complyeah
External security + agent readiness

Know what attackers can exploit and what AI agents cannot understand.

Continuous external security and Agent Readiness monitoring for one verified website. Run posture scans, quarterly external pentests, and real AI buyer journeys. Get evidence, concrete fixes, and repeatable retests.

$49 per verified domain per month. Free posture snapshot available.

Verified ownershipAttributable trafficNon-destructive by defaultEvidence on every result
app.complyeah.com

AI buyer simulation

SaaS buyer readiness

3 tasks · Live read only test · Manual run

yourdomain.com

Verified

Evidence report

Ready

Interactive product preview. Switch modules and select a journey.

One domain, two independent modules

One verified domain. Two kinds of failure.

A secure site can still be difficult for an agent to understand. An agent-readable site can still be insecure. complyeah keeps both outcomes clear instead of blending them into a meaningless score.

Shared workflow

Verify once. Choose the right test. Retest what changed.

External Security and Agent Readiness share the domain and evidence workflow while keeping authorization, runners, limits, and results separate.

  1. 01

    Verify the domain

    Prove ownership once with the existing DNS or file flow. Both product modules reuse that verified domain.

  2. 02

    Choose the test

    Run a posture scan, an external pentest, or an editable AI Buyer Journey suite under its separate execution policy.

  3. 03

    Review evidence and fixes

    Inspect security findings or task-level agent answers, sources, screenshots, assertions, and concrete remediation.

  4. 04

    Retest what changed

    Rerun after a deployment and keep the new evidence, resolved findings, regressions, and recoveries in history.

Example product output

Evidence you can inspect, not an opaque score.

Security findings and Agent Readiness tasks retain their own result models. Each shows what was observed, why it matters, and what to change before the next run.

Low severityapi.yourdomain.com
Missing HSTS header

The site does not set Strict-Transport-Security, so a first request can be downgraded to HTTP.

Fix · ~15 min

Add a Strict-Transport-Security response header with a max-age of at least one year.

AI Buyer JourneyExample result
Can customer data remain in the EU?
Partial

The security page mentions EU hosting, but it does not identify which plans or subprocessors the statement covers.

Evidence
/security/data-residency
Fix

Add a direct residency statement with plan scope, region choices, and a link to the subprocessor list.

Posture grade, not a wall of red

Every report leads with an A-F grade and severity counts, so the headline is a decision - not a panic.

A fix on every finding

Each issue is paired with concrete remediation and an effort estimate, ordered so you fix what matters first.

Control-mapping appendix

Findings map to the exact controls your auditor checks - SOC 2 and ISO 27001:2022 - as a first-class appendix.

Stated methodology & scope

Assessed against OWASP WSTG, PTES, and NIST SP 800-115, with an explicit external-only scope and limitations statement.

Re-test evidence trail

Re-scan after you fix. Criticals and highs carry a remediation trail - the evidence auditors weight most.

Human-verified sign-off

Some auditors want a human sign-off. Add a reviewer attestation to any comprehensive report for $99 - our team reviews it and counter-signs your certificate with a verifiable digital signature.

Why complyeah

Built for founders shipping SOC 2 - not for a SOC team.

Choose one test or continuous assurance

$50 runs a full pentest with one 60-day retest. Continuous adds monthly security posture and five full agent runs for $49 per verified domain, never per seat.

External-only

We test what the internet can reach. No source-code access, no agents to install, nothing to deploy.

Re-verify your fixes

Fixed a finding? Re-verify it right from the report, so your certificate reflects what you shipped - not last quarter.

Authorized by design

No scan runs without verified ownership and a stored authorization. Re-checked before every run. There is no override.

Calm, decision-first reporting

Grade, counts, and fixes - presented so a founder can act, not a report engineered to scare you into a retainer.

Auditor-ready output

Control mapping, methodology, scope, and a remediation trail - the shape auditors already expect.

Mapped, not just scanned

Every finding lands on a control your auditor already uses.

SOC 2 and ISO 27001 reviews need scoped evidence that an auditor can assess, so security findings map to the relevant controls below.

SOC 2CC4.1SOC 2CC6.1SOC 2CC7.1SOC 2CC7.2ISO 27001A.8.8ISO 27001A.8.29
MethodologyOWASP WSTGPTESNIST SP 800-115
Pricing

Start free, buy one pentest, or monitor continuously.

A free posture snapshot is $0. A full external pentest is $50 and includes one retest within 60 days. Continuous is $49 per domain each month or $490 annually and adds security plus five full agent runs.

Free scan
$0
Shallow posture snapshot

A real security check. No card required.

