Skip to content
SECQON

A product of Infiqon

Scanners tell you what is there. SecQon proves what is exploitable.

SecQon tests your internet-facing assets the way an attacker would, validates every candidate finding before it reaches you, and produces the OWASP- and SOC 2-mapped report your customer or auditor is asking for. Self-service from $49 a month — no sales call, no five-figure engagement.

Re-tested every day, not once a year. Paid plans scan daily with vulnerability checks refreshed daily from the open-source security community, so a check for a newly disclosed CVE reaches your assets within days.

The free tier stays free: one verified asset, re-tested every month, no card on file. We only ever test assets you have proved you own.

Free · no signup · passive

Check what an attacker can already see

A read-only snapshot of a domain you own — TLS, DNS, email spoofing and exposed headers. A DNS lookup, a few short TLS handshakes and a couple of ordinary page requests. No ports are swept and no payload is sent.

Protected by reCAPTCHA. Google’s Privacy Policy and Terms of Service apply.

  • TLS & certificates
  • DNS & email spoofing
  • Security headers
  • Exposed technology

15 min

from signup to a scan running against an asset you have verified

$49/mo

for one verified asset, with the written report — a commissioned external pentest starts in the five figures

Evidence-backed

every finding about your site shows the request and response it was observed in — scan status notes say plainly when nothing was

Nothing destroyed

no data deleted, no persistence, no lateral movement — and the pentest tier's real payloads run only when you acknowledge them, per scan

A list of maybes is not a security posture

Finding candidate vulnerabilities is the easy half. Any scanner can produce hundreds of them. The hard half is knowing which ones an attacker could really reach — before someone on your team spends a fortnight chasing entries that were never exploitable in your configuration.

SecQon treats a scanner hit as a claim to be tested, not an answer to be trusted. Each candidate is re-examined against the live asset: is the path actually reachable, does the evidence hold together, does the affected component really behave that way here. What survives is labelled confirmed. What does not is still shown, marked likely or unconfirmed, with the reason attached — we would rather show our working than quietly drop things.

That is the whole design. Put the handful of findings that genuinely matter at the top of the list, and make every one of them defensible to an engineer who is going to ask you why it matters.

HighConfirmedcustom:ports

Port 6379/tcp (redis) is reachable from the internet

Why this matters
A database or cache port is answering from the public internet. These services are normally reachable only from your own application servers, and several of them accept unauthenticated connections in their default configuration.
Evidence
TCP connect yourcompany.com:6379
connection established to yourcompany.com:6379 (redis)
Fix
Close this port to the internet at the firewall or security group and bind the service to a private interface. Confirm authentication is enabled, then rotate any credential that was reachable while it was exposed.
OWASP A05:2021CWE-668SOC 2 CC6.1SOC 2 CC6.6SOC 2 CC7.1

An illustrative finding, in the shape SecQon delivers them.

From a domain name to a defensible report

Four stages. You are involved in the first two, which take a few minutes, and then only when you want to be.

  1. Add an asset

    Enter a domain, subdomain, IP or API base URL you own. No agent to install and nothing to deploy.

  2. Prove it is yours

    Publish one DNS TXT record, drop a file, or add a meta tag. Copy, paste, re-check. Nothing is scanned until this passes.

  3. Scan and validate

    SecQon tests the asset the way an external attacker would, then re-tests each candidate finding to establish whether it is genuinely reachable and exploitable.

  4. Report and watch

    Get an OWASP- and SOC 2-mapped report with evidence and fixes. Paid plans then re-test every day, with vulnerability checks kept current, and alert you when something changes.

Add your first asset

Verification is usually the longest part, and that is mostly DNS propagation.

The report your auditor will accept

Most teams do not want a security tool. They want the thing at the end of it: a document that satisfies a customer's security questionnaire, an auditor's evidence request, or an investor's diligence checklist — without a five-figure engagement and a six-week wait.

Every finding carries a severity, an exploitability verdict, the raw evidence, a plain-English explanation and specific remediation — mapped to OWASP Top 10 categories and SOC 2 Trust Services criteria wherever they apply, and carrying a CVSS score wherever the source publishes one. Export it as a PDF or hand someone a share link.

  • OWASP Top 10

    Every finding categorised against the current list.

  • SOC 2

    Mapped to the Trust Services criteria your auditor works from.

