The continuous layer between your pentests

Pentests cover one weekWe cover the other 51

Daily monitoring of your external attack surface, with a CTO-ready brief on every scan.

~60 seconds to scan. Read-only and non-intrusive. No agent.

A+A+ on Mozilla Observatory — same grade as Stripe and Google. We hold our own perimeter to the bar we ask customers to clear.

~/cyberscore — scan stripe.com

Cross-referenced sources on every scan

Same data your auditor cross-references, automated and continuous.See our methodology →

Why we exist

The pentest is dated the day the auditor leaves

Annual audits catch what was true that week. We catch what becomes true the other 51.

The problem

You scan once a year

The pentester finds 47 issues. You fix them in two weeks. For the next 50 weeks, your external surface drifts silently:

  • A developer spins up a staging.acme.com subdomain on a Tuesday.
  • Your TLS cert expires on a Sunday at 2 AM.
  • An S3 bucket goes public after a Terraform change.
  • A new CVE drops on the nginx version you forgot to patch.
  • A junior dev commits an AWS key to a public GitHub repo.

Your report is stale before the ink dries.

Our answer

We scan every day

Same external surface your pentester sees, monitored continuously. When something changes you know within 24 hours, with a fix path in the alert:

  • Subdomain enum every 24h with 10k-word probing — new hosts flagged.
  • TLS certificate watch + email when expiry is <30 days.
  • Cloud bucket sweep across 73 providers, public ones alerted instantly.
  • CVE matching against your detected stack versions, nightly.
  • GitHub secret scan on every repo your team touches.

Your auditor signs off without comment.

Product tour

See it in action

Real interface. Real data. Click a tab to explore.

Watch the scan stream every check — DNS, TLS, headers, subdomain enum, GitHub leaks — and resolve to a 0–100 score in under a minute.

Built-in AI brief

A brief, not a 200-page PDF nobody reads

Pentest reports gather dust because they're 200 pages long and a quarter old. Our AI engine drafts a CTO-ready brief on every scan: TL;DR, top 3 priorities with effort tags, quick wins, 30/60/90-day plan, score commentary — grounded in the actual findings, never invented.

Appendix C · cont.Page 142 / 187
CVE-2023-4863webp · libwebp9.6
CVE-2023-32434kernel · iOS <16.58.1
CVE-2022-37434zlib · inflate9.8
CVE-2024-23222WebKit · type conf8.8
CVE-2023-21716MS Word · RCE9.8
CVE-2023-44487HTTP/2 reset7.5
…continues for 43 more rows
Section 5.1 — Risk matrix · p. 32
3
2
1
3
2
1
5
2
1
5
4
1
5
4
3
5
4
3
2
Likelihood →Impact ↑
Appendix F — NIST 800-53 mapping
AC-2Account management
AC-3Access enforcement
AU-3Content of audit records
AU-12Audit record generation
IA-5Authenticator management
SC-7Boundary protection
SI-2Flaw remediation
CM-7Least functionality
…73 more controls
Figure 4.7 — Network topologyp. 56
Legend: ◉ host · — link · see app. B for IPs
Section 4.3.2 — SSH Configurationp. 89
# /etc/ssh/sshd_config (excerpt)
PermitRootLogin yes no
PasswordAuthentication no
Volume 1 of 3 · Internal use only

Annual Penetration Test Report 2024

Prepared by Acme Pentest Consulting · Jan 12, 2024

Page 1 / 187Last opened: Feb 14, 2024

Before187 pages · 3 volumes · last opened 11 months ago

0
/100
AI Security Brief
stripe.com
Good practice

TL;DR
Three findings drive 80% of your risk: a public S3 bucket holding 2.3M objects, a leaked AWS key 47 days old on GitHub, and a dangling CNAME on old-blog.stripe.com.

Top 3 priorities

  1. Lock the public S3 bucketEffort: 1h
  2. Revoke the leaked AWS keyEffort: 5min
  3. Take ownership of the dangling CNAMEEffort: 1h
…4 more sections in the full brief: quick wins, 30/60/90 plan, score commentary.

Today1 brief · 3 actions · grounded in this scan

One free sampleSingle use per visitor

Try a real partial scan on your domain.

Email security, DNS, certificate-transparency subdomains. Top findings shown — full report behind purchase. One preview per visitor.

https://
Or try a demo:

Read-only, non-intrusiveReal data, partial coverageOne preview per visitor

The cost of inaction

Public breaches an external scanner would have caught

Three real, documented incidents from the past 18 months. Each one started with an externally visible weak signal — exactly the kind we surface on every scan.

  1. October 2023Okta~$1B market cap

    Customer support portal compromise via leaked session token.

    With CyberScore: A continuous secret scan flags GitHub-leaked tokens within hours.

  2. May 2024Snowflake customers165+ companies, hundreds of millions in damages

    Credential stuffing against accounts without MFA, leaked passwords from old breaches.

    With CyberScore: HIBP-style breach lookup catches the credentials before exploitation.

  3. April 2024AT&T73M records exposed

    Customer data leaked via dark-web post; traced back to a third-party cloud storage exposure.

    With CyberScore: Cloud-bucket sweep across 73 providers catches public buckets in under 60 seconds.

Industry benchmark

Average breach cost (IBM 2024 report): $4.45M

CyberScore Always-On: $399/month

Incidents above are publicly documented. References available on request. CyberScore claims describe technical capability, not a guarantee of breach prevention.

Paris, May 2026

Hi,

I built CyberScore because I watched a friend's SMB get hit by ransomware three months after their annual pentest cleared them. The pentester wasn't sloppy — the company spun up a new staging subdomain in week 2, exposed an admin panel, and the report from January didn't mention it. It couldn't have.

Pentests are great. They miss the other 51 weeks.

So I built the layer between two pentests: a continuous scanner for the external attack surface, with an AI brief a CTO can read in five minutes and an auditor can drop into a SOC 2 binder.

If you try CyberScore and it's useful — tell me. If it isn't, tell me what's missing. I read every email and I usually ship a fix within 48 hours.

Patrick Astoul, founder of CyberScore

Yours,

Patrick Astoul
Founder, CyberScore
Who is this for

Three teams, one continuous layer

We're not a Burp replacement, and we're not a vendor-risk scoring tool. We're what runs between two pentests so nothing new slips through.

Startup CTO, no pentest budget

The pain: A €15k pentest is half a junior salary. You can't justify it to your board, but your enterprise prospects keep asking for a security artifact.

CyberScore: Run an audit-prep scan ($299) on your way to your first SOC 2. Or subscribe to Pro ($249/mo) for continuous coverage — same arithmetic, 80% of the value at 5% of the price.

Best fit · Audit Prep · Pro

CISO of a compliance-bound SMB

The pain: You pay €15k/yr for an annual pentest because ISO 27001 / SOC 2 / NIS2 demand it. The report goes stale the day after the auditor leaves.

CyberScore: CyberScore is the continuous layer next to your annual pentest, not a replacement. Daily checks on the external surface; you know before your auditor does when a new S3 bucket goes public or a cert expires.

Best fit · Pro · Always-On

MSP / agency managing 30 clients

The pain: Each client wants 'continuous security monitoring' but you can't run a pentest per quarter per client. You need a portfolio dashboard that scales with headcount, not with engagement count.

CyberScore: One Always-On subscription, 25 monitored domains, daily rescans, bulk import, multi-domain portfolio, CSV exports for client deliverables. The unit economics finally work.

Best fit · Always-On
Pricing

Pay once or subscribe

Same scanner across every tier — monitored vs snapshot. The recurring plans add continuous monitoring, alerts, and a bigger surface to cover.

Pay once

One-shot, no commitment

A single scan, or audit-prep with a 90-day free rescan — no recurring billing, no auto-renew.

Sample preview
$0one preview, ever
  • Illustrative report on a demo target
  • Shows the structure: score, top findings, AI brief
  • Run the real scan once you have an account
  • No card required
See a sample report
One-time scan
$49one-time, 1 domain
  • Full multi-page PDF report
  • Every detection module included
  • AI Security Brief
  • Renewable manually anytime
Buy scan
Audit Prep
$299one-time, 1 domain
  • Everything in One-time scan, plus
  • 1-page Executive Summary PDF (audit-dossier ready)
  • 1 free rescan within 90 days (use it after you fix things)
  • Findings-delta report on the rescan ("✓ Verified fix" badges)
  • Designed for SOC 2 / ISO 27001 / NIS2 audit prep
Order audit prep
Or subscribe

Continuous monitoring

Daily scans, drift alerts, multi-domain portfolio. Cancel anytime, no auto-roll-over.

Starter
$99per month
  • 10 scans / month
  • 1 monitored domain
  • Full report: ports, TLS, headers, CVEs, OSINT (open-source intel)
  • AI Security Brief on every scan
  • Wayback + GitHub leak detection
  • Email alerts on score drop
  • Compliance tracker + CSV export
  • Public score badge (opt-in)
Start
Most popular
Pro
$249per month
  • Everything in Starter, plus
  • 30 scans / month (vs 10)
  • 5 monitored domains (vs 1)
  • Weekly continuous monitoring + email digest
  • Slack webhook alerts on score drops
  • Findings delta after each rescan ("✓ Verified fix")
Get Pro
Always-On
$399per month
  • Everything in Pro, plus
  • Unlimited scans (fair-use 500/mo)
  • 25 monitored domains (vs 5)
  • Daily monitoring (vs weekly)
  • Multi-domain portfolio dashboard
  • Bulk import + rescan-all on incident
  • Audit-ready PDF + CSV exports for your DPO
Get started

All paid plans include the AI Security Brief, every detection module, PDF export, and email support. Annual saves 20%. Cancel anytime.

Built in France
CS
CyberScore
Independent. Self-funded. No tracking.

A small product with one job: surface the public assets you forgot existed. Methodology and threat model are public on /security.

What runs under the hood
  • SecLists top-10k subdomain wordlist
  • Certificate Transparency (crt.sh)
  • Wayback Machine CDX API
  • Public GitHub Code Search + 22 TruffleHog patterns
  • Shodan InternetDB (free endpoint)
  • Frontier-class AI for the written brief
What we never do
  • Send exploit payloads at your servers
  • Store your scan results past your subscription
  • Share data with advertisers or third-party brokers
  • Charge you for surprise overages
Read the full security page →
Independently audited

Click any badge to re-run the scan on our own site.

FAQ

Stop guessing what is exposed — get the report

$49 for a one-time scan, $249/mo for continuous monitoring. Skip months of pen-test scoping.