01Web Security
Find, know, stop, notice. Protect your public web from four angles
ASM
Seeing what an attacker sees, ASM automatically discovers your subdomains and servers visible from the outside, every day. It inspects open ports, certificates and technology stacks, and alerts you first to vulnerabilities that are being exploited.
- Discovers assets from certificate logs, DNS and AWS
- Uses KEV and EPSS to flag what to fix now
- Active checks only on targets you approve
Threat intelligence
Combines trusted public feeds, your own IOCs and the feeds you subscribe to in one place. It removes noise, assigns confidence scores, delivers over the REST API and TAXII 2.1, and feeds your WAAP WAF rules.
- Public feeds + your IOCs + subscribed feeds in one place
- Removes false-positive sources and assigns confidence
- Delivered via TAXII 2.1 / API, applied to WAAP automatically
WAAP
Reduces false blocks in AWS WAF and automates operations, from switching Count to Block to quarantining attacking IPs and bot defense.
- Apply exclusions for false blocks in one click
- Estimate impact before changes
- Bot defense without paid rule groups
Defacement detection
Crawls your public websites from the outside and inspects them for defacement in three layers: page content, rendered screen and AI analysis. It also detects skimming scripts that leave the page unchanged, by watching where scripts are loaded from.
- Three layers: content, screen and AI
- Detects unfamiliar script sources
- Intervals as short as 5 minutes, logged-in pages too
02Cloud Security
Configuration, activity, vulnerabilities. Keep checking your cloud from three angles
CSPM
Continuously finds cloud misconfigurations against CIS Benchmarks and other standards, and prioritizes them by risk that accounts for external attack paths, data exposure and criticality.
- Assessed against CIS, AWS FSBP and more
- Visualizes attack paths and data exposure
- Supports AWS, Azure, Google Cloud and OCI
CSEM
Detects suspicious sign-ins, permission changes and external access every 15 minutes from AWS, Azure, Google Cloud and OCI audit and flow logs, and Microsoft 365 and Google Workspace logs. AI explains what each event means and how to respond.
- Spans multi-cloud and SaaS logs
- Predefined rules plus custom rules
- AI explains analysis, response and prevention
SCA
Builds SBOMs from the dependencies of containers, serverless functions, virtual machines and repositories, and continuously manages vulnerability, end-of-life, license and supply chain risks.
- AWS, Azure, Google Cloud plus GitHub and GitLab
- Prioritized with KEV, EPSS and JVN
- Automatic checks on pull requests
03Security Inspect
Find weaknesses before attackers do
AutoPentest
AI agents carry out reconnaissance, enumeration, vulnerability verification and reporting. Run penetration tests whenever and as often as you need, under guardrails that keep them within scope.
- Automated from recon to verification to reporting
- Guardrails block out-of-scope traffic
- Runs inside your AWS account
SAST
AI reads the code behind candidates detected by Semgrep, traces the data flow, and reports only what is truly exploitable. It also looks for authorization gaps that patterns can't find.
- AI filters out false positives
- Actively hunts for authorization gaps and business logic flaws
- From a zip or a Git repository
Mobile App Assessment
Static assessment of Android (APK) and iOS (IPA) apps against OWASP MASVS. Just upload the app to surface issues in configuration, cryptography, network communication and data storage.
- Follows OWASP MASVS / MASTG
- Supports Flutter, React Native and more
- Just upload the app
Related services
Services that protect new entry points into web services, such as generative AI apps and file upload features.
LLM Firewall
Inspects input before it reaches your generative AI app, with a single API. Detects prompt injection, personal and confidential information, web attacks, harmful content and obfuscated input.
- Detects injection with ML and rules
- Covers Japan-specific data such as My Number
- Removes obfuscation before analysis
MalScan
Automatically analyzes files stored in Amazon S3 and determines whether they are suspected malware. An input-side safeguard for services that accept file uploads from users.
- Automatic inspection on S3 upload
- Per-format analysis with verdict reasons
- IOCs to your SIEM via STIX / TAXII
Not sure where to start? Talk to us
We will propose a combination that fits your scope and challenges.