  • Evidence attached

    The request, the response, the record — not a claim.

  • Share links

    Send a report to a customer without giving them an account.

  • Change detection

    Diffed against the last scan, so you see what is new.

  • Attestation summary

    An assessment summary for the top of the pack.

You are letting a machine test your production systems. Here is exactly what it may do.

We are a security vendor, so our own restraint is part of the product. These are enforced in the engine, not promised in a policy document.

  • Nothing is tested until you prove you own it

    DNS TXT, hosted file or meta tag. An unverified asset cannot be scanned — the gate is in the engine, not the UI.

  • Bounded, rate-limited, non-destructive

    A request budget per host and hard scope enforcement, so a scan never wanders onto a neighbouring system. Standard sends no attack payloads at all; the pentest tier sends real ones, which is what it is for, and asks you to acknowledge that on every scan.

  • Internal addresses are refused

    Any target resolving to a private or reserved range is rejected before a packet leaves, and again per-connection during the scan.

  • Evidence is redacted before any model sees it

    Secrets, tokens and personal data are stripped in the pipeline rather than trusted to a prompt. Your findings never train a model.

  • The free check really is passive

    A DNS lookup, a few short TLS handshakes and a couple of ordinary HTTPS GETs of your homepage. No ports swept, no payload sent, no path requested beyond the one you give it.

  • Every authorisation is logged, and the log cannot be edited

    Accepting the agreements, proving an asset, each scan you attest to, every scope-guard refusal and every share link is written to an append-only, HMAC-chained record. There is no self-service view of it yet — ask us and we will produce your organisation's log.

Priced per asset, published in full

An asset is one verified hostname, IP or API base URL. Yearly billing is two months free. No quote, no call, no minimum term.

  • Free

    $0forever

    1 verified asset

    Prove it finds something real on an asset you own.

    • The full non-intrusive check set
    • Evidence behind every finding
    • Monthly passive re-test, no card needed
    Start free
  • Starter

    $49per month

    $490 billed yearly — two months free

    1 verified asset, add more for $25 each (up to 4)

    Answering a customer security questionnaire.

    • Written report with step-by-step fixes
    • Security questionnaire pack from your evidence
    • Daily change checks, monthly full re-audit
    Choose Starter
  • Growth

    Most chosen

    $149per month

    $1,490 billed yearly — two months free

    up to 10 verified assets

    Teams with a real application, not just a marketing site.

    • Deep scans with bounded exploit proofs
    • Testing behind your login
    • Real-browser crawl for single-page apps
    Choose Growth
  • Business

    $399per month

    $3,990 billed yearly — two months free

    up to 30 verified assets

    When you want what a manual pentest does, continuously.

    • Automated penetration test with real attack payloads
    • Object-access and mass-assignment probes
    • Measures which attack signatures your WAF blocks
    Choose Business

One-off pentest report — $99 once

You need one report, by a date, and not a subscription. 1 verified asset.

  • One automated penetration test of one asset
  • Complete report with evidence and fixes
  • No subscription, no card kept on file

Compare every feature

More than 30 assets, or reselling assessments to your own clients? Start on a free account and we will size a plan around what you actually run.

Questions worth asking a security vendor

If an answer here is vague, that is a bug — tell us and we will sharpen it.

How is this different from a vulnerability scanner?

A scanner reports what it can see and leaves you to work out what it means — which is why a typical report runs to hundreds of entries, most of which are not reachable, not exploitable, or already mitigated somewhere else in your stack. SecQon takes each candidate finding and tests the claim: is this actually reachable, does the affected path exist, does the evidence hold together. Findings arrive labelled with what we actually established — demonstrated when a bounded proof-of-exploit changed how your application behaved, confirmed when a re-test observed the same thing again, likely when we saw it once and could not reproduce it, unconfirmed when only a tool reported it — each with the evidence attached, so triage is a decision rather than an investigation.

Is this a real penetration test, or an automated scan?

It is automated external testing with a validation layer, and we describe it that way deliberately. It covers a good deal of the ground an external pentest covers — security headers and cookie flags, TLS and certificate posture, deprecated TLS versions, DNS and email spoofing (SPF, DMARC, CAA, DNSSEC), exposed services and open ports, technology fingerprinting, exposed version-control and build files, CORS policy, unencoded reflection of request input, third-party scripts loaded without integrity pinning, and template-driven checks for known-vulnerable software. On the tiers that include it, the pentest layer adds crawling and testing behind your login, an active scanner sending real payloads for path traversal, OS-command injection, server-side template injection, XXE, XPath, open redirect and CRLF, object-level authorization testing (IDOR/BOLA) and mass-assignment probes against your API's own schema, and a measurement of how much of that your WAF actually blocked. It produces the same class of report. That reaches six of the OWASP Top 10 categories with a purpose-built test — A01, A02, A03, A05, A06 and A08 — plus A07 only where a template recognises a service still answering on its shipped default credentials. Those are the categories a purpose-built test reaches on every profile. The remaining three are each named on the face of every report: A04 (Insecure Design) and A09 (Logging and Monitoring Failures) are not observable from outside at all, and A10 (SSRF) is confirmed out-of-band — the proof is your server calling a collector we run, which is never visible in a response, so it is a Deep-profile check and a report from any other profile states that SSRF was not assessed. What it is not is a human red-teamer chasing business-logic flaws, and no automated product should claim otherwise. Many teams use SecQon continuously and still commission a human pentest once a year.

Can you test anything I point you at?

No, and that is deliberate. Every asset must be verified as yours by a DNS TXT record, a hosted file, or a meta tag before a single request is sent. Unverified assets cannot be scanned at all. The one exception is the free exposure check on this page, which is strictly passive — a DNS lookup, a few short TLS handshakes (including ones that offer TLS 1.0 and 1.1, to see whether they are still accepted) and a couple of ordinary HTTPS GETs of your homepage. No ports are swept, no payload is sent and no path is requested beyond the one you give it.

Will scanning break my production site?

The engine is bounded and non-destructive by design: it is rate-limited per host, refuses anything resolving to a private or reserved address, and holds to the scope you verified — no wandering onto a neighbouring host. On the Light and Standard profiles it sends no attack payloads at all; validation there re-tests that a finding is still observable, and does not try to exploit it. The penetration-test tier does send real payloads — path traversal, OS-command injection, template injection, XXE and the rest — because that is what distinguishes it, which is why it is never on by default and asks you to acknowledge its intrusiveness on every scan. At no depth does the engine delete data, deny service, establish persistence, move laterally, or extract data in bulk.

What do the reports actually contain?

Every finding about your site carries a severity, an exploitability verdict, the evidence behind it, a plain-English explanation of the risk, and specific remediation — plus a CVSS score wherever the source that produced the finding publishes one. Findings are mapped to OWASP Top 10 categories and SOC 2 Trust Services criteria wherever they apply, so the report can go straight to an auditor or a customer's security team. Reports export as PDF and can be shared through a link.

How long until I see my first result?

Adding a domain and publishing the verification record takes a few minutes; DNS propagation is usually the longest part. Once an asset is verified you can launch a scan immediately, and results land in hours rather than the weeks a scheduled engagement takes.

Where does my data go, and what does the AI see?

Everything runs on Google Cloud in asia-south1 (Mumbai), and your findings and their evidence live in that database. The model is Gemini on Vertex AI in the same region, and it sees only normalised finding fields and short evidence snippets that have been minimised and then redacted — secrets, tokens and personal data are stripped in the pipeline rather than trusted to a prompt, and credentials you give us for authenticated scanning are encrypted at rest and never enter a prompt at all. On the Free plan and on a Light scan no model is called. Findings, evidence and reports belong to your tenant and are never used to train a model. Authorisation events — agreements accepted, assets verified, scans attested, scope refusals, share links issued — are written to an append-only, hash-chained log. The full account is at secqon.com/legal/privacy.

What happens when I hit the limits of the free tier?

Nothing breaks. The free tier covers one verified asset, indefinitely, with no card on file, and you can launch the full non-intrusive check set on it yourself whenever you like. What paying buys is the written report and the questionnaire pack, more assets, authenticated scanning behind your login, faster automatic monitoring on the full check set rather than the passive one, and — higher up — the penetration-test tier. If you never upgrade, that free asset keeps being tested.

Point it at one domain and judge it on the result

Add an asset, publish one DNS record, and see what a validated finding looks like on something you actually own. It takes about fifteen minutes.

One asset free forever · no card · nothing scanned until you verify ownership