CyDrakk
EU-compliant · GDPR & NIS2 · sovereign by design

See your attack surface like an attacker would — within a strictly authorized scope.

CyDrakk maps your external exposure, correlates it daily with global exploitation intelligence, and proves what is actually exploitable — without any data ever leaving your infrastructure.

No active packet without proof of control and a signed mandate. Every action is logged.

2.6 M
indexed CPE matches
Daily
KEV · EPSS · NVD refreshed
0
data leaving your infra
Multi-tenant
isolated & white-label
Live demo

Scan your site now

Instant passive preview. Then, after proof of control, a full active scan + AI remediation.

The pipeline

Like a pentester — automated, every day

From discovery to proof, a deterministic chain. AI augments the analyst and prioritizes; sensitive actions stay behind human validation gates.

01 · RECON

Living map

Recursive passive recon: subdomains, DNS, IPs, services, forgotten assets — rebuilt into a "who talks to what" graph.

02 · CORRELATION

Real exploitability

Every tech/version is linked to CVEs, KEV, EPSS and exploit availability. Ranking follows real risk — never raw CVSS.

03 · VALIDATION

Reproducible proof

A deterministic validator only concludes "exploitable" with replayable proof. Strict safe-mode, never any post-exploitation.

04 · REPORT

Two readings

One run, an executive summary and a technical annex. Attack paths, prioritized remediation, PDF export — white-labeled.

What sets us apart

Sovereign, proven, resellable

Product principles embodied in the code — not just the pitch.

Absolute sovereignty

Hosted on your own infrastructure. The only outbound flows are public intel feeds. Air-gap mode with a local feed mirror.

Authorization by design

The rules-of-engagement engine allows, limits or denies every action — and logs it to a tamper-evident audit trail.

Near-zero false positives

A flaw only becomes "exploitable" with reproducible proof. No more 4,000 theoretical CVEs to triage.

Real prioritization

KEV › EPSS › exploit availability › exposure › business criticality. An actively exploited medium outranks a dormant critical.

Attack-path chaining

Link exposure + flaw + leaked credential into a proven attack path with impact — not a flat list.

Coming · P5

Multi-tenant & white-label

MSSP / host reselling: per-tenant theme, domain and reports, with strict isolation verified at the database level (RLS).

Platform modules

One platform, modular capabilities

Every module activates per tenant — the console grows as you enable them.

Continuous change detection

New asset, service, finding or leak? Instant alerts to Slack, Teams, webhook or email — plus an inventory diff between scans.

ROE Cockpit

Consent, proof of control (DNS TXT) and signed mandate per asset, with a global and per-campaign kill-switch. The guardrail no other offensive platform shows.

Signed exploitation proof

Each proven flaw carries a timestamped, cryptographically signed, audit-grade proof — safe-mode, nothing modified.

Personalized threat center

Emerging KEV/EPSS and public exploits filtered to your assets, plus credential-leak correlation (Have I Been Pwned).

Sovereign AI analyst

Prioritizes and explains findings in safe-mode — Claude (EU, zero-retention) or a fully local model. PII minimized, never a decision-maker.

Signed reports & shareable portal

Executive + technical reports as signed PDF, and an interactive web portal via an expiring, revocable link with client↔analyst comments.

Remediation & ticketing

Group findings into projects with owner, SLA and verification re-scan — push to Jira / ServiceNow / webhook in one click.

Read-only connectors

Fortinet, Microsoft 365 / Entra, GitHub, AWS, SNMP — credentials in a sovereign vault, each connector an activatable module.

Pricing

From a free scan to a sovereign platform

Start free in 60 seconds. Scale to continuous, then to your own sovereign instance.

Lite

Free

Instant passive preview + one full active scan after proof of control (DNS). Clear report with CVE + AI fix suggestions.

Scan now
Most popular

Advanced

€290/mo

Continuous offensive testing (the snake), multi-layer active scanning, CVE correlation KEV/EPSS, change detection + alerts, signed PDF reports + shareable portal, sovereign AI analyst.

Start

Sovereign / Enterprise

Custom

Your own self-hosted multi-tenant instance: ROE engine + signed mandates, local+Entra SSO, internal VPN assessment, read-only connectors, reverse engineering, white-label, air-gap, compliance mapping.

Talk to us
Legal framework, by design

No active action outside the authorized scope

In France, unauthorized access to a system is a criminal offense. A written mandate and proof of control are the only protection — CyDrakk enforces them automatically, per asset type.

Asset typePassiveActive scanValidation
Asset you ownproof + mandate ✓ Allowed ✓ Non-destructive ✓ Safe-mode
M365 / SharePoint tenantshared service ✓ Allowed ⚠ Config / exposure ⚠ Identification only
Unmandated third-party asset ⚠ Public OSINT ✕ Denied ✕ Denied
  • Proof of control — DNS TXT, HTTP file, email, ASN or Entra admin before any active packet.
  • Safe-mode by default — read-only, never another party's data, no state change, never any persistence.
  • Append-only audit — who, what, when, under which authorization. Admissible evidence in a dispute.
  • Kill-switch — immediate global stop per tenant and per campaign.
Education & M365 vertical

Built for the training-provider world — and for compliance

Native understanding of the M365 / SharePoint / Entra surface, with GDPR and security-policy requirements built in. NIS2 requires knowing your IT estate: CyDrakk keeps a living Technical Architecture Document up to date.

  • Native M365 surface — exposure, configuration, Entra SSO, without going beyond identification on shared services.
  • GDPR & policy — sovereign audit data, controlled retention.
  • NIS2 compliance — self-maintained architecture document, drift over time. Coming · P6
Weekly report — preview

For the executive

Exposure to watch

4 actually exploitable flaws this week, 2 of them on critical services. Priority: 72 h.

For the CISO

CVE-2021-41773 — RCE, KEV, proof attached

CVE-2023-27997 — FortiOS, EPSS 0.94

CVE-2024-21413 — ransomware campaign

Sovereign suite

Offensive and defensive, one foundation

CyDrakk shares its foundation (CVE ingestion, asset model, report engine) with OpenVault, the self-hosted SOC agent. A red + blue suite, 100% sovereign.

Red · Offensive

CyDrakk

External attack surface, exploitability correlation, safe-mode validation, chaining and reporting. Coming: internal bot and breach-and-attack simulation (BAS) without breaking anything.

Blue · Defensive

OpenVault

Self-hosted SOC agent. Detection and response on the same asset model and intel — closing the loop between what is exposed and what is monitored.

Internal network testing

Audit the inside — like a pentester on site

Connect one or more VPNs per client and assess the information system from within: inventory, flow mapping, hybrid AD/Entra — under explicit authorization and a signed internal mandate, fully logged.

  • Passive discovery first — hosts, OS, services, versions, accounts; no active packet without authorization.
  • Flow mapping — "who talks to what", segmentation, trust relationships, hybrid AD / Entra in read-only.
  • Safe-mode BAS — lateral-movement simulation that proves possible paths without breaking or exfiltrating anything.
  • Gated by the ROE — one or more VPNs per tenant, isolated egress, kill-switch, append-only audit.

No destructive action, no data exfiltration — the platform proves, it never pushes further.

Internal access via VPN
CyDrakk VPN Internal network
Application layer

Analyze your CRM, ERP and business apps

Authenticated, read-only scanning of business applications (CRM, ERP, SaaS, M365, web apps) with a test account provided by the client — stored in Vault. Strict safe-mode: never a write, never another account's data.

Access flaws

IDOR, broken authentication, missing server-side session control — proven with fictitious accounts and objects whenever possible.

Misconfigured rights

Over-permissive roles, exposed debug endpoints, overly open CORS, missing security headers.

Read-only, always

Never writes or changes state, never touches another user's data, and never adds or modifies rights autonomously — that stays a human-validated admin action.

Shared SaaS respected

On mutualized services (M365 & co.), the ROE caps validation at identification — per Microsoft's policy, no exploitation of shared services.

Live threat feed

Latest actively exploited vulnerabilities

CISA KEV feed, ingested daily by the platform — what attackers are exploiting right now.

Loading feed…

Frequently asked

What we guarantee

Is this an "autonomous AI pentester"?
No — by design. Long-horizon offensive reasoning is not solved by the state of the art. Our AI augments the analyst and prioritizes, with human validation gates. That is also what keeps the tool legal and safe.
Does our data leave our infrastructure?
Never. CyDrakk is 100% self-hosted. The only outbound flows are public intel feeds (KEV, EPSS, NVD, templates) and scans toward your authorized targets. An air-gap mode with a local feed mirror is available.
How are unauthorized scans prevented?
No active packet is emitted without proof of control of the asset and a signed mandate. The rules-of-engagement engine decides for every action, per asset type, and logs everything to an append-only audit trail.
Can we resell it to our own clients?
Yes. Multi-tenant by design, with white-label: per-tenant theme, domain and reports, with strict isolation. Built for sovereign MSSPs and hosts.

Ready to see your real exposure?

Connect your authorized domains and get, from the very first week, the map of what is actually exploitable.

Open the console

A demo, a question? contact@cydrakk.io