Know what attackers can exploit and what AI agents cannot understand.
Continuous external security and Agent Readiness monitoring for one verified website. Run posture scans, quarterly external pentests, and real AI buyer journeys. Get evidence, concrete fixes, and repeatable retests.
$49 per verified domain per month. Free posture snapshot available.
AI buyer simulation
SaaS buyer readiness
3 tasks · Live read only test · Manual run
yourdomain.com
Verified
Evidence report
Ready
Interactive product preview. Switch modules and select a journey.
One verified domain. Two kinds of failure.
A secure site can still be difficult for an agent to understand. An agent-readable site can still be insecure. complyeah keeps both outcomes clear instead of blending them into a meaningless score.
Module 01
External Security
Find weaknesses on your public surface and produce structured evidence for SOC 2 and ISO 27001.
Module 02
Agent Readiness
See whether AI agents can identify your product, find the right facts, support their answers, and reach the correct buyer action.
Verify once. Choose the right test. Retest what changed.
External Security and Agent Readiness share the domain and evidence workflow while keeping authorization, runners, limits, and results separate.
- 01
Verify the domain
Prove ownership once with the existing DNS or file flow. Both product modules reuse that verified domain.
- 02
Choose the test
Run a posture scan, an external pentest, or an editable AI Buyer Journey suite under its separate execution policy.
- 03
Review evidence and fixes
Inspect security findings or task-level agent answers, sources, screenshots, assertions, and concrete remediation.
- 04
Retest what changed
Rerun after a deployment and keep the new evidence, resolved findings, regressions, and recoveries in history.
Evidence you can inspect, not an opaque score.
Security findings and Agent Readiness tasks retain their own result models. Each shows what was observed, why it matters, and what to change before the next run.
The site does not set Strict-Transport-Security, so a first request can be downgraded to HTTP.
Add a Strict-Transport-Security response header with a max-age of at least one year.
The security page mentions EU hosting, but it does not identify which plans or subprocessors the statement covers.
Add a direct residency statement with plan scope, region choices, and a link to the subprocessor list.
Posture grade, not a wall of red
Every report leads with an A-F grade and severity counts, so the headline is a decision - not a panic.
A fix on every finding
Each issue is paired with concrete remediation and an effort estimate, ordered so you fix what matters first.
Control-mapping appendix
Findings map to the exact controls your auditor checks - SOC 2 and ISO 27001:2022 - as a first-class appendix.
Stated methodology & scope
Assessed against OWASP WSTG, PTES, and NIST SP 800-115, with an explicit external-only scope and limitations statement.
Re-test evidence trail
Re-scan after you fix. Criticals and highs carry a remediation trail - the evidence auditors weight most.
Human-verified sign-off
Some auditors want a human sign-off. Add a reviewer attestation to any comprehensive report for $99 - our team reviews it and counter-signs your certificate with a verifiable digital signature.
Built for founders shipping SOC 2 - not for a SOC team.
Choose one test or continuous assurance
$50 runs a full pentest with one 60-day retest. Continuous adds monthly security posture and five full agent runs for $49 per verified domain, never per seat.
External-only
We test what the internet can reach. No source-code access, no agents to install, nothing to deploy.
Re-verify your fixes
Fixed a finding? Re-verify it right from the report, so your certificate reflects what you shipped - not last quarter.
Authorized by design
No scan runs without verified ownership and a stored authorization. Re-checked before every run. There is no override.
Calm, decision-first reporting
Grade, counts, and fixes - presented so a founder can act, not a report engineered to scare you into a retainer.
Auditor-ready output
Control mapping, methodology, scope, and a remediation trail - the shape auditors already expect.
Every finding lands on a control your auditor already uses.
SOC 2 and ISO 27001 reviews need scoped evidence that an auditor can assess, so security findings map to the relevant controls below.
Start free, buy one pentest, or monitor continuously.
A free posture snapshot is $0. A full external pentest is $50 and includes one retest within 60 days. Continuous is $49 per domain each month or $490 annually and adds security plus five full agent runs.
A real security check. No card required.
- TLS / certificate, security-header & cookie checks
- Detection of exposed secrets & API keys
- Email-DNS hygiene (SPF, DMARC)
- Posture grade + every finding paired with a fix
- A snapshot, not a pentest - upgrade any time
A full external pentest plus one full retest within 60 days.
- One comprehensive external penetration test
- Auditor-ready report + shareable live certificate
- SOC 2 & ISO 27001:2022 control mapping
- Connect via MCP so your agent can fix findings and re-verify them
- One full retest within 60 days
- Add as many domains as you want - free to verify
- Buy as many credits as you want; each is valid a full year
Continuous assurance for one website.
- 3 security posture scans each month
- 5 agent runs each month, with up to 10 workflow nodes per run
- 1 external pentest each quarter, available immediately
- One full retest per pentest within 60 days
- MCP fix loop for your coding agent
- History, PDF + JSON exports, private sharing, and alerts
Guard the workflows that cannot regress.
- 5 agent runs each month
- Up to 30 workflow nodes per run
- Select critical nodes for regression monitoring
- Coverage for up to 3 verified domains
- Alerts and task tracking integrations
A security reviewer assesses a completed comprehensive report and counter-signs its certificate.
Open reports- Available only for completed comprehensive security reports
- Reviewer attestation and verifiable counter-signature
- Does not guarantee acceptance by every auditor
Volume programs, procurement, and a human sign-off on your reports.
Talk to us- Volume pricing and consolidated invoicing
- Human-verified sign-off available for $99 per report
- Priority support and onboarding
One complete workflow execution is one agent run, regardless of how many nodes it contains within the plan limit. Monthly quotas reset on the billing anniversary and do not roll over, including on annual plans. The first quarterly pentest is available immediately; quarterly entitlements do not stack. Cancel any time and retain access through the paid period. Continuous covers one verified domain. Business covers up to three verified domains and adds focused critical regression monitoring. Human review is purchased separately at $99 per comprehensive report.
The things founders ask first.
Still unsure? Start a scan - you verify ownership before anything runs.
How much does it cost?
A security posture snapshot is free. One comprehensive external pentest is $50 and includes one full retest within 60 days. Continuous is $49 per verified domain each month or $490 annually, with 3 posture scans and 5 agent runs of up to 10 nodes each month plus one external pentest each quarter. Business is $199 monthly for 3 domains, 30-node workflows, and selected critical regression monitoring. Human review is $99 per security report. There are no seat charges.
Can I get a refund, and how long do credits last?
Every credit is valid for a full year (12 months), and we email you before one expires. If you change your mind, you can withdraw and refund any credit you haven't used within 14 days of purchase - self-serve from your billing page, back to your original payment method. Starting a scan uses a credit and waives that 14-day withdrawal for it. And if a scan ever fails on our side, we restore the credit automatically at no cost to you.
Do auditors accept AI-run pentests?
Auditor requirements vary. We produce a scoped, methodology-backed report with evidence and a remediation trail. Where an auditor requires a human sign-off, you can add a $99 reviewer attestation; confirm suitability with your auditor first.
What exactly do you test?
Your external, internet-facing surface: web applications, APIs, and exposed services on domains you've verified. It's external-only by design - no source-code review, no internal-network testing, and no social engineering.
Why is this a fraction of the price of a normal pentest?
A traditional pentest is priced on consultant hours. We automate repeatable external testing and report assembly, then deliver scoped evidence and fixes through a self-serve workflow. Where an auditor wants human sign-off, add a $99 reviewer attestation to a comprehensive report.
How do you make sure a scan is authorized?
No scan runs without DNS-verified ownership of the domain and a stored authorization that records scope and rules of engagement. Ownership is re-checked immediately before every scan, and there is no override - it's enforced in the service layer, not just the UI.
Is it safe to run against production?
The runners are designed for authorized production targets. Security testing is external and bounded, while Agent Readiness is read only and restricted to the verified domain. Traffic is attributable. Review the published scanner and agent runner disclosures against your own production policy before running.
How long does it take?
Setup is a few minutes: add a domain, drop a DNS record, and authorize the selected test. Completion time depends on the target and test type. Reruns are available within the credit or subscription entitlement shown for that domain.
Test the product you actually shipped.
Start with a free posture snapshot, buy one external pentest, or monitor security and Agent Readiness continuously.