EU-hosted · GDPR-native · ISO 27001 aligned · SOC 2 Type II — roadmap 2026

Continuous AI penetration testing for web, API & cloud.

Real exploitation with reproducible proof of concept, from $69 per scan — with the evidence pack NIS2, DORA and ISO 27001 auditors ask for.

Free surface scan on the homepage. No signup. No card. No catch.
No credit card Surface preview in seconds Your data never trains our models

Read-only surface signals only (headers, TLS, tech, page counts). A full pentest needs an account and scan credit.

Built on & audited by
Cloudflare Workers (EU) Fly.io Frankfurt Anthropic AI (EU endpoint) Resend EU Polar.sh (Merchant of Record)
The reality

Annual pentests miss what ships on Tuesday.

A pentest signed off in January describes a system that no longer exists by March. Your team ships continuously. The attackers iterate continuously. The audit cadence is the only thing that hasn’t moved.

The result is a widening gap between what your last pentest verified and what is actually exposed to the internet today. That gap is where breaches are born — and where insurers, auditors and regulators are starting to look first.

AssurePort closes the gap by running the same depth of test your annual provider runs, but on every meaningful change — pull request, deploy, new endpoint, new cloud bucket, new domain.

What AssurePort is

A continuous penetration testing platform — not a scanner.

AssurePort is a continuous penetration testing platform that combines AI agents — trained against the OWASP, MITRE ATT&CK and CWE corpora — with deterministic security checks to find, prove and explain exploitable vulnerabilities across web applications, REST and GraphQL APIs, GitHub repositories and cloud configurations. It is operated from the European Union, with all data, scan logs and AI inference contained within EU-hosted infrastructure (Cloudflare EU + Fly Frankfurt + Anthropic EU endpoint).

AssurePort is not a vulnerability scanner with marketing on top. Scanners tell you what might be wrong. AssurePort proves what is exploitable, on your specific configuration, with a reproducible proof-of-concept attached to every critical finding.

How it works

Three steps to your first report.

No agents to install. No long onboarding. Sign up, point us at something, and read the report.

Step 01

Connect

Point AssurePort at a domain, a Git repository or a cloud account. Connections are read-only by default and revocable in one click.

Step 02

Test continuously

AI agents run authenticated scans, business-logic probes and controlled exploit attempts — every action mapped to OWASP, MITRE ATT&CK and CWE.

Step 03

Get auditor-ready reports

Each finding ships with severity, a reproducible PoC, the suggested remediation and CWE/CVE references. Export to PDF or JSON.

Free Toolkits

14 Free Threat Intel Tools. Zero Sign-up.

Diagnose DNS, TLS posture, security headers, tech stack, and email security instantly from the edge.

4 featured below — all 14 are one click away in the full toolkit.

CryptoCheck Grader

Check cryptographic hygiene, TLS/HSTS configuration, and post-quantum readiness with a viral SVG badge.

Test domain

Security Headers Grader

Score HTTP security headers (CSP, HSTS, CORS, SameSite) from A+ to F with actionable fixing advice.

Analyze headers

DNSBL Blacklist Audit

Verify if your public mail server or domain IP is listed on major spam reputation blocklists.

Check IP reputation

Email Spoofing Check

Audit SPF, DMARC, and DKIM policies to prevent attackers from sending emails as your domain.

Check posture
Coverage

One platform. Every surface that matters.

Stop assembling six scanners, a consultancy and a Friday-night spreadsheet. AssurePort covers every surface your auditor will ask about.

Web applications LIVE

OWASP Top 10, business-logic abuse, broken authentication, IDOR — full proof-of-concept.

REST / GraphQL APIs LIVE

OWASP API Top 10 2023. Auth bypass, BOLA, mass assignment, injection.

GitHub / Supply chain LIVE

Leaked secrets, vulnerable dependencies, IaC misconfigurations.

Cloud posture LIVE

AWS, Azure, GCP, Kubernetes. CIS Benchmark aligned. IAM blast-radius, exposed buckets, K8s API surface.

Active Directory LIVE

Kerberoasting, ACL gaps, DC recon. Read-only, non-destructive AD security assessment.

SAP LIVE

NetWeaver / S/4HANA auth gaps, ABAP and RFC misuse. Read-only analysis.

