Your customer asked for a penetration test
Usually it arrives as a line in a security questionnaire, or a condition on a contract you are trying to close. You need a real test, evidence it happened, and the problems fixed. Not in six weeks.
What happens
Ryvx will not test a domain until you have demonstrated you control it, by placing a file it gives you at a URL on that domain. This is not a formality. It is the reason you can hand the resulting report to a client without a conversation about authorization.
A finding is only reported if Ryvx can produce a working proof of concept for it. Anything it merely suspects is discarded. That is the single most important thing on this page, because the usual complaint about automated security tools is that someone on your team spends a week disproving a list.
This part is arranged with us, not a toggle in the product: connect a repository through Ryvx and, for findings in code it can reach, we open a draft pull request against it with the change, then re-scan the diff to confirm the fix held. Your developers review a proposed fix instead of translating a PDF into work.
A report with each finding, its CVSS score and the arithmetic behind it, the proof, the remediation, and the mapping to the frameworks your customer is asking about: SOC 2, ISO 27001, PCI DSS, CIS and NIST CSF. Exportable as PDF, or as a machine format your tooling can ingest.
What it refuses to do
This matters more to a buyer than the feature list, so it is stated plainly rather than buried in documentation.
It does not exploit without permission
Proving a vulnerability and taking advantage of it are different actions. Ryvx does the first by default. The second requires you to switch it on deliberately, and against a target marked production it stops and asks a human first. Run unattended, it refuses rather than proceeding.
It does not wander
Every request is checked against the scope you authorized, before it is sent and again after the response. If a redirect would take it somewhere you did not authorize, it stops and records the attempt rather than following it.
It does not report what it cannot show you
If the evidence is not there, the finding does not ship. If part of the analysis could not run, the report says so on its face rather than letting a clean-looking result imply more than it earned.
It keeps the receipts
Every action every agent takes is written to an append-only audit trail, delivered with the report. If anyone ever asks what was done to their systems, the answer is a file, not a recollection.
What it costs
Credit-based, billed through Stripe, with no per-seat license and no annual minimum, and no subscription required. A full deep pentest is 100 credits; a standard compliance scan is 50 credits; a light recon pass is 20 credits. Buy credits as needed; current prices are on the pricing page and unused credits roll forward, no expiry.
Ryvx Compliance is not a PCI Approved Scanning Vendor and does not issue compliance certification.
You can also run it entirely on your own machine with your own model API key, in which case you pay your model provider directly and nothing leaves your network except what you choose to send.
If you resell to your own clients
Everything above assumes you are the one being tested. If you are a consultancy or an MSSP instead, you can run Ryvx on behalf of your clients and hand the report onward under your own name. That is the Partner plan.
The report is yours, not ours
Your name, your logo, your accent color, your footer. No Ryvx mark anywhere on the deliverable.
You keep the relationship
Your client deals with you. Ryvx is the engine running underneath, not a name they see.
The authorization is still yours to hold
The domain-control step above runs against your client's systems the same as it would against your own, and you are the one responsible for holding that client's authorization to test them before you point Ryvx at anything.
We carry no professional indemnity insurance
Ryvx is a UK sole trader with no PI cover and no SOC 2. If an engagement of yours needs either, that is arranged by you, not inherited from us.
Priced separately from the plans above, on volume across your whole client book rather than per scan. See the Partner plan on the pricing page.
What we are not going to claim
Everything above is a description of what the product does. None of it is a claim about how well it does it, and the difference matters if you are betting a customer relationship on the answer.
One run, not a rate
We publish one scored benchmark result, on a public deliberately vulnerable application, graded by that application's own scoreboard rather than by reading our own report. It is one run. One run is not a rate, and we say so on the benchmarks page.
No quoted false-positive rate
We do not quote a false-positive rate, because we have not independently verified one. Quoting a number we cannot show the working for would be exactly the behavior this product exists to avoid.
Not a substitute for a specialist
An automated test is not a substitute for a human specialist on a novel, high-stakes system. It is a substitute for not testing, for testing once a year, and for the six weeks between deciding you need a test and receiving one.
See it rather than read about it
One real finding from a real run is published in full: the filed finding, the proof of concept, what the target actually returned, and an excerpt of the audit trail behind it. It is the fastest way to judge whether this is worth your time.
Ryvx is for systems you own or are contracted to test. Domain control is verified before any live target is touched, and exploitation against a production-tagged target requires a human decision at the time it happens. See the security policy for the full position.