EU-hosted · GDPR-native · ISO 27001 aligned · SOC 2 Type II in progress

Penetration testing that runs every day, not once a year.

AssurePort continuously tests your web apps, APIs, GitHub, mobile and cloud the way a senior penetration tester would — only faster, cheaper, and on a schedule your auditor will actually accept.

No credit card First report in under 10 minutes Your data never trains our models
Built on & audited by
Cloudflare Workers (EU) Fly.io Frankfurt Anthropic AI (EU endpoint) Resend EU Polar.sh (Merchant of Record)
The reality

Annual pentests miss what ships on Tuesday.

A pentest signed off in January describes a system that no longer exists by March. Your team ships continuously. The attackers iterate continuously. The audit cadence is the only thing that hasn’t moved.

The result is a widening gap between what your last pentest verified and what is actually exposed to the internet today. That gap is where breaches are born — and where insurers, auditors and regulators are starting to look first.

AssurePort closes the gap by running the same depth of test your annual provider runs, but on every meaningful change — pull request, deploy, new endpoint, new cloud bucket, new domain.

What AssurePort is

A continuous penetration testing platform — not a scanner.

AssurePort is a continuous penetration testing platform that combines AI agents — trained against the OWASP, MITRE ATT&CK and CWE corpora — with deterministic security checks to find, prove and explain exploitable vulnerabilities across web applications, REST and GraphQL APIs, Android mobile apps, GitHub repositories and cloud configurations. It is operated from the European Union, with all data, scan logs and AI inference contained within EU-hosted infrastructure (Cloudflare EU + Fly Frankfurt + Anthropic EU endpoint).

AssurePort is not a vulnerability scanner with marketing on top. Scanners tell you what might be wrong. AssurePort proves what is exploitable, on your specific configuration, with a reproducible proof-of-concept attached to every critical finding.

How it works

Three steps to your first report.

No agents to install. No long onboarding. Sign up, point us at something, and read the report.

Step 01

Connect

Point AssurePort at a domain, a Git repository, a cloud account or a mobile APK. Connections are read-only by default and revocable in one click.

Step 02

Test continuously

AI agents run authenticated scans, business-logic probes and controlled exploit attempts — every action mapped to OWASP, MITRE ATT&CK and CWE.

Step 03

Get auditor-ready reports

Each finding ships with severity, a reproducible PoC, the suggested remediation and CWE/CVE references. Export to PDF or JSON.

Coverage

One platform. Every surface that matters.

Stop assembling six scanners, a consultancy and a Friday-night spreadsheet. AssurePort covers every surface your auditor will ask about.

Web applications LIVE

OWASP Top 10, business-logic abuse, broken authentication, IDOR — full proof-of-concept.

REST / GraphQL APIs LIVE

OWASP API Top 10 2023. Auth bypass, BOLA, mass assignment, injection.

Mobile (Android) LIVE

Binary analysis, insecure storage, cert pinning bypass. MASVS L1 + L2.

GitHub / Supply chain LIVE

Leaked secrets, vulnerable dependencies, IaC misconfigurations.

Cloud posture LIVE

AWS, Azure, GCP, Kubernetes. CIS Benchmark aligned. IAM blast-radius, exposed buckets, K8s API surface.

Active Directory LIVE

Kerberoasting, ACL gaps, DC recon. Read-only, non-destructive AD security assessment.

SAP LIVE

NetWeaver / S/4HANA auth gaps, ABAP and RFC misuse. Read-only analysis.

Email Security LIVE

SPF/DKIM/DMARC validation, phishing-kit detection, passive mail infrastructure reconnaissance.

Network / Host LIVE

TCP port and service discovery, product fingerprinting, and no-authentication exposure detection (open Redis/Elasticsearch/MongoDB/Docker API, anonymous FTP, SMTP open-relay). Detection only — no exploitation.

OSINT / Recon LIVE

Passive and light-active external footprinting: WHOIS/RDAP, certificate-transparency subdomain enumeration, full DNS records, origin-IP discovery behind a CDN, live subdomain probing. Your public attack surface, mapped.

Scan Import LIVE

Import an existing Nessus, OpenVAS, Nmap, Burp, CSV or PDF report and get an AI-triaged summary mapped to GDPR/NIS2/ISO. Turns raw findings into prioritised insight.

Network / Host ($149), OSINT / Recon ($49) and Scan Import ($9) join the eight pentest engines above — eleven coverage surfaces in total, all live in production. Read-only AI agent pipelines: detection and passive analysis only, no destructive actions.
Trust & data handling

Your data is the product you are protecting. We treat it that way.

We built AssurePort with the assumption that the security teams using it would read our architecture diagram, our independent pentest report and our DPA before granting access. They do. Here is what they read.

Your data never trains our models.

All scan inputs, code excerpts, screenshots and findings are processed inside isolated, tenant-scoped containers. Nothing you give us — not a line of source code, not a screenshot, not a URL — is used to train AssurePort’s models or any third-party model. Contractually guaranteed in our DPA. Anthropic EU endpoint enforces this at the infrastructure level.

EU-only infrastructure.

