MAPPING ATTACK SURFACE

Your whole security team.
From just a domain.

Cassandra is an autonomous virtual security team for mid-market companies. A squad of AI agents maps your attack surface, finds what's actually exploitable, proves it, and keeps you compliant — reported in plain language your board can read. No agents to install. No stack to integrate.

Request a demo →See how it works
Northwind·Security Cockpit
AGENTS WORKING

connecting to northwind.com
deploying agents · outside-in
0
EXPOSURE SCORE
Moderate · improving
1,284
ASSETS DISCOVERED
7
EXPLOITABLE NOW
2
CRITICAL PATHS
What's exploitable right now
REAL-WORLD, NOT SCANNER NOISE
CRITICAL
Internet-facing admin panel with no MFA
Being exploited by attackers right now
HIGH
Exposed database backup on a forgotten host
Reachable from the public internet
HIGH
Leaked employee credentials for sale
Found on a dark-web marketplace
MEDIUM
Outdated VPN gateway with a known exploit
Patch available — not yet applied
Agent activity
Surveyor mapped 1,284 internet-facing assets
Sentinel flagged 7 findings attackers exploit now
Oracle matched 3 active threat groups to your surface
Red-Team proved 2 attack paths — benign, no data touched
Magistrate assessed NIS2 coverage — gaps listed honestly
NIS2
78%
ISO 27001
64%
GDPR
81%

↑ A LIVE PRODUCT MOCKUP — IT STARTS EMPTY AND FILLS IN AS THE AGENTS LEARN YOU

01 / How it works

Setup is one line long

STEP 01

Give us your domain

That's the whole setup. Nothing to deploy on your machines, nothing to integrate into your stack.

STEP 02

The agents go to work

Continuously, outside-in — like a real attacker would. Mapping, testing, researching, and proving, around the clock.

STEP 03

Watch your cockpit grow

Plain-language findings, prioritized by real risk, in your own brand — updated live as the team learns you.

02 / The core magic

A security team you can watch working

Cassandra isn't a static PDF report. It's a living cockpit that starts nearly empty and visibly grows as the agents learn your company. The proof it's working is the dashboard filling in front of you.

Starts empty, grows with you
New sections and findings appear live as agents complete their work — not once a year, continuously.
Board-ready in plain language
Findings are written for a non-technical decision-maker — what it says, how bad it is, what to do — so an exec or board member grasps it in seconds.
COCKPIT · DAY 1 → DAY 30
DAY 1
DAY 4
DAY 12
DAY 30
The same cockpit, four weeks apart. It fills in as the agents learn you.
03 / Meet the squad

A whole team — not a single point tool

Each agent does the job of a specialist you'd otherwise hire, and works as one product across three levels.

TIER 01

See

What we expose, what’s exploitable, how bad.
Surveyor
Recon & attack surface

Finds everything you expose to the internet — subdomains, services, tech, email posture, leaked credentials — from just your domain.

Stands in for: an attack-surface analyst
Sentinel
Vulnerabilities & exposure

Turns “here’s your surface” into “fix these first,” ranked by what attackers are actually exploiting in the wild.

Stands in for: a vulnerability-management analyst
Cartographer
The map-maker

Builds the picture of how your infrastructure connects, finds single points of failure, and clears false alarms so the team stays accurate.

Keeps the whole squad honest
Console
The executive cockpit

One calm view of how bad it is and what to do next — the vCISO at a glance, in plain language.

Stands in for: your vCISO, at a glance
TIER 02

Understand

Who’s coming, and how would they get in?
Oracle
Threat intelligence

Who targets a company like yours, with what tactics, and which weaknesses they’re exploiting now — matched to your surface, not a generic feed.

Stands in for: a threat-intel analyst
Threat Modeler
The strategist

Fuses everything into a company-specific picture: your crown jewels, the step-by-step paths an attacker would take, and which to worry about first.

Stands in for: a security architect
TIER 03

Prove & Govern

Prove it’s real. Prove we’re covered.
Red-Team
Proof of exploitability

Within an authorized scope, safely proves a path is real with benign evidence — no damage, no data taken. Proof ends arguments.

Stands in for: a red-team / pentester
Magistrate
Compliance & governance

Maps what the team finds to the frameworks that matter — NIS2, ISO 27001, GDPR, NIST — proof you’re covered, with honest gaps.

Stands in for: a compliance officer
AND GROWING

More specialists are on the way — people & dark-web monitoring, plus coverage add-ons for AppSec, cloud posture, third-party risk and security training. The squad expands as the threat landscape does.

04 / What you get at each level

Start where you are. Each level includes the last.

01

See

Show me what we expose and what’s exploitable — and how bad.

A complete stand-alone loop

For companies with no security visibility today.

Request pricing
02

Understand

Tell me who’s coming and how they’d get in.

Everything in See, plus threat intel & attack paths

For teams that need to prioritize and justify security to leadership.

Request pricing →
03

Prove & Govern

Prove the risk is real, and prove we’re compliant.

Everything in Understand, plus proof & compliance

For regulated, higher-stakes orgs — NIS2, DORA, ISO, SOC 2.

Request pricing

Pricing is tailored to your level and size — request pricing in a quick demo.

05 / Why Cassandra

Five reasons it's different

01

Zero-input onboarding

Works from a domain alone. Nothing to deploy, nothing to integrate.

02

A whole team, not a point tool

Recon, exploit-validation, threat intel, attack paths, proof and compliance — as one product.

03

Exploitability-first, not noise

Prioritizes what attackers are actually exploiting now, with a transparent method — no black box.

04

Board-ready in your brand

Plain-language, white-label dashboards an exec grasps in seconds.

05

Living, not episodic

Continuous assessment that grows with you — not a once-a-year pentest snapshot.

35–100 day pentest
Continuous
Always-on assessment instead of a once-a-year snapshot.
$10K–$35K+ per pentest
Predictable
A continuous subscription instead of episodic project fees.
$500K–$1M+ in-house team
A fraction
A full security team’s coverage at a fraction of the cost.
Weeks of setup
Zero setup
From domain to first findings with nothing to install.
06 / Trust, safety & compliance

Offensive power, kept on a leash

Authorized & non-destructive

Offensive work runs only inside a signed engagement scope, is benign by design, consent-tiered, and fully audit-logged.

Transparent method, not a black box

Every finding shows its reasoning and evidence — so you can trust and defend the conclusion.

Built-in governance

Scope, identity, monitoring, accountability, and a human override / kill-switch are wired in from the start.

Compliance-ready

NIS2, DORA, GDPR, ISO 27001 and NIST mapping — a real edge for European mid-market.

Tenant isolation

Each customer’s data is structurally separated — your findings stay yours.

MAPPED TO THE FRAMEWORKS THAT MATTER
NIS2DORAGDPRISO 27001NIST

Start from your domain.

See what attackers see — before they move. We'll show you your live cockpit, built from your domain, in a quick demo.

https://
NO AGENTS TO INSTALL · NO STACK TO INTEGRATE · WORKS OUTSIDE-IN