Email Security LIVE

SPF/DKIM/DMARC validation, phishing-kit detection, passive mail infrastructure reconnaissance.

Network / Host LIVE

TCP port and service discovery, product fingerprinting, and no-authentication exposure detection (open Redis/Elasticsearch/MongoDB/Docker API, anonymous FTP, SMTP open-relay). Detection only — no exploitation.

OSINT / Recon LIVE

Passive and light-active external footprinting: WHOIS/RDAP, certificate-transparency subdomain enumeration, full DNS records, origin-IP discovery behind a CDN, live subdomain probing. Your public attack surface, mapped.

Scan Import LIVE

Import an existing Nessus, OpenVAS, Nmap, Burp, CSV or PDF report and get an AI-triaged summary mapped to GDPR/NIS2/ISO. Turns raw findings into prioritised insight.

PCI-DSS External Vuln Scan LIVE

Quarterly external vulnerability scan following PCI-DSS Requirement 11.3.2 (ASV-style methodology). Automatically calculates CVSS v3.1 compliance and generates auditor-ready readiness reports. AssurePort is not a PCI SSC Approved Scanning Vendor; this scan does not replace a scan by a listed ASV.

All eleven coverage surfaces are live in production. Web and API pentests run controlled exploitation and attach a reproducible proof of concept. GitHub, Cloud, AD, SAP, Email, Network, OSINT, Scan Import and the PCI-DSS external scan are detection and passive analysis only. No engine performs destructive actions on any surface.
Trust & data handling

Your data is the product you are protecting. We treat it that way.

We built AssurePort with the assumption that the security teams using it would read our architecture diagram, our independent pentest report and our DPA before granting access. They do. Here is what they read.

Your data never trains our models.

All scan inputs, code excerpts, screenshots and findings are processed inside isolated, tenant-scoped containers. Nothing you give us — not a line of source code, not a screenshot, not a URL — is used to train AssurePort’s models or any third-party model. Contractually binding in our DPA. Anthropic EU endpoint enforces this at the infrastructure level.

EU-only infrastructure.

AssurePort is hosted exclusively on European infrastructure — Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction), Resend (EU). Anthropic AI inference is routed to the EU endpoint. Data, logs, AI inference and backups never leave the EU.

AI you can audit.

Every action an AssurePort agent takes is logged with the model used, the prompt, the tool call and the resulting output. You can replay any scan minute-by-minute and export the full trace for forensic review. 7-year retention, aligned with GDPR Article 32.

Read-only by default.

AssurePort never writes to your production systems, never executes destructive payloads, and never persists credentials beyond the lifetime of an authenticated scan. Domain Control Verification (DCV) and Rules of Engagement (RoE) validation are enforced as hard gates before any Advanced Mode scan proceeds.

Every finding ships with a reproducible PoC.

We refuse to ship a critical-severity finding without a proof-of-concept you can rerun in your own environment. If we cannot reproduce it deterministically, we do not call it critical. Period. Findings without a working PoC are automatically downgraded to unconfirmed.

We pentest AssurePort, too.

Our own platform is pentested before every release. The latest self-pentest report (May 2026: 5 findings, all remediated; SSRF + path-traversal + info-disclosure) is published on our Trust Center. External CREST-accredited audit is on our roadmap for Q4 2026 — Q2 2027 alongside ISO 27001 certification.

No model training. No data leaving the EU. Every action audit-logged.

How we compare

The honest comparison.

Annual pentest DIY scanners AssurePort
Frequency Once a year On-demand, manual Continuous, on every change
Surfaces covered What you pay for One per tool 11 engines live today
Time to first report 4–8 weeks Hours of setup Minutes, not weeks
Proof-of-concept per finding Sometimes No Always (reproducible)
Auditor-acceptable Yes No (raw output) Yes (CWE/CVE/OWASP mapped)
Remediation guidance Rarely No Yes, per finding
Annual cost (mid-size org) €40k–€120k €15k+ in licences From $69 one-time / $199 monthly
Transparency

We publish what we actually do.

No fabricated case studies. No anonymous metrics. We make claims we can back with a link.

