A product of Infiqon
Scanners tell you what is there. SecQon proves what is exploitable.
SecQon tests your internet-facing assets the way an attacker would, validates every candidate finding before it reaches you, and produces the OWASP- and SOC 2-mapped report your customer or auditor is asking for. Self-service from $99 a month — no sales call, no five-figure engagement.
The free tier stays free: one verified asset, re-tested every month, no card on file. We only ever test assets you have proved you own.
Check what an attacker can already see
A read-only snapshot of any domain — TLS, DNS, email spoofing and exposed headers. It sends no more traffic than an ordinary visit.
- TLS & certificates
- DNS & email spoofing
- Security headers
- Exposed technology
15 min
from signup to a scan running against an asset you have verified
$99/mo
for five assets — a commissioned external pentest starts near $15,000
Every finding
mapped to OWASP Top 10 and SOC 2 Trust Services criteria
Zero
destructive payloads — every check is bounded, rate-limited, non-destructive
A list of maybes is not a security posture
Finding candidate vulnerabilities is the easy half. Any scanner can produce hundreds of them. The hard half is knowing which ones an attacker could really reach — before someone on your team spends a fortnight chasing entries that were never exploitable in your configuration.
SecQon treats a scanner hit as a claim to be tested, not an answer to be trusted. Each candidate is re-examined against the live asset: is the path actually reachable, does the evidence hold together, does the affected component really behave that way here. What survives is labelled confirmed. What does not is still shown, marked likely or unconfirmed, with the reason attached — we would rather show our working than quietly drop things.
That is the whole design. Put the handful of findings that genuinely matter at the top of the list, and make every one of them defensible to an engineer who is going to ask you why it matters.
Subdomain takeover on assets.example.com
- Why this matters
- The CNAME points at a storage bucket that no longer exists. Anyone can claim that name and serve content from your domain — which means your cookies, your brand and your SPF-aligned mail.
- Evidence
- assets.example.com. 300 IN CNAME legacy-cdn.s3.amazonaws.com.
HTTP/1.1 404 NoSuchBucket - Fix
- Delete the dangling CNAME, or re-create the bucket under your account and lock ownership.
An illustrative finding, in the shape SecQon delivers them.
From a domain name to a defensible report
Four stages. You are involved in the first two, which take a few minutes, and then only when you want to be.
Add an asset
Enter a domain, subdomain, IP or API base URL you own. No agent to install and nothing to deploy.
Prove it is yours
Publish one DNS TXT record, drop a file, or add a meta tag. Copy, paste, re-check. Nothing is scanned until this passes.
Scan and validate
SecQon tests the asset the way an external attacker would, then re-tests each candidate finding to establish whether it is genuinely reachable and exploitable.
Report and watch
Get an OWASP- and SOC 2-mapped report with evidence and fixes, then continuous re-testing whenever your attack surface changes.
Verification is usually the longest part, and that is mostly DNS propagation.
The report your auditor will accept
Most teams do not want a security tool. They want the thing at the end of it: a document that satisfies a customer's security questionnaire, an auditor's evidence request, or an investor's diligence checklist — without a five-figure engagement and a six-week wait.
Every finding carries a severity, a CVSS score, an exploitability verdict, the raw evidence, a plain-English explanation and specific remediation — already mapped to OWASP Top 10 categories and SOC 2 Trust Services criteria. Export it as a PDF or hand someone a share link.
OWASP Top 10
Every finding categorised against the current list.
SOC 2
Mapped to the Trust Services criteria your auditor works from.
Evidence attached
The request, the response, the record — not a claim.
Share links
Send a report to a customer without giving them an account.
Change detection
Diffed against the last scan, so you see what is new.
Attestation summary
An assessment summary for the top of the pack.
You are letting a machine test your production systems. Here is exactly what it may do.
We are a security vendor, so our own restraint is part of the product. These are enforced in the engine, not promised in a policy document.
Nothing is tested until you prove you own it
DNS TXT, hosted file or meta tag. An unverified asset cannot be scanned — the gate is in the engine, not the UI.
Bounded, rate-limited, non-destructive
No state-changing exploit payloads, a request budget per host, and hard scope enforcement so a scan never wanders onto a neighbouring system.
Internal addresses are refused
Any target resolving to a private or reserved range is rejected before a packet leaves, and again per-connection during the scan.
Evidence is redacted before any model sees it
Secrets, tokens and personal data are stripped in the pipeline rather than trusted to a prompt. Your findings never train a model.
The free check really is passive
A DNS lookup, a TLS handshake and one ordinary HTTPS GET. It sends no more traffic than a visitor loading your homepage.
Every privileged action is logged
Scans, report exports and share links are written to an append-only audit trail your auditor can read.
Priced per asset, published in full
An asset is one verified hostname, IP or API base URL. Yearly billing is two months free. No quote, no call, no minimum term.
Free
$0forever
1 verified asset
Prove it works on something you own.
- Recon and safe passive checks
- Monthly re-test
- Basic findings report
- No card required
Starter
Most chosen$99per month
up to 5 verified assets
$990 billed yearly — two months free
The pentest-report answer to a customer security questionnaire.
- Full OWASP Top 10 and infrastructure testing
- Every finding AI-validated for exploitability
- Weekly monitoring
- Shareable reports with evidence and fixes
Growth
$249per month
up to 15 verified assets
$2,490 billed yearly — two months free
Teams heading into a SOC 2 audit.
- Everything in Starter
- Daily change detection across your attack surface
- SOC 2 and OWASP compliance reports
- Alerting when something new appears
Business
$499per month
up to 40 verified assets
$4,990 billed yearly — two months free
A real attack surface that changes every week.
- Everything in Growth
- Continuous monitoring
- Full compliance pack and attestation summary
- Priority support
More than 40 assets, or reselling assessments to your own clients? Start on a free account and we will size a Scale plan around what you actually run.
Questions worth asking a security vendor
If an answer here is vague, that is a bug — tell us and we will sharpen it.
How is this different from a vulnerability scanner?
A scanner reports what it can see and leaves you to work out what it means — which is why a typical report runs to hundreds of entries, most of which are not reachable, not exploitable, or already mitigated somewhere else in your stack. SecQon takes each candidate finding and tests the claim: is this actually reachable, does the affected path exist, does the evidence hold together. Findings arrive labelled confirmed, likely or unconfirmed, with the evidence attached, so triage is a decision rather than an investigation.
Is this a real penetration test, or an automated scan?
It is automated external testing with a validation layer, and we describe it that way deliberately. It covers the ground an external pentest covers — OWASP Top 10, TLS and certificate posture, DNS and email spoofing, exposed services, security headers and technology fingerprinting — and it produces the same class of report. What it is not is a human red-teamer chasing business-logic flaws, and no automated product should claim otherwise. Many teams use SecQon continuously and still commission a human pentest once a year.
Can you test anything I point you at?
No, and that is deliberate. Every asset must be verified as yours by a DNS TXT record, a hosted file, or a meta tag before a single request is sent. Unverified assets cannot be scanned at all. The one exception is the free exposure check on this page, which is strictly passive — a DNS lookup, a TLS handshake and an ordinary HTTPS GET — and sends no more traffic than a visitor loading your homepage.
Will scanning break my production site?
The engine is bounded and non-destructive by design. It runs no exploit payloads that change state, is rate-limited per host, refuses anything resolving to a private or reserved address, and holds to the scope you verified — no wandering onto a neighbouring host. Validation confirms a finding is reachable; it does not prove it by exploiting it.
What do the reports actually contain?
Every finding carries a severity and CVSS score, an exploitability verdict, the evidence behind it, a plain-English explanation of the risk, and specific remediation. Findings are mapped to OWASP Top 10 categories and SOC 2 Trust Services criteria, so the report can go straight to an auditor or a customer's security team. Reports export as PDF and can be shared through a link.
How long until I see my first result?
Adding a domain and publishing the verification record takes a few minutes; DNS propagation is usually the longest part. Once an asset is verified you can launch a scan immediately, and results land in hours rather than the weeks a scheduled engagement takes.
Where does my data go, and what does the AI see?
Scan evidence is redacted before it reaches a model — secrets, tokens and personal data are stripped in the pipeline rather than trusted to a prompt. Findings, evidence and reports belong to your tenant and are never used to train a model. Every privileged action is written to an append-only audit log.
What happens when I hit the limits of the free tier?
Nothing breaks. The free tier covers one verified asset with monthly re-testing, indefinitely, with no card on file. When you need more assets, faster monitoring or the compliance reports, you upgrade — and if you do not, the free asset keeps being tested.
Point it at one domain and judge it on the result
Add an asset, publish one DNS record, and see what a validated finding looks like on something you actually own. It takes about fifteen minutes.
One asset free forever · no card · nothing scanned until you verify ownership