AssurePort is hosted exclusively on European infrastructure — Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction), Resend (EU). Anthropic AI inference is routed to the EU endpoint. Data, logs, AI inference and backups never leave the EU.

AI you can audit.

Every action an AssurePort agent takes is logged with the model used, the prompt, the tool call and the resulting output. You can replay any scan minute-by-minute and export the full trace for forensic review. 7-year retention, GDPR Article 32 compliant.

Read-only by default.

AssurePort never writes to your production systems, never executes destructive payloads, and never persists credentials beyond the lifetime of an authenticated scan. Domain Control Verification (DCV) and Rules of Engagement (RoE) validation are enforced as hard gates before any Advanced Mode scan proceeds.

Every finding ships with a reproducible PoC.

We refuse to ship a critical-severity finding without a proof-of-concept you can rerun in your own environment. If we cannot reproduce it deterministically, we do not call it critical. Period. Findings without a working PoC are automatically downgraded to unconfirmed.

We pentest AssurePort, too.

Our own platform is pentested before every release. The latest self-pentest report (May 2026: 5 findings, all remediated; SSRF + path-traversal + info-disclosure) is published on our Trust Center. External CREST-accredited audit is on our roadmap for Q4 2026 — Q2 2027 alongside ISO 27001 certification.

No model training. No data leaving the EU. Every action audit-logged.

How we compare

The honest comparison.

Annual pentest DIY scanners AssurePort
Frequency Once a year On-demand, manual Continuous, on every change
Surfaces covered What you pay for One per tool 11 engines live today
Time to first report 4–8 weeks Hours of setup Under 10 minutes
Proof-of-concept per finding Sometimes No Always (reproducible)
Auditor-acceptable Yes No (raw output) Yes (CWE/CVE/OWASP mapped)
Remediation guidance Rarely No Yes, per finding
Annual cost (mid-size org) €40k–€120k €15k+ in licences From $99 one-time / $349 monthly
Transparency

We publish what we actually do.

No fabricated case studies. No anonymous metrics. We make claims we can back with a link.

Latest self-pentest

May 2026. 5 findings. All remediated. SSRF, path-traversal and info-disclosure confirmed and closed before release.

Read the full report →

Public security disclosure

RFC 9116 security.txt with PGP-signed contact. Responsible disclosure policy. Researcher reports processed within 5 business days.

View security.txt →

Open certification roadmap

ISO 27001 + external CREST audit targeted Q4 2026 — Q2 2027. Public commitment, tracked monthly on our Trust Center.

View roadmap →
“We chose ‘continuous AI pentest’ as a category because the alternative — annual pentest + quarterly scanner reports — was demonstrably failing the customers we talked to. We publish our own findings. We publish our own roadmap. We publish our own architecture. That’s the bar.”
AssurePort engineering team — May 2026
FAQ

Frequently asked questions

Is AI penetration testing actually reliable?
Yes, when it is built correctly. AssurePort’s agents do not freelance — they operate inside a deterministic test harness that enforces scope, prevents destructive actions and verifies every finding with a reproducible proof-of-concept. Findings without a working PoC are automatically downgraded to unconfirmed rather than published as critical.
Will my code or data be used to train AI models?
No. All inputs — source code, screenshots, URLs, scan results — are processed in tenant-isolated containers and are never used to train AssurePort’s models or any third-party model. This is in our DPA. Anthropic’s EU endpoint API agreements independently prevent training on API traffic.
Where is my data stored?
Exclusively in the European Union. We use Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction) and Resend (EU). Anthropic AI inference is routed to the EU endpoint. No data crosses the EU border.
How is AssurePort different from a vulnerability scanner like Nessus or Burp Suite?
Scanners tell you what might be vulnerable. AssurePort proves what is exploitable on your specific configuration and ships a reproducible proof-of-concept with every critical finding. It also covers six attack surfaces in one platform instead of one surface per tool, and generates auditor-acceptable reports mapped to OWASP, CWE and CVE identifiers.
Does AssurePort replace human penetration testers?
No, and we don’t pretend it does. AssurePort handles the volume — the 95% of findings any competent pentester would identify given enough hours. Human pentesters focus on the 5% that requires creative attack chains. Most customers run AssurePort continuously and a human-led red team annually.
What compliance frameworks does AssurePort support?
Reports are formatted to map directly to control evidence for ISO 27001 (Annex A.12.6.1), NIS2 (Art.21), DORA (Art.24), GDPR (Art.32) and the EU AI Act (Art.10 data governance). SOC 2 and PCI-DSS mappings are on our roadmap.
How quickly can I run my first scan?
Under ten minutes from signup to first report on a public-facing web app. Authenticated scans (internal APIs, cloud accounts) take longer to configure but can usually be ready the same day. No agents to install. No prerequisites.
How much does AssurePort cost?
Pricing starts at $99 one-time for a single web scan (Starter), or $349/month for Pro (40,000 tokens monthly, rollover). Most teams land between $349 and $899 monthly depending on scope. Flat token pricing: $1 = 100 tokens at every tier; monthly plans add bonus tokens. See full pricing.

Run your first scan in the next ten minutes.

No credit card. No sales call. Sign up, point us at a domain, get a real report.