The header of an AssurePort report: target host, DNS TXT ownership proof, scan type and completion date, beside a severity summary showing 1 critical, 2 high and 2 medium findings.
Every assessment opens with what was tested, how ownership was proven, and what was found. The screenshot is from our illustrative sample report; our own real one is linked in the card below. See the full report →

Latest self-pentest

10 August 2026, Web engine, our own platform: no vulnerabilities confirmed. The previous run (May 2026) found 5 — SSRF, path-traversal and info-disclosure — all closed before release. The PDF includes what the assessment could not cover.

Read the full report →

Public security disclosure

RFC 9116 security.txt with PGP-signed contact. Responsible disclosure policy. Researcher reports processed within 5 business days.

View security.txt →

Open certification roadmap

ISO 27001 + external CREST audit targeted Q4 2026 — Q2 2027. Public commitment, tracked monthly on our Trust Center.

View roadmap →
“We chose ‘continuous AI pentest’ as a category because the alternative — annual pentest + quarterly scanner reports — was demonstrably failing the customers we talked to. We publish our own findings. We publish our own roadmap. We publish our own architecture. That’s the bar.”
AssurePort engineering team — May 2026
Product Roadmap

What we are building next.

We build in public. Here is a transparent look at our upcoming capabilities and release schedule.

Planned Q3 2026

Alternative Domain Verification

Verify domain control quickly using automated administrative email codes (security@, admin@) or placing a meta-tag in the homepage header, bypassing DNS delays.

In Development

Slack & Teams Notifications

Get instant, real-time vulnerability alerts and scan completion reports delivered directly to your engineering channels with action links.

In Development

Agent-to-Agent Threat Feeds

Connect multiple isolated scanning agents together to dynamically share OSINT indicators and coordinate passive external threat intelligence.

FAQ

Frequently asked questions

Is AI penetration testing actually reliable?
Yes, when it is built correctly. AssurePort’s agents do not freelance — they operate inside a deterministic test harness that enforces scope, prevents destructive actions and verifies every finding with a reproducible proof-of-concept. Findings without a working PoC are automatically downgraded to unconfirmed rather than published as critical.
Will my code or data be used to train AI models?
No. All inputs — source code, screenshots, URLs, scan results — are processed in tenant-isolated containers and are never used to train AssurePort’s models or any third-party model. This is in our DPA. Anthropic’s EU endpoint API agreements independently prevent training on API traffic.
Where is my data stored?
Exclusively in the European Union. We use Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction) and Resend (EU). Anthropic AI inference is routed to the EU endpoint. No data crosses the EU border.
How is AssurePort different from a vulnerability scanner like Nessus or Burp Suite?
Scanners tell you what might be vulnerable. AssurePort proves what is exploitable on your specific configuration and ships a reproducible proof-of-concept with every critical finding. It also covers eleven attack surfaces in one platform (web, API, GitHub, network, cloud, Active Directory, SAP, OSINT, email, scan import, and PCI-DSS external scan) instead of one surface per tool, and generates auditor-acceptable reports mapped to OWASP, CWE and CVE identifiers.
Does AssurePort replace human penetration testers?
No, and we don’t pretend it does. AssurePort handles the volume — the 95% of findings any competent pentester would identify given enough hours. Human pentesters focus on the 5% that requires creative attack chains. Most customers run AssurePort continuously and a human-led red team annually.
What compliance frameworks does AssurePort support?
Reports are formatted to map directly to control evidence for ISO 27001 (Annex A.12.6.1), NIS2 (Art.21), DORA (Art.24), GDPR (Art.32) and the EU AI Act (Art.10 data governance). PCI-DSS external vulnerability scanning is live; we do not provide official ASV attestation. SOC 2 mapping is on our roadmap.
How quickly can I run my first scan?
Under ten minutes from signup to first report on a public-facing web app. Authenticated scans (internal APIs, cloud accounts) take longer to configure but can usually be ready the same day. No agents to install. No prerequisites.
How much does AssurePort cost?
Pricing starts at $69 one-time for a single web scan (Starter), or $199/month for Pro (6 web pentests/month, rollover). Business is $599/month for 15 web pentests/month. Real AI pentests from $69 — consultancy pentests typically cost $5,000+. See full pricing.

Run your first scan in the next ten minutes.

No sales call. Creating an account is free — you only pay when you run a scan. Not ready? The free surface scan above needs no signup at all.