Why we exist

Trust can’t be bought.It’s earned, one true finding at a time.

We believe every company deserves real security coverage, and most are running with far less than they think. So that’s what we are: a continuous watch on everything an attacker can reach from your name, honest judgment about which findings actually matter, and a real red team behind it when something serious trips. Not a scanner. A standing relationship.

Built for companies with more
surface than coverage,
and founders who’d
rather never have to
think about this again.

The security market is crowded everywhere you aren’t.

At the top

Real penetration-testing firms. Excellent, human, and point-in-time. Even if you can afford one, you get a snapshot that starts going stale the day the report lands. An engagement isn’t coverage.

At the bottom

Automated scanners. They’ll happily email you forty findings a month. They will never tell you which three matter for your stack, or sit with you while you fix one.

The middle is where most companies actually live: someone who knows your surface, tells you the truth about it, and helps you act. Nobody serves it, because judgment doesn’t scale like software. We’re built for exactly this.

- 01 · WHY

You’re not short on tools. You’re short on judgment.

Security software is becoming a commodity. Every scan we can run, someone else can run too, and in a few years anyone will. What can’t be commoditized is knowing you: your surface, your stack, what you’ve already fixed, what you’ve looked at and decided to accept. That’s the part we’re building the company on.

The scanner
emailed forty findings. Nobody knows which three matter.
The pentest
quoted five figures for a company with no security budget.
The founder
assumed someone, somewhere, was checking this.

Our answer isn’t another dashboard. It’s a role: your outside security person. We watch, we tell you what matters in plain English, and when something is genuinely beyond a config change, real operators are one click away, already holding everything the watch knows about your site.

And because trust is the whole product, we earn it the only way it can be earned: by being right, specific, and asking nothing first.

- 02 · HOW

One relationship, three layers.

The monthly watch keeps us present. The judgment makes it useful. The depth is there for the day you need it. Each layer earns the next. Nothing is sold cold.

- THE WATCH

Always-on eyes on your whole surface.

Every cycle we re-walk everything reachable from your name and report what’s new and what regressed, because your site isn’t static. You ship, dependencies rot, new CVEs drop against libraries you already run. The world moves even when your code doesn’t.

discover // reachable_surface
watch // every_cycle
report // new + regressed
- THE JUDGMENT

Which findings matter, in plain English.

Every finding: what it is, the actual risk to your setup, and how to fix it, all prioritized so you never have to become a security engineer. We surface, you decide. Your call is recorded as yours: reviewed, fixed, or accepted, on the record.

triage // what_matters
guide // the_fix
record // your_decision
- THE DEPTH

Real operators, one click away.

When the watch trips something a config change won’t solve, a human-led penetration test is one click away, scoped by everything we already know about your surface. A deliberate decision, priced like one, and we’ll tell you plainly when you actually need it.

escalate // one_click
operate // human_led
scope // already_known
- 03 · HOW

We watch your surface, not your asset list.

Most tools scope and bill per domain, per IP, per app. That’s a billing model wearing a security costume, and its blind spot is structural: attackers don’t respect your asset inventory. The thing that breaches you is disproportionately the forgotten one: the staging box, the side project, the subdomain nobody remembers deploying.

So we don’t ask for a list of everything you own. You couldn’t give us one, and that’s the point. You give us one name. We follow what’s reachable from it, the way an attacker would. Competitors scan what you tell them you own; we scan what an attacker can actually reach from you.

Fair use is bounded by effort, not entity counts. No per-domain steppers quietly inflating your quote. Every scan carries a work budget; if your surface outgrows it, the scan still completes and still returns real findings, and then a human reaches out to fit you right. Above the line is a conversation, never a surprise invoice.

- 04 · HOW

What you’re paying for in a quiet month.

Most monitoring quietly loses its customers in the months where nothing goes wrong. We designed for those months on purpose. A quiet month should be worth more, not less.

The record

Proof you’ve been watching.

Every cycle, timestamped: what was scanned, what was found, what was fixed, what you reviewed and accepted. One click exports it as evidence for security questionnaires, vendor reviews, cyber-insurance, and your auditor, with the scope stated plainly on the document itself.

A clean record is more valuable to hand over, not less
The relief

It’s off your plate.

You didn’t start a company to think about session cookies. The watch means somebody competent is thinking about it so you don’t have to, and will interrupt you only when something genuinely deserves your attention.

“It’s handled” is worth the same with or without findings
The horizon

The world moves. We notice.

Even if you ship nothing, your exposure changes: new CVEs drop against libraries you already run, dependencies age, things you deployed last year become tomorrow’s advisory. Every report covers what changed around you, not just what changed in you.

There is always signal, even on a static site
- 05 · WHAT

Simple prices. Each step up is a trust decision, not a paywall.

Outside needs no permission; it’s what any attacker already sees. Inside starts when you hand us a key. The pentest is for when it’s serious. You move up when you’re ready, never because we gated something behind it.

- First Look
$0
One scan · ever
  • Full discovery across your reachable surface
  • Every finding, severity-ranked, nothing held back as a teaser
  • Plain-English: what it is, the real risk, how to fix it
  • No account wall, no demo call, no catch

Fix everything yourself and never pay us. Genuinely fine. We’d rather be the ones who told you.

- Outside
$199/m
$99/m with active Network membership
External watch · no access needed
  • Monthly watch of everything reachable from your name
  • New & regressed report every cycle
  • Alerts for new CVEs against the stack you already run
  • Triage and fix guidance on every finding
  • Exportable evidence record

Sees what any attacker outside can see. The entry rung.

- Inside
$299/m
$199/m with active Network membership
Authenticated watch · you hand us a key
  • Everything in Outside
  • Authenticated scans behind your login
  • The findings that only exist inside, where the serious ones live
  • Deeper, active testing, safe because you’ve consented to it
  • Direct line to the operators behind the platform

The upgrade isn’t a paywall. It’s the moment you decide we’ve earned a key. We take that moment seriously.

- Pentest
Talk
Human-led · when it’s serious
  • Real operators, full engagement
  • Scoped by everything the watch already knows about you
  • Findings validated to impact, not listed to length
  • The report your auditor actually means by “pentest”

Deliberately a considered purchase. A real pentest should be a decision, not a line item.

- 06 · WHAT

The Network: peers who know where they stand.

Members answer one short survey a quarter about their security posture, tooling, and practices. In return: a quarterly benchmark of how you compare to companies like yours, and $100/month off either watch tier while your membership is active.

Same offer for everyone, any size. A two-person startup joins for the discount and the insight; a two-hundred-person company joins because knowing where you stand against your peers is worth more than the credit. Don’t value the benchmark? Pay list and skip the survey. No friction, no resentment, one door.

Membership, plainly
Joining Granted on request. We say yes to nearly everyone, and reserve the right not to. It keeps the benchmark honest.
Staying One short survey a quarter, plus consent for your answers to be used in aggregate. That’s the whole deal.
Lapsing Miss the requirements and you drift gently back to list price. No dunning, no drama, and you can rejoin whenever you like.
Your data Aggregate use only, under the same terms that govern your scan data. Never sold, never attributed.
- 07

Straight answers to fair questions.

If the whole product is trust, the marketing can’t hedge. Here’s what we’d tell you across a table.

“Is this a penetration test?”

No. The watch is an external scan of your running systems (authenticated too, on Inside). It is not a guarantee of security and not a substitute for a full penetration test. That language is printed on every report we produce, because it’s true. When you need the real thing, it’s behind us, and we’ll say so plainly.

“Will this make us SOC 2 compliant?”

No tool makes you compliant, and we won’t pretend otherwise. What we provide is evidence: a timestamped record of continuous monitoring, findings, and remediation that feeds your audit. Your auditor judges; we never issue verdicts, checkboxes, or “readiness” scores.

“What if we fix everything free and leave?”

Then you’re safer and we told you the truth. That’s a win we’ll take. The free scan is complete on purpose, not a teaser. What you can’t do alone is know when things change next month. If that matters to you, we’ll be here.

“Who decides if a finding matters?”

You do. We surface, prioritize, and explain; the call is yours and recorded as yours. We’ll never quietly mark something “safe” on your behalf. And when something is serious enough that dismissing it would be a mistake, it will not go quietly.

“Why aren’t you cheaper?”

Because a $50 security service isn’t one. You know it, and so do we. The price reflects what this is: a real, entry-level security function with humans behind it, priced well under the pentest it stands in front of. Simple splits, list on the sticker, no steppers quietly inflating the quote.

“Why aren’t you more expensive?”

Because we don’t have to be. The attack research already happens: our operators run live engagements as their day job, so keeping the watch current isn’t an extra cost we pass to you. And because we believe every site deserves security, not just the ones with a budget line for it. Pricing you away would defeat the point of us.

- 08

The depth is real. Operators, not analysts.

The team behind Foundation Zero runs full-scope adversary emulation against production systems as their day job. They find paths to impact, not lists of CVEs. That’s why the watch stays sharp: every new attack pattern surfaced in a live engagement becomes an automated check in your next cycle.

And it’s why the escalation is honest: when we say a finding deserves a human, the humans are already here, already holding your context. One click, your call.
Public Acknowledgments
Apple Security · credited
Google VRP · credited
Microsoft MSRC · credited
Mozilla · credited
+ 12 more
Research Output
120+ CVEs disclosed
20-year combined experience across web, mobile, and infrastructure testing.
Red Team Operations
Active · ongoing engagements
Live adversary emulation work feeds the watch’s test library on a published cadence.
- 09

How we handle your data.

Consent The external watch looks only at what any visitor on the internet already receives. Anything deeper, like authenticated scans or active testing, happens only after you’ve explicitly granted access. Consent is the boundary, always.
Data residency US AWS infrastructure. Customer data does not leave US-region storage. No data egress to research environments.
Access Engagement-scoped, audit-logged, time-bound. No persistent access to customer environments.
Traffic attribution All probes carry HMAC-signed identifiers (headers, workspace and job IDs) so you, or your SOC if you have one, can verify, whitelist, and audit Foundation Zero activity in your own logs with certainty.

Procurement, security, or legal questions? Email [email protected]. Typical response within one business day.

- 10

Start with the free look. It’s complete, and it’s yours.

One scan, the only free one you’ll ever get from us, so we made it count. Everything reachable from your name, every finding explained in plain English with the fix. Read it, fix it, close the tab if that’s all you need. If you’d rather never think about this again, that’s the part we charge for.

/External only: we look at what the internet already sees
/No account, no demo call, no follow-up pressure
/One per company, ever. Complete, not a teaser