeks.
Not an ASV scan
This is not a PCI Approved Scanning Vendor scan. It does not satisfy PCI DSS requirement 11.3.2.
8 of 17 rows are self-declared
Not independently verified. They're labeled self-declared on the certificate, always.
Mappings, not an audit
SOC 2, NIST CSF, CIS Controls and ISO 27001 mappings are per-finding tags, not a completed audit against any of those frameworks.
A tool, not a firm
Ryvx is a UK sole trader with no security certification of its own. This product is the tool, not a firm vouching for you.