Skip to main content
For Enterprise

Your customer asked for a penetration test

Usually it arrives as a line in a security questionnaire, or a condition on a contract you are trying to close. You need a real test, evidence it happened, and the problems fixed. Not in six weeks.

What happens

01
You prove the target is yours

Ryvx will not test a domain until you have demonstrated you control it, by placing a file it gives you at a URL on that domain. This is not a formality. It is the reason you can hand the resulting report to a client without a conversation about authorization.

02
It tests, and it proves what it finds

A finding is only reported if Ryvx can produce a working proof of concept for it. Anything it merely suspects is discarded. That is the single most important thing on this page, because the usual complaint about automated security tools is that someone on your team spends a week disproving a list.

03
It can open the fix as a pull request

This part is arranged with us, not a toggle in the product: connect a repository through Ryvx and, for findings in code it can reach, we open a draft pull request against it with the change, then re-scan the diff to confirm the fix held. Your developers review a proposed fix instead of translating a PDF into work.

04
You get something you can send onward

A report with each finding, its CVSS score and the arithmetic behind it, the proof, the remediation, and the mapping to the frameworks your customer is asking about: SOC 2, ISO 27001, PCI DSS, CIS and NIST CSF. Exportable as PDF, or as a machine format your tooling can ingest.

What it refuses to do

This matters more to a buyer than the feature list, so it is stated plainly rather than buried in documentation.

It does not exploit without permission

Proving a vulnerability and taking advantage of it are different actions. Ryvx does the first by default. The second requires you to switch it on deliberately, and against a target marked production it stops and asks a human first. Run unattended, it refuses rather than proceeding.

It does not wander

Every request is checked against the scope you authorized, before it is sent and again after the response. If a redirect would take it somewhere you did not authorize, it stops and records the attempt rather than following it.

It does not report what it cannot show you

If the evidence is not there, the finding does not ship. If part of the analysis could not run, the report says so on its face rather than letting a clean-looking result imply more than it earned.

It keeps the receipts

Every action every agent takes is written to an append-only audit trail, delivered with the report. If anyone ever asks what was done to their systems, the answer is a file, not a recollection.

What it costs

Credit-based, billed through Stripe, with no per-seat license and no annual minimum, and no subscription required. A full deep pentest is 100 credits; a standard compliance scan is 50 credits; a light recon pass is 20 credits. Buy credits as needed; current prices are on the pricing page and unused credits roll forward, no expiry.

Ryvx Compliance is not a PCI Approved Scanning Vendor and does not issue compliance certification.

You can also run it entirely on your own machine with your own model API key, in which case you pay your model provider directly and nothing leaves your network except what you choose to send.

If you resell to your own clients

Everything above assumes you are the one being tested. If you are a consultancy or an MSSP instead, you can run Ryvx on behalf of your clients and hand the report onward under your own name. That is the Partner plan.

The report is yours, not ours

Your name, your logo, your accent color, your footer. No Ryvx mark anywhere on the deliverable.

You keep the relationship

Your client deals with you. Ryvx is the engine running underneath, not a name they see.

The authorization is still yours to hold

The domain-control step above runs against your client's systems the same as it would against your own, and you are the one responsible for holding that client's authorization to test them before you point Ryvx at anything.

We carry no professional indemnity insurance

Ryvx is a UK sole trader with no PI cover and no SOC 2. If an engagement of yours needs either, that is arranged by you, not inherited from us.

Priced separately from the plans above, on volume across your whole client book rather than per scan. See the Partner plan on the pricing page.

What we are not going to claim

Everything above is a description of what the product does. None of it is a claim about how well it does it, and the difference matters if you are betting a customer relationship on the answer.

One run, not a rate

We publish one scored benchmark result, on a public deliberately vulnerable application, graded by that application's own scoreboard rather than by reading our own report. It is one run. One run is not a rate, and we say so on the benchmarks page.

No quoted false-positive rate

We do not quote a false-positive rate, because we have not independently verified one. Quoting a number we cannot show the working for would be exactly the behavior this product exists to avoid.

Not a substitute for a specialist

An automated test is not a substitute for a human specialist on a novel, high-stakes system. It is a substitute for not testing, for testing once a year, and for the six weeks between deciding you need a test and receiving one.

See it rather than read about it

One real finding from a real run is published in full: the filed finding, the proof of concept, what the target actually returned, and an excerpt of the audit trail behind it. It is the fastest way to judge whether this is worth your time.

Ryvx is for systems you own or are contracted to test. Domain control is verified before any live target is touched, and exploitation against a production-tagged target requires a human decision at the time it happens. See the security policy for the full position.

STAY IN THE LOOP

Release notes and product updates, by email.

We'll send a confirmation email; you're not on the list until you click the link in it. See our privacy policy.