  • TLS / certificate, security-header & cookie checks
  • Detection of exposed secrets & API keys
  • Email-DNS hygiene (SPF, DMARC)
  • Posture grade + every finding paired with a fix
  • A snapshot, not a pentest - upgrade any time
External pentest
$50/ scan
One verified domain

A full external pentest plus one full retest within 60 days.

  • One comprehensive external penetration test
  • Auditor-ready report + shareable live certificate
  • SOC 2 & ISO 27001:2022 control mapping
  • Connect via MCP so your agent can fix findings and re-verify them
  • One full retest within 60 days
  • Add as many domains as you want - free to verify
  • Buy as many credits as you want; each is valid a full year
Continuous
Recommended
$49/ month
Per verified domain · $490/year

Continuous assurance for one website.

  • 3 security posture scans each month
  • 5 agent runs each month, with up to 10 workflow nodes per run
  • 1 external pentest each quarter, available immediately
  • One full retest per pentest within 60 days
  • MCP fix loop for your coding agent
  • History, PDF + JSON exports, private sharing, and alerts
Business
$199/ month
Up to 3 verified domains

Guard the workflows that cannot regress.

  • 5 agent runs each month
  • Up to 30 workflow nodes per run
  • Select critical nodes for regression monitoring
  • Coverage for up to 3 verified domains
  • Alerts and task tracking integrations
Human review
$99/ report
Optional reviewer attestation

A security reviewer assesses a completed comprehensive report and counter-signs its certificate.

Open reports
  • Available only for completed comprehensive security reports
  • Reviewer attestation and verifiable counter-signature
  • Does not guarantee acceptance by every auditor
Enterprise
Custom
Talk to us

Volume programs, procurement, and a human sign-off on your reports.

Talk to us
  • Volume pricing and consolidated invoicing
  • Human-verified sign-off available for $99 per report
  • Priority support and onboarding

One complete workflow execution is one agent run, regardless of how many nodes it contains within the plan limit. Monthly quotas reset on the billing anniversary and do not roll over, including on annual plans. The first quarterly pentest is available immediately; quarterly entitlements do not stack. Cancel any time and retain access through the paid period. Continuous covers one verified domain. Business covers up to three verified domains and adds focused critical regression monitoring. Human review is purchased separately at $99 per comprehensive report.

Questions

The things founders ask first.

Still unsure? Start a scan - you verify ownership before anything runs.

How much does it cost?

A security posture snapshot is free. One comprehensive external pentest is $50 and includes one full retest within 60 days. Continuous is $49 per verified domain each month or $490 annually, with 3 posture scans and 5 agent runs of up to 10 nodes each month plus one external pentest each quarter. Business is $199 monthly for 3 domains, 30-node workflows, and selected critical regression monitoring. Human review is $99 per security report. There are no seat charges.

Can I get a refund, and how long do credits last?

Every credit is valid for a full year (12 months), and we email you before one expires. If you change your mind, you can withdraw and refund any credit you haven't used within 14 days of purchase - self-serve from your billing page, back to your original payment method. Starting a scan uses a credit and waives that 14-day withdrawal for it. And if a scan ever fails on our side, we restore the credit automatically at no cost to you.

Do auditors accept AI-run pentests?

Auditor requirements vary. We produce a scoped, methodology-backed report with evidence and a remediation trail. Where an auditor requires a human sign-off, you can add a $99 reviewer attestation; confirm suitability with your auditor first.

What exactly do you test?

Your external, internet-facing surface: web applications, APIs, and exposed services on domains you've verified. It's external-only by design - no source-code review, no internal-network testing, and no social engineering.

Why is this a fraction of the price of a normal pentest?

A traditional pentest is priced on consultant hours. We automate repeatable external testing and report assembly, then deliver scoped evidence and fixes through a self-serve workflow. Where an auditor wants human sign-off, add a $99 reviewer attestation to a comprehensive report.

How do you make sure a scan is authorized?

No scan runs without DNS-verified ownership of the domain and a stored authorization that records scope and rules of engagement. Ownership is re-checked immediately before every scan, and there is no override - it's enforced in the service layer, not just the UI.

Is it safe to run against production?

The runners are designed for authorized production targets. Security testing is external and bounded, while Agent Readiness is read only and restricted to the verified domain. Traffic is attributable. Review the published scanner and agent runner disclosures against your own production policy before running.

How long does it take?

Setup is a few minutes: add a domain, drop a DNS record, and authorize the selected test. Completion time depends on the target and test type. Reruns are available within the credit or subscription entitlement shown for that domain.

Test the product you actually shipped.

Start with a free posture snapshot, buy one external pentest, or monitor security and Agent Readiness continuously.