Free AI pentest · 24-hour turnaround
How it works Get my free test →
Powered by CYRIK™

Your free external AI pentest, back in 24 hours.

Enter your domain, confirm the scope from an address on it, then book your findings review — that booking is what starts the assessment. A Privaxi analyst validates every finding and walks it with you live. The written report and remediation are what you pay for — the findings are yours free.

✓ No credit card
✓ Domain ownership verified
✓ Signed rules of engagement
✓ Live findings review
CYRIK™ agent · sample run enumeration
$ cyrik scan --target northbaylogistics.com
› resolving DNS · 41 subdomains, 12 live hosts
› tcp/443 open nginx 1.18.0
! tcp/8006 ope
›
›
✓
Step 1 of 5 — Scope

Claim your free external AI pentest

Five short steps, about two minutes. We verify you own the target, you sign the rules of engagement, and nothing is tested until your review is booked. One domain per test — not a range or a list.

No credit card No agent to install Stop the test any time

Trusted by 100+ organizations in healthcare, fintech and logistics

Source Meridian IntelePeer Validic Soda Health e-courier MDFlow MedCloudDepot Zeldis Paybotx

How the free test runs

Authorized, bounded, stoppable.

Five things are true before a single packet leaves our infrastructure — and they stay true for the whole window.

01

Ownership is verified first

Registrant records, netblock ownership, and a confirmation link to an address on your own domain. If the assets are not yours, nothing runs.

02

You sign the rules of engagement

Exact scope, the testing window, and the source addresses our agent tests from — so your team can allowlist or monitor us while we work.

03

Hard exclusions, always

No denial of service, no destructive payloads, no social engineering of your staff, and no data pulled beyond what proves access.

04

One reply stops it

An emergency contact is on your confirmation email. We halt testing within 15 minutes of a stop request, no questions asked.

05

The audit record is kept

Signer, title, timestamp, source address and the full scope hash are retained in append-only storage for both of our protection.

Redacted, from real assessments

What a free test turns up.

Every finding is validated before it reaches you. If we say something is exploitable, we exploited it.

Critical CVSS 9.8

Management interface exposed to the internet

A virtualization console on a non-standard port with default credentials unchanged — full host control from an unauthenticated session.

High CVSS 8.1

Forgotten staging host with a live database

A subdomain nobody remembered provisioning, running an old build with a database socket bound to the public interface.

Medium CVSS 6.4

Breached credentials still valid on the VPN

Employee addresses found in third-party breach dumps, with password reuse confirmed against the VPN portal and MFA not enforced on that path.

Findings mapped to the frameworks your auditors ask about

HIPAA HITRUST PCI-DSS ISO 27001 SOC 2 NIST

After the free test

Keep it tested every month.

Priced by the IPs you actually expose — published, not quoted. Less than a single annual AI pentest, and anything you spend on a one-off evaluation is credited against your first month.

Annual — 2 months free

Single target

One target evaluated, once — $69

A single domain, fully assessed with the written report included. No subscription — the cleanest way to put one host in front of an auditor.

Evaluate one target
10 IPs
12550100150+

Recommended: Essential
Covers up to 10 IPs — from $49.90 per IP, per month

$499/month

Your fit

Essential

1–10 target IPs

$499 /month

$4,990/year billed annually

From $49.90 per IP, per month

Automated testing

  • ✓One full external AI pentest every month, run by the CYRIK™ agent
  • ✓Change-triggered rescans when new hosts or services appear
  • ✓Severity-ranked findings portal with remediation guidance
  • ✓Retest verification after you remediate
Start with the free test
Most popular

Standard

11–25 target IPs

$999 /month

$9,990/year billed annually

From $39.96 per IP, per month

Analyst-reviewed

  • ✓Everything in Essential
  • ✓Continuous attack surface discovery — subdomains, shadow IT, new services
  • ✓Analyst-reviewed monthly report, false positives removed
  • ✓Evidence pack for cyber insurance and vendor questionnaires
  • ✓1 business-hour response SLA on critical findings
Start with the free test

Professional

26–50 target IPs

$1,599 /month

$15,990/year billed annually

From $31.98 per IP, per month

Human validation

  • ✓Everything in Standard
  • ✓Human validation of every critical and high finding
  • ✓Proof of exploitation on confirmed issues
  • ✓1 web application included
  • ✓Quarterly review call with a named analyst
Start with the free test

Advanced

51–100 target IPs

$2,999 /month

$29,990/year billed annually

From $29.99 per IP, per month

Full programme

  • ✓Everything in Professional
  • ✓2 web applications included
  • ✓Credentialed and authenticated testing
  • ✓Named analyst with a monthly review call
  • ✓API access and SIEM integration
Start with the free test

More than 100 IPs?

Anything above 100 IPs is priced custom. Larger estates, multi-site networks and regulated infrastructure get scoped individually — depth, cadence and terms set against your environment rather than a band.

Get a scoped quote

Every plan reports as audit evidence. Each test produces a signed PDF mapped to the control your framework tests you against — the same document your auditor asks for.

SOC 2 CC7.1 HIPAA §164.308(a)(1) HITRUST 10.m PCI DSS 4.0 Req. 11.4 ISO 27001 A.8.8 ISO 42001 AI risk assessment NIST 800-171 3.11.2 CMMC L2 RA.L2-3.11.2 FedRAMP RA-5

Fair questions.

What if you find nothing?

You get a clean external result and a list of everything we tried, free. That is useful evidence for an auditor or an insurer, and a strong argument for testing the inside instead.

Will this take our site down?

No denial of service, ever. Testing is rate-limited, the window is yours to set, and one reply halts it inside 15 minutes.

I am not the person who can authorize testing.

Start anyway. At the authorization step you can forward a pre-filled rules-of-engagement request to whoever can, and you stay on the thread.

What happens to what you find?

Nothing is pulled beyond what proves access. Evidence is retained for your report and destroyed on request. Your findings are never shared or resold.

One domain · 24 hours · no card

Find out what an attacker can already reach.

You will know before this time tomorrow. The findings are yours whatever you decide afterwards.

Start my